MattGuy
2011-04-18, 19:11
Hi,
I have run Spybot several times always finding Click.GiftLoad, everytime Spybot has not been able to remove it.
Malwarebytes and Microsoft Security Essentials have not found it (both up-to-date).
See below as per the "Before you post" guidlines for DDS log and Scan results
DDS.txt
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Matt at 16:34:02.37 on 18/04/2011
Internet Explorer: 8.0.6001.19048
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.3069.1898 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\RtkAudioService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
c:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
c:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Sony\Network Utility\NSUService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMService.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Sony\Network Utility\LANUtil.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10p_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Matt\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.co.uk/
uDefault_Page_URL = hxxp://www.club-vaio.com
mDefault_Page_URL = hxxp://www.club-vaio.com
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\progra~1\google~1\BAE.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [NSUFloatingUI] "c:\program files\sony\network utility\LANUtil.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [<NO NAME>]
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: VESWinlogon - VESWinlogon.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsle4387db3;MpKsle4387db3;c:\programdata\microsoft\microsoft antimalware\definition updates\{8c473098-1d3a-43be-a768-0cbe3aedc503}\MpKsle4387db3.sys [2011-4-18 28752]
R2 NSUService;NSUService;c:\program files\sony\network utility\NSUService.exe [2011-4-14 229376]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-18 11032]
R2 RtkHDMIService;RtkHDMIService;c:\windows\RTKAUDIOSERVICE.EXE [2008-5-16 98304]
R2 uCamMonitor;CamMonitor;c:\program files\arcsoft\magic-i visual effects\uCamMonitor.exe [2011-4-14 104960]
R2 VAIO Power Management;VAIO Power Management;c:\program files\sony\vaio power management\SPMService.exe [2008-5-16 411488]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\drivers\ArcSoftKsUFilter.sys [2011-4-14 17408]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\drivers\NETw5v32.sys [2008-4-28 3658752]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2007-12-17 9344]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2008-5-16 28464]
S3 SOHCImp;VAIO Media plus Content Importer;c:\program files\sony\vaio media plus\SOHCImp.exe [2011-4-14 104288]
S3 SOHDms;VAIO Media plus Digital Media Server;c:\program files\sony\vaio media plus\SOHDms.exe [2011-4-14 350048]
S3 SOHDs;VAIO Media plus Device Searcher;c:\program files\sony\vaio media plus\SOHDs.exe [2011-4-14 63328]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\sony\vcm intelligent analyzing manager\VcmIAlzMgr.exe [2011-4-14 333088]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\common files\sony shared\vcmxml\VcmXmlIfHelper.exe [2011-4-14 87328]
S3 VUAgent;VUAgent;c:\program files\sony\vaio update 5\VUAgent.exe [2011-4-14 722288]
.
=============== Created Last 30 ================
.
