Poradain
2010-11-03, 07:08
Hi Spybot team,
Since about a month ago, clicking on search results from Google redirects me to either a 'continue' button or some random search engine. Happens most (but not all) of the time and if I keep opening the link, it eventually gets through. I have performed full scans with Kaspersky as well as Spybot S&D. Kaspersky turned up clean while Spybot found some red items which I ran the 'fix it' option on. New scans on both are now clean, however the original problem persists. Further, I have been having problems connecting to the Spybot website today and only managed to reach this forum via other links.
My OS is Windows 7 and default browser is Firefox. I have ran ERUNT and below are DDS logs as per instructions in the 'Before you post' thread.
Your help in fixing this problem will be greatly appreciated.
Thanks in advance,
Edmond
DDS (Ver_10-11-01.01) - NTFSx86
Run by Edmond at 15:56:43.71 on 03/11/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
Microsoft Windows 7 Ultimate 6.1.7600.0.950.852.1033.18.2046.1157 [GMT 11:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\AERTSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Kaspersky Internet Security 2011\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
D:\Seagate Manager\Sync\FreeAgentService.exe
D:\Hamachi\hamachi-2.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Nakido\nakido.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system\HsMgr.exe
D:\Kaspersky Internet Security 2011\avp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\iTune\iTunesHelper.exe
C:\Program Files\ASUS Xonar D2 Audio\Customapp\ASUSAUDIOCENTER.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\taskhost.exe
C:\Program Files\Opera\opera.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Users\Edmond\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.2345.com/?271011
uInternet Settings,ProxyOverride = *.local
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - d:\kaspersky internet security 2011\ievkbd.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - d:\megaupload manager\MegaIEMn.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\java\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - d:\kaspersky internet security 2011\klwtbbho.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
TB: @c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [EPSON TX300F Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiejp.exe /fu "c:\windows\temp\E_SB9A.tmp" /EF "HKCU"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [msconfg] c:\program files\coopen\Coopen.exe
mRun: [UpdateLBPShortCut] "d:\cyberlink\labelprint\muitransfer\muistartmenu.exe" "d:\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdateP2GoShortCut] "d:\cyberlink\power2go\muitransfer\muistartmenu.exe" "d:\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePPShortCut] "d:\cyberlink\powerproducer\muitransfer\muistartmenu.exe" "d:\cyberlink\powerproducer" updatewithcreateonce "software\cyberlink\powerproducer\5.0"
mRun: [UpdatePSTShortCut] "d:\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "d:\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [Cmaudio8788] RunDll32 cmicnfgp.cpl,CMICtrlWnd
mRun: [Cmaudio8788GX] c:\windows\system\HsMgr.exe Envoke
mRun: [AVP] "d:\kaspersky internet security 2011\avp.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "d:\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "d:\itune\iTunesHelper.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
StartupFolder: c:\users\edmond\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Anti-Banner - d:\kaspersky internet security 2011\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - d:\kaspersky internet security 2011\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - d:\kaspersky internet security 2011\klwtbbho.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
TCP: NameServer = 208.67.220.220,208.67.222.222
TCP: {5AA3F36C-3FBB-4020-9E94-CA99044AEA85} = 198.142.0.51,93.188.166.72
TCP: {E1739C79-D875-4970-A773-8F4BD0A4B1A2} = 208.67.220.220,208.67.222.222
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: d:\kasper~2\mzvkbd3.dll,d:\kasper~2\kloehk.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\edmond\appdata\roaming\mozilla\firefox\profiles\s3j0eesw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - component: c:\users\edmond\appdata\roaming\mozilla\firefox\profiles\s3j0eesw.default\extensions\glasser@sixxgate.com\components\dwmxpcom.dll
FF - component: d:\firefox\extensions\kavantibanner@kaspersky.ru\components\abhelperxpcom.dll
FF - component: d:\firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: d:\firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: d:\firefox\plugins\npwachk.dll
FF - plugin: d:\itune\mozilla plugins\npitunes.dll
FF - plugin: d:\java\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\java\bin\new_plugin\npjp2.dll
FF - plugin: d:\quicktime\plugins\npqtplugin.dll
FF - plugin: d:\quicktime\plugins\npqtplugin2.dll
FF - plugin: d:\quicktime\plugins\npqtplugin3.dll
FF - plugin: d:\quicktime\plugins\npqtplugin4.dll
FF - plugin: d:\quicktime\plugins\npqtplugin5.dll
FF - plugin: d:\quicktime\plugins\npqtplugin6.dll
FF - plugin: d:\quicktime\plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - d:\firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - d:\firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
============= SERVICES / DRIVERS ===============
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2009-11-3 22104]
R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-9-8 176128]
R2 AVP;Kaspersky Anti-Virus Service;d:\kaspersky internet security 2011\avp.exe -r --> d:\kaspersky internet security 2011\avp.exe -r [?]