2011-04-18 14:55:58 28752 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{8c473098-1d3a-43be-a768-0cbe3aedc503}\MpKsle4387db3.sys
2011-04-18 14:55:36 6792528 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{8c473098-1d3a-43be-a768-0cbe3aedc503}\mpengine.dll
2011-04-15 17:54:37 -------- d-----w- c:\windows\system32\Adobe
2011-04-15 17:25:26 -------- d-----w- c:\users\matt\Drivers & Installers
2011-04-15 16:43:31 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-04-15 16:43:31 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-04-15 16:43:31 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-04-15 16:43:31 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-04-15 16:43:31 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-04-15 16:40:32 -------- d-sh--w- c:\windows\system32\%APPDATA%
2011-04-15 16:40:19 231936 ----a-w- c:\windows\system32\msshsq.dll
2011-04-15 16:36:36 378368 ----a-w- c:\windows\system32\winhttp.dll
2011-04-15 16:36:31 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-04-14 18:33:16 -------- d-----w- c:\program files\Microsoft
2011-04-14 18:33:00 -------- d-----w- c:\program files\Windows Live SkyDrive
2011-04-14 18:32:27 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-04-14 18:28:26 484632 ----a-w- c:\program files\common files\windows live\.cache\be44d2641cbfad1\DXSETUP.exe
2011-04-14 18:28:25 74520 ----a-w- c:\program files\common files\windows live\.cache\be44d2641cbfad1\DSETUP.dll
2011-04-14 18:28:25 1670936 ----a-w- c:\program files\common files\windows live\.cache\be44d2641cbfad1\dsetup32.dll
2011-04-14 18:24:06 -------- d-----w- c:\program files\common files\Windows Live
2011-04-14 18:14:18 6792528 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-04-14 18:14:07 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-14 17:51:06 80896 ----a-w- c:\windows\system32\MSNP.ax
2011-04-14 17:51:06 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-04-14 17:51:02 293376 ----a-w- c:\windows\system32\psisdecd.dll
2011-04-14 17:51:01 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-04-14 17:41:12 454656 ----a-w- c:\program files\common files\system\msadc\msadce.dll
2011-04-14 17:36:59 7680 ----a-w- c:\program files\internet explorer\iecompat.dll
2011-04-14 17:34:58 293376 ----a-w- c:\windows\system32\browserchoice.exe
2011-04-14 17:32:36 -------- d-----w- c:\users\matt\appdata\local\Microsoft Help
2011-04-14 17:20:43 97800 ----a-w- c:\windows\system32\infocardapi.dll
2011-04-14 17:20:42 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2011-04-14 17:20:41 622080 ----a-w- c:\windows\system32\icardagt.exe
2011-04-14 17:20:41 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2011-04-14 17:20:41 11264 ----a-w- c:\windows\system32\icardres.dll
2011-04-14 17:20:39 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2011-04-14 17:15:36 158720 ----a-w- c:\windows\system32\mscorier.dll
2011-04-14 17:15:30 83968 ----a-w- c:\windows\system32\mscories.dll
2011-04-14 17:13:07 24064 ----a-w- c:\windows\system32\nshhttp.dll
2011-04-14 17:13:03 411136 ----a-w- c:\windows\system32\drivers\http.sys
2011-04-14 17:13:03 31232 ----a-w- c:\windows\system32\httpapi.dll
2011-04-14 17:12:17 -------- d-----w- c:\program files\MSXML 4.0
2011-04-14 16:46:08 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2011-04-14 16:46:05 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2011-04-14 16:45:57 801280 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2011-04-14 16:38:35 499200 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2011-04-14 16:37:43 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2011-04-14 16:36:56 310784 ----a-w- c:\windows\system32\unregmp2.exe
2011-04-14 16:35:58 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2011-04-14 16:34:20 866816 ----a-w- c:\windows\system32\wmpmde.dll
2011-04-14 16:34:18 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-04-14 16:34:14 24064 ----a-w- c:\windows\system32\amxread.dll