R2 FreeAgentGoNext Service;Seagate Service;d:\seagate manager\sync\FreeAgentService.exe [2009-9-25 189736]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\hamachi\hamachi-2.exe -s --> d:\hamachi\hamachi-2.exe -s [?]
R2 Nakido;Nakido;c:\program files\nakido\nakido.exe [2010-5-23 333312]
R2 SSPORT;SSPORT;c:\windows\system32\drivers\SSPORT.SYS [2010-9-13 5120]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-9-8 6381056]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-9-8 221696]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2010-8-16 101904]
R3 cmudaxp;ASUS Xonar D2 Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [2010-6-28 1497600]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2009-9-4 27632]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SBSDWSCService;SBSD Security Center Service;d:\spybot - search & destroy\spybot - search & destroy\SDWinSec.exe [2010-3-29 1153368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-21 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [2010-3-10 25112]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19984]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2009-9-4 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2009-9-4 120744]
S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-14 980992]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2009-7-14 266752]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-3 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
=============== Created Last 30 ================
2010-10-29 07:47:28 -------- d-----w- c:\progra~2\PPREGMSG
2010-10-29 07:43:41 -------- d-----w- c:\users\edmond\appdata\local\Penpower
2010-10-29 07:42:58 59920 ------w- c:\windows\system32\ppadapi.dll
2010-10-29 07:42:58 137744 ------w- c:\windows\system32\PPWORDW.DLL
2010-10-29 07:42:47 -------- d-----w- c:\progra~2\WINPENJR
2010-10-29 07:42:33 -------- d-----w- c:\program files\WINPENJR
2010-10-26 23:40:45 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-10-26 23:40:45 417792 ----a-w- c:\windows\system32\msdri.dll
2010-10-26 23:40:44 204288 ----a-w- c:\windows\system32\MSNP.ax
2010-10-26 23:40:44 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2010-10-26 23:40:39 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-10-21 12:42:54 -------- d-sh--w- c:\windows\system32\%APPDATA%
2010-10-21 12:40:40 -------- d-----w- c:\users\edmond\appdata\local\Opera
2010-10-21 01:01:00 -------- d-----w- c:\windows\en
2010-10-21 01:00:39 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2010-10-21 01:00:08 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-10-21 00:57:28 -------- d-----w- c:\program files\MSN Toolbar
2010-10-21 00:57:09 -------- d-----w- c:\program files\Bing Bar Installer
2010-10-21 00:56:10 469256 ----a-w- c:\program files\common files\windows live\.cache\bf20315c1cb70ba14\InstallManager_WLE_WLE.exe
2010-10-21 00:56:07 15712 ----a-w- c:\program files\common files\windows live\.cache\be2747ae1cb70ba13\MeshBetaRemover.exe
2010-10-21 00:55:55 94040 ----a-w- c:\program files\common files\windows live\.cache\b65be2dd1cb70ba12\DSETUP.dll
2010-10-21 00:55:55 525656 ----a-w- c:\program files\common files\windows live\.cache\b65be2dd1cb70ba12\DXSETUP.exe
2010-10-21 00:55:55 1691480 ----a-w- c:\program files\common files\windows live\.cache\b65be2dd1cb70ba12\dsetup32.dll
2010-10-21 00:55:52 94040 ----a-w- c:\program files\common files\windows live\.cache\b509539c1cb70ba11\DSETUP.dll
2010-10-21 00:55:52 525656 ----a-w- c:\program files\common files\windows live\.cache\b509539c1cb70ba11\DXSETUP.exe
2010-10-21 00:55:52 1691480 ----a-w- c:\program files\common files\windows live\.cache\b509539c1cb70ba11\dsetup32.dll
2010-10-21 00:55:15 6260088 ----a-w- c:\program files\common files\windows live\.cache\9e63f6c11cb70ba0d\Silverlight.4.0.exe
2010-10-21 00:54:49 -------- d-----w- c:\users\edmond\appdata\local\Windows Live
2010-10-21 00:54:14 3181568 ----a-w- c:\windows\system32\mf.dll
2010-10-21 00:54:14 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2010-10-21 00:54:13 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2010-10-10 07:14:01 -------- d-----w- c:\program files\Microsoft XNA
2010-10-09 08:27:11 -------- d-----w- c:\program files\common files\ATI Technologies
2010-10-09 08:25:22 -------- d-----w- c:\program files\ATI Technologies
2010-10-09 08:25:20 -------- d-----w- c:\program files\ATI
2010-10-09 08:15:50 -------- d-----w- C:\AMD
==================== Find3M ====================
2010-09-22 13:47:28 49016 ----a-w- c:\windows\system32\sirenacm.dll
2010-09-22 13:32:56 301936 ----a-w- c:\windows\WLXPGSS.SCR
2010-09-21 03:03:14 208768 ----a-w- c:\windows\system32\LIVESSP.DLL
2010-09-08 04:30:04 978432 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 03:22:31 386048 ----a-w- c:\windows\system32\html.iec
2010-09-08 02:48:16 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-09-08 01:55:20 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-09-08 01:55:10 528384 ----a-w- c:\windows\system32\aticfx32.dll
2010-09-08 01:52:04 450560 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-09-08 01:51:32 380928 ----a-w- c:\windows\system32\atieclxx.exe
2010-09-08 01:51:02 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2010-09-08 01:50:30 15830016 ----a-w- c:\windows\system32\atioglxx.dll
2010-09-08 01:49:52 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2010-09-08 01:49:36 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2010-09-08 01:49:24 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2010-09-08 01:49:18 11776 ----a-w- c:\windows\system32\atimuixx.dll
2010-09-08 01:49:10 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-09-08 01:46:10 3914240 ----a-w- c:\windows\system32\atidxx32.dll
2010-09-08 01:28:28 46080 ----a-w- c:\windows\system32\aticalrt.dll
2010-09-08 01:28:18 44032 ----a-w- c:\windows\system32\aticalcl.dll
2010-09-08 01:28:06 4057088 ----a-w- c:\windows\system32\atiumdag.dll
2010-09-08 01:27:02 4375552 ----a-w- c:\windows\system32\aticaldd.dll
2010-09-08 01:24:52 65536 ----a-w- c:\windows\system32\coinst.dll
2010-09-08 01:21:16 3392512 ----a-w- c:\windows\system32\atiumdva.dll
2010-09-08 01:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 01:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-09-08 01:15:26 241664 ----a-w- c:\windows\system32\atiadlxx.dll
2010-09-08 01:15:14 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-09-08 01:15:08 19968 ----a-w- c:\windows\system32\atigktxx.dll
2010-09-08 01:14:16 30208 ----a-w- c:\windows\system32\atiuxpag.dll
2010-09-08 01:14:02 28160 ----a-w- c:\windows\system32\atiu9pag.dll
2010-09-08 01:08:28 52736 ----a-w- c:\windows\system32\atimpc32.dll
2010-09-08 01:08:28 52736 ----a-w- c:\windows\system32\amdpcom32.dll
2010-09-01 04:23:49 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-01 02:34:52 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-08-31 04:32:30 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-08-27 05:46:48 168448 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 04:39:58 109056 ----a-w- c:\windows\system32\t2embed.dll
2010-08-21 05:36:33 738816 ----a-w- c:\windows\system32\wmpmde.dll
2010-08-21 05:36:24 224256 ----a-w- c:\windows\system32\schannel.dll
2010-08-21 05:33:24 530432 ----a-w- c:\windows\system32\comctl32.dll
2010-08-21 05:32:37 316928 ----a-w- c:\windows\system32\spoolsv.exe
============= FINISH: 16:00:16.00 ===============
Since about a month ago, clicking on search results from Google redirects me to either a 'continue' button or some random search engine. Happens most (but not all) of the time and if I keep opening the link, it eventually gets through. I have performed full scans with Kaspersky as well as Spybot S&D. Kaspersky turned up clean while Spybot found some red items which I ran the 'fix it' option on. New scans on both are now clean, however the original problem persists. Further, I have been having problems connecting to the Spybot website today and only managed to reach this forum via other links.