2011-04-14 16:34:14 13824 ----a-w- c:\windows\system32\apilogen.dll
2011-04-14 16:34:07 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2011-04-14 16:34:05 43520 ----a-w- c:\windows\system32\msdxm.tlb
2011-04-14 16:34:05 18432 ----a-w- c:\windows\system32\amcompat.tlb
2011-04-14 16:34:03 603648 ----a-w- c:\windows\system32\schedsvc.dll
2011-04-14 16:34:03 357376 ----a-w- c:\windows\system32\taskschd.dll
2011-04-14 16:34:02 345088 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-04-14 16:34:02 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-04-14 16:34:02 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-04-14 16:31:11 90112 ----a-w- c:\windows\system32\wshext.dll
2011-04-14 16:31:11 180224 ----a-w- c:\windows\system32\scrobj.dll
2011-04-14 16:31:11 172032 ----a-w- c:\windows\system32\scrrun.dll
2011-04-14 16:31:11 155648 ----a-w- c:\windows\system32\wscript.exe
2011-04-14 16:31:11 135168 ----a-w- c:\windows\system32\wshom.ocx
2011-04-14 16:31:11 135168 ----a-w- c:\windows\system32\cscript.exe
2011-04-14 16:27:10 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2011-04-14 16:27:10 31744 ----a-w- c:\windows\system32\msvidc32.dll
2011-04-14 16:27:10 22528 ----a-w- c:\windows\system32\msyuv.dll
2011-04-14 16:27:10 13312 ----a-w- c:\windows\system32\msrle32.dll
2011-04-14 16:27:10 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2011-04-14 16:27:09 91136 ----a-w- c:\windows\system32\avifil32.dll
2011-04-14 16:27:09 82944 ----a-w- c:\windows\system32\mciavi32.dll
2011-04-14 16:27:09 65024 ----a-w- c:\windows\system32\avicap32.dll
2011-04-14 16:27:09 123904 ----a-w- c:\windows\system32\msvfw32.dll
2011-04-14 16:27:06 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2011-04-14 16:23:25 171520 ----a-w- c:\windows\system32\wintrust.dll
2011-04-14 16:23:19 98304 ----a-w- c:\windows\system32\cabview.dll
2011-04-14 16:09:34 2421760 ----a-w- c:\windows\system32\wucltux.dll
2011-04-14 16:09:18 87552 ----a-w- c:\windows\system32\wudriver.dll
2011-04-14 16:09:11 33792 ----a-w- c:\windows\system32\wuapp.exe
2011-04-14 16:09:11 171608 ----a-w- c:\windows\system32\wuwebv.dll
2011-04-14 02:24:20 -------- d-----w- c:\progra~2\Roaming
2011-04-14 02:23:52 -------- d-----w- c:\program files\Cisco
2011-04-14 02:23:51 -------- d-----w- c:\program files\common files\Intel
2011-04-14 02:23:20 -------- d-----w- c:\program files\common files\InterVideo
2011-04-14 02:21:48 1645320 ----a-w- c:\windows\system32\gdiplus.dll
2011-04-14 02:21:38 -------- d-----w- C:\Documentation
2011-04-14 02:16:08 86016 ----a-w- c:\windows\system32\SonyAIwd.dll
2011-04-14 02:16:08 155648 ----a-w- c:\windows\system32\SonyAIwo.dll
2011-04-14 02:16:08 147456 ----a-w- c:\windows\system32\SonyAIds.dll
2011-04-14 02:14:44 -------- d-----w- c:\program files\common files\Sonic Shared
2011-04-14 02:10:24 212480 ----a-w- c:\windows\system32\PCDLIB32.DLL
2011-04-14 02:10:23 55808 ----a-w- c:\windows\system32\ArcSoftKsUFilter.dll
2011-04-14 02:10:23 245408 ----a-w- c:\windows\system32\unicows.dll
2011-04-14 02:10:23 17408 ----a-w- c:\windows\system32\drivers\ArcSoftKsUFilter.sys
2011-04-14 02:10:21 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2011-04-14 02:10:21 32768 ------w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2011-04-14 02:10:21 225280 ------w- c:\program files\common files\installshield\iscript\iscript.dll
2011-04-14 02:10:21 176128 ------w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2011-04-14 02:10:20 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2011-04-14 02:07:33 -------- d-----w- c:\program files\common files\PX Storage Engine
2011-04-14 02:07:18 -------- d-----w- c:\program files\DivX
2011-04-14 02:05:13 -------- d-----w- c:\program files\Google BAE
2011-04-14 02:03:55 -------- d-----w- c:\program files\ATI Technologies
2011-04-14 02:03:52 -------- d-----w- c:\program files\ATI
2011-04-14 01:56:03 129520 ------w- c:\windows\system32\pxafs.dll