My OS is Windows 7 and default browser is Firefox. I have ran ERUNT and below are DDS logs as per instructions in the 'Before you post' thread.
Your help in fixing this problem will be greatly appreciated.
Thanks in advance,
Edmond
DDS (Ver_10-11-01.01) - NTFSx86
Run by Edmond at 15:56:43.71 on 03/11/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
Microsoft Windows 7 Ultimate 6.1.7600.0.950.852.1033.18.2046.1157 [GMT 11:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\AERTSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Kaspersky Internet Security 2011\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
D:\Seagate Manager\Sync\FreeAgentService.exe
D:\Hamachi\hamachi-2.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Nakido\nakido.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system\HsMgr.exe
D:\Kaspersky Internet Security 2011\avp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\iTune\iTunesHelper.exe
C:\Program Files\ASUS Xonar D2 Audio\Customapp\ASUSAUDIOCENTER.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\taskhost.exe
C:\Program Files\Opera\opera.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Users\Edmond\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.2345.com/?271011
uInternet Settings,ProxyOverride = *.local
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - d:\kaspersky internet security 2011\ievkbd.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - d:\megaupload manager\MegaIEMn.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\java\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - d:\kaspersky internet security 2011\klwtbbho.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
TB: @c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [EPSON TX300F Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiejp.exe /fu "c:\windows\temp\E_SB9A.tmp" /EF "HKCU"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [msconfg] c:\program files\coopen\Coopen.exe
mRun: [UpdateLBPShortCut] "d:\cyberlink\labelprint\muitransfer\muistartmenu.exe" "d:\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdateP2GoShortCut] "d:\cyberlink\power2go\muitransfer\muistartmenu.exe" "d:\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePPShortCut] "d:\cyberlink\powerproducer\muitransfer\muistartmenu.exe" "d:\cyberlink\powerproducer" updatewithcreateonce "software\cyberlink\powerproducer\5.0"
mRun: [UpdatePSTShortCut] "d:\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "d:\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [Cmaudio8788] RunDll32 cmicnfgp.cpl,CMICtrlWnd
mRun: [Cmaudio8788GX] c:\windows\system\HsMgr.exe Envoke
mRun: [AVP] "d:\kaspersky internet security 2011\avp.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "d:\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "d:\itune\iTunesHelper.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
StartupFolder: c:\users\edmond\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Anti-Banner - d:\kaspersky internet security 2011\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - d:\kaspersky internet security 2011\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - d:\kaspersky internet security 2011\klwtbbho.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
TCP: NameServer = 208.67.220.220,208.67.222.222
TCP: {5AA3F36C-3FBB-4020-9E94-CA99044AEA85} = 198.142.0.51,93.188.166.72
TCP: {E1739C79-D875-4970-A773-8F4BD0A4B1A2} = 208.67.220.220,208.67.222.222
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: d:\kasper~2\mzvkbd3.dll,d:\kasper~2\kloehk.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\users\edmond\appdata\roaming\mozilla\firefox\profiles\s3j0eesw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - component: c:\users\edmond\appdata\roaming\mozilla\firefox\profiles\s3j0eesw.default\extensions\glasser@sixxgate.com\components\dwmxpcom.dll
FF - component: d:\firefox\extensions\kavantibanner@kaspersky.ru\components\abhelperxpcom.dll
FF - component: d:\firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: d:\firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: d:\firefox\plugins\npwachk.dll
FF - plugin: d:\itune\mozilla plugins\npitunes.dll
FF - plugin: d:\java\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\java\bin\new_plugin\npjp2.dll
FF - plugin: d:\quicktime\plugins\npqtplugin.dll
FF - plugin: d:\quicktime\plugins\npqtplugin2.dll
FF - plugin: d:\quicktime\plugins\npqtplugin3.dll
FF - plugin: d:\quicktime\plugins\npqtplugin4.dll
FF - plugin: d:\quicktime\plugins\npqtplugin5.dll
FF - plugin: d:\quicktime\plugins\npqtplugin6.dll
FF - plugin: d:\quicktime\plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - d:\firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - d:\firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
d:\firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
============= SERVICES / DRIVERS ===============
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2009-11-3 22104]
R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-9-8 176128]
R2 AVP;Kaspersky Anti-Virus Service;d:\kaspersky internet security 2011\avp.exe -r --> d:\kaspersky internet security 2011\avp.exe -r [?]