2011-04-14 01:55:22 -------- d-----w- c:\progra~2\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2011-04-14 01:55:20 -------- d-----w- c:\program files\Activation Assistant for the 2007 Microsoft Office suites
2011-04-14 01:54:34 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
2011-04-14 01:54:34 32656 ----a-w- c:\windows\system32\msonpmon.dll
2011-04-14 01:53:55 -------- d-----w- c:\windows\PCHEALTH
2011-04-14 01:51:44 -------- d-----w- c:\windows\Sonysys
2011-04-13 20:17:30 -------- d-----w- c:\windows\pss
2011-04-13 19:26:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-04-13 19:26:25 -------- d-----w- c:\progra~2\Spybot - Search & Destroy
2011-04-13 19:23:45 -------- d-----w- c:\users\matt\appdata\roaming\Malwarebytes
2011-04-13 19:23:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-13 19:23:37 -------- d-----w- c:\progra~2\Malwarebytes
2011-04-13 19:23:33 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-13 19:23:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-13 19:22:12 -------- d-----w- c:\program files\CCleaner
2011-04-13 19:19:35 -------- d-----w- C:\Update
2011-04-13 19:18:51 439632 ------w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{a1f1fa77-e5fc-4f57-aec4-483044eaa31b}\gapaengine.dll
2011-04-13 19:04:39 -------- d-----w- c:\program files\Microsoft Security Client
2011-04-13 18:48:30 -------- d-----w- c:\users\matt\appdata\local\Sony_NSCE
2011-04-13 18:48:12 -------- d-----w- c:\users\matt\appdata\local\Google
2011-04-13 18:48:11 -------- d-----w- c:\users\matt\appdata\local\ATI
.
==================== Find3M ====================
.
2011-03-10 16:12:54 1161728 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-10 16:12:54 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-03-03 15:00:15 738816 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 12:53:48 2040832 ----a-w- c:\windows\system32\win32k.sys
2011-03-02 14:49:43 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-02-22 06:21:28 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 06:17:08 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 06:16:53 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 06:16:40 71680 ----a-w- c:\windows\system32\iesetup.dll
2011-02-22 06:16:40 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-02-22 05:20:39 385024 ----a-w- c:\windows\system32\html.iec
2011-02-22 04:43:54 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-02-22 04:42:38 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-02-16 15:29:56 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-02-16 13:24:56 292864 ----a-w- c:\windows\system32\atmfd.dll
.
============= FINISH: 16:34:57.74 ===============
Scan results
Click.GiftLoad: [SBI $89783858] User settings (Registry value, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION\svchost.exe
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2011-04-13 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2011-03-18 Includes\Adware.sbi (*)
2011-03-22 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-03-08 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2011-03-29 Includes\Hijackers.sbi (*)
2011-03-29 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2011-03-08 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2011-04-05 Includes\Malware.sbi (*)
2011-04-12 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2011-03-15 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2011-03-08 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2011-02-24 Includes\Spyware.sbi (*)
2011-03-15 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-12-28 Includes\Trojans.sbi (*)
2011-04-12 Includes\TrojansC-02.sbi (*)
2011-04-11 Includes\TrojansC-03.sbi (*)
2011-03-08 Includes\TrojansC-04.sbi (*)
2011-04-11 Includes\TrojansC-05.sbi (*)
2011-03-08 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
I have run Spybot several times always finding Click.GiftLoad, everytime Spybot has not been able to remove it.
Malwarebytes and Microsoft Security Essentials have not found it (both up-to-date).