R2 FreeAgentGoNext Service;Seagate Service;d:\seagate manager\sync\FreeAgentService.exe [2009-9-25 189736]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\hamachi\hamachi-2.exe -s --> d:\hamachi\hamachi-2.exe -s [?]
R2 Nakido;Nakido;c:\program files\nakido\nakido.exe [2010-5-23 333312]
R2 SSPORT;SSPORT;c:\windows\system32\drivers\SSPORT.SYS [2010-9-13 5120]
R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-9-8 6381056]
R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-9-8 221696]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2010-8-16 101904]
R3 cmudaxp;ASUS Xonar D2 Audio Interface;c:\windows\system32\drivers\cmudaxp.sys [2010-6-28 1497600]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2009-9-4 27632]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 SBSDWSCService;SBSD Security Center Service;d:\spybot - search & destroy\spybot - search & destroy\SDWinSec.exe [2010-3-29 1153368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-21 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [2010-3-10 25112]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19984]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2009-9-4 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2009-9-4 120744]
S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-14 980992]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2009-7-14 266752]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-3 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
=============== Created Last 30 ================
2010-10-29 07:47:28 -------- d-----w- c:\progra~2\PPREGMSG
2010-10-29 07:43:41 -------- d-----w- c:\users\edmond\appdata\local\Penpower
2010-10-29 07:42:58 59920 ------w- c:\windows\system32\ppadapi.dll
2010-10-29 07:42:58 137744 ------w- c:\windows\system32\PPWORDW.DLL
2010-10-29 07:42:47 -------- d-----w- c:\progra~2\WINPENJR
2010-10-29 07:42:33 -------- d-----w- c:\program files\WINPENJR
2010-10-26 23:40:45 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-10-26 23:40:45 417792 ----a-w- c:\windows\system32\msdri.dll
2010-10-26 23:40:44 204288 ----a-w- c:\windows\system32\MSNP.ax
2010-10-26 23:40:44 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2010-10-26 23:40:39 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-10-21 12:42:54 -------- d-sh--w- c:\windows\system32\%APPDATA%
2010-10-21 12:40:40 -------- d-----w- c:\users\edmond\appdata\local\Opera
2010-10-21 01:01:00 -------- d-----w- c:\windows\en
2010-10-21 01:00:39 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2010-10-21 01:00:08 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-10-21 00:57:28 -------- d-----w- c:\program files\MSN Toolbar
2010-10-21 00:57:09 -------- d-----w- c:\program files\Bing Bar Installer
2010-10-21 00:56:10 469256 ----a-w- c:\program files\common files\windows live\.cache\bf20315c1cb70ba14\InstallManager_WLE_WLE.exe
2010-10-21 00:56:07 15712 ----a-w- c:\program files\common files\windows live\.cache\be2747ae1cb70ba13\MeshBetaRemover.exe
2010-10-21 00:55:55 94040 ----a-w- c:\program files\common files\windows live\.cache\b65be2dd1cb70ba12\DSETUP.dll
2010-10-21 00:55:55 525656 ----a-w- c:\program files\common files\windows live\.cache\b65be2dd1cb70ba12\DXSETUP.exe
2010-10-21 00:55:55 1691480 ----a-w- c:\program files\common files\windows live\.cache\b65be2dd1cb70ba12\dsetup32.dll
2010-10-21 00:55:52 94040 ----a-w- c:\program files\common files\windows live\.cache\b509539c1cb70ba11\DSETUP.dll
2010-10-21 00:55:52 525656 ----a-w- c:\program files\common files\windows live\.cache\b509539c1cb70ba11\DXSETUP.exe
2010-10-21 00:55:52 1691480 ----a-w- c:\program files\common files\windows live\.cache\b509539c1cb70ba11\dsetup32.dll
2010-10-21 00:55:15 6260088 ----a-w- c:\program files\common files\windows live\.cache\9e63f6c11cb70ba0d\Silverlight.4.0.exe
2010-10-21 00:54:49 -------- d-----w- c:\users\edmond\appdata\local\Windows Live
2010-10-21 00:54:14 3181568 ----a-w- c:\windows\system32\mf.dll
2010-10-21 00:54:14 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2010-10-21 00:54:13 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2010-10-10 07:14:01 -------- d-----w- c:\program files\Microsoft XNA
2010-10-09 08:27:11 -------- d-----w- c:\program files\common files\ATI Technologies
2010-10-09 08:25:22 -------- d-----w- c:\program files\ATI Technologies
2010-10-09 08:25:20 -------- d-----w- c:\program files\ATI
2010-10-09 08:15:50 -------- d-----w- C:\AMD
==================== Find3M ====================
2010-09-22 13:47:28 49016 ----a-w- c:\windows\system32\sirenacm.dll
2010-09-22 13:32:56 301936 ----a-w- c:\windows\WLXPGSS.SCR
2010-09-21 03:03:14 208768 ----a-w- c:\windows\system32\LIVESSP.DLL
2010-09-08 04:30:04 978432 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 03:22:31 386048 ----a-w- c:\windows\system32\html.iec
2010-09-08 02:48:16 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-09-08 01:55:20 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-09-08 01:55:10 528384 ----a-w- c:\windows\system32\aticfx32.dll
2010-09-08 01:52:04 450560 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-09-08 01:51:32 380928 ----a-w- c:\windows\system32\atieclxx.exe
2010-09-08 01:51:02 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2010-09-08 01:50:30 15830016 ----a-w- c:\windows\system32\atioglxx.dll
2010-09-08 01:49:52 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2010-09-08 01:49:36 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2010-09-08 01:49:24 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2010-09-08 01:49:18 11776 ----a-w- c:\windows\system32\atimuixx.dll
2010-09-08 01:49:10 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-09-08 01:46:10 3914240 ----a-w- c:\windows\system32\atidxx32.dll
2010-09-08 01:28:28 46080 ----a-w- c:\windows\system32\aticalrt.dll
2010-09-08 01:28:18 44032 ----a-w- c:\windows\system32\aticalcl.dll
2010-09-08 01:28:06 4057088 ----a-w- c:\windows\system32\atiumdag.dll
2010-09-08 01:27:02 4375552 ----a-w- c:\windows\system32\aticaldd.dll
2010-09-08 01:24:52 65536 ----a-w- c:\windows\system32\coinst.dll
2010-09-08 01:21:16 3392512 ----a-w- c:\windows\system32\atiumdva.dll
2010-09-08 01:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 01:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-09-08 01:15:26 241664 ----a-w- c:\windows\system32\atiadlxx.dll
2010-09-08 01:15:14 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-09-08 01:15:08 19968 ----a-w- c:\windows\system32\atigktxx.dll
2010-09-08 01:14:16 30208 ----a-w- c:\windows\system32\atiuxpag.dll
2010-09-08 01:14:02 28160 ----a-w- c:\windows\system32\atiu9pag.dll
2010-09-08 01:08:28 52736 ----a-w- c:\windows\system32\atimpc32.dll
2010-09-08 01:08:28 52736 ----a-w- c:\windows\system32\amdpcom32.dll
2010-09-01 04:23:49 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-01 02:34:52 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-08-31 04:32:30 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-08-27 05:46:48 168448 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 04:39:58 109056 ----a-w- c:\windows\system32\t2embed.dll
2010-08-21 05:36:33 738816 ----a-w- c:\windows\system32\wmpmde.dll
2010-08-21 05:36:24 224256 ----a-w- c:\windows\system32\schannel.dll
2010-08-21 05:33:24 530432 ----a-w- c:\windows\system32\comctl32.dll
2010-08-21 05:32:37 316928 ----a-w- c:\windows\system32\spoolsv.exe
============= FINISH: 16:00:16.00 ===============