See below as per the "Before you post" guidlines for DDS log and Scan results
DDS.txt
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Matt at 16:34:02.37 on 18/04/2011
Internet Explorer: 8.0.6001.19048
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.3069.1898 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\RtkAudioService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
c:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
c:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Sony\Network Utility\NSUService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMService.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Sony\Network Utility\LANUtil.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10p_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Matt\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.co.uk/
uDefault_Page_URL = hxxp://www.club-vaio.com
mDefault_Page_URL = hxxp://www.club-vaio.com
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\progra~1\google~1\BAE.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [NSUFloatingUI] "c:\program files\sony\network utility\LANUtil.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [<NO NAME>]
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: VESWinlogon - VESWinlogon.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsle4387db3;MpKsle4387db3;c:\programdata\microsoft\microsoft antimalware\definition updates\{8c473098-1d3a-43be-a768-0cbe3aedc503}\MpKsle4387db3.sys [2011-4-18 28752]
R2 NSUService;NSUService;c:\program files\sony\network utility\NSUService.exe [2011-4-14 229376]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-18 11032]
R2 RtkHDMIService;RtkHDMIService;c:\windows\RTKAUDIOSERVICE.EXE [2008-5-16 98304]
R2 uCamMonitor;CamMonitor;c:\program files\arcsoft\magic-i visual effects\uCamMonitor.exe [2011-4-14 104960]
R2 VAIO Power Management;VAIO Power Management;c:\program files\sony\vaio power management\SPMService.exe [2008-5-16 411488]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\drivers\ArcSoftKsUFilter.sys [2011-4-14 17408]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\drivers\NETw5v32.sys [2008-4-28 3658752]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2007-12-17 9344]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2008-5-16 28464]
S3 SOHCImp;VAIO Media plus Content Importer;c:\program files\sony\vaio media plus\SOHCImp.exe [2011-4-14 104288]
S3 SOHDms;VAIO Media plus Digital Media Server;c:\program files\sony\vaio media plus\SOHDms.exe [2011-4-14 350048]
S3 SOHDs;VAIO Media plus Device Searcher;c:\program files\sony\vaio media plus\SOHDs.exe [2011-4-14 63328]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\sony\vcm intelligent analyzing manager\VcmIAlzMgr.exe [2011-4-14 333088]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\common files\sony shared\vcmxml\VcmXmlIfHelper.exe [2011-4-14 87328]
S3 VUAgent;VUAgent;c:\program files\sony\vaio update 5\VUAgent.exe [2011-4-14 722288]
.
=============== Created Last 30 ================
.
2011-04-18 14:55:58 28752 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{8c473098-1d3a-43be-a768-0cbe3aedc503}\MpKsle4387db3.sys
2011-04-18 14:55:36 6792528 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{8c473098-1d3a-43be-a768-0cbe3aedc503}\mpengine.dll
2011-04-15 17:54:37 -------- d-----w- c:\windows\system32\Adobe
2011-04-15 17:25:26 -------- d-----w- c:\users\matt\Drivers & Installers
2011-04-15 16:43:31 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-04-15 16:43:31 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-04-15 16:43:31 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-04-15 16:43:31 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-04-15 16:43:31 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-04-15 16:40:32 -------- d-sh--w- c:\windows\system32\%APPDATA%
2011-04-15 16:40:19 231936 ----a-w- c:\windows\system32\msshsq.dll
2011-04-15 16:36:36 378368 ----a-w- c:\windows\system32\winhttp.dll
2011-04-15 16:36:31 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-04-14 18:33:16 -------- d-----w- c:\program files\Microsoft
2011-04-14 18:33:00 -------- d-----w- c:\program files\Windows Live SkyDrive
2011-04-14 18:32:27 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-04-14 18:28:26 484632 ----a-w- c:\program files\common files\windows live\.cache\be44d2641cbfad1\DXSETUP.exe
2011-04-14 18:28:25 74520 ----a-w- c:\program files\common files\windows live\.cache\be44d2641cbfad1\DSETUP.dll
2011-04-14 18:28:25 1670936 ----a-w- c:\program files\common files\windows live\.cache\be44d2641cbfad1\dsetup32.dll
2011-04-14 18:24:06 -------- d-----w- c:\program files\common files\Windows Live
2011-04-14 18:14:18 6792528 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-04-14 18:14:07 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-14 17:51:06 80896 ----a-w- c:\windows\system32\MSNP.ax
2011-04-14 17:51:06 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-04-14 17:51:02 293376 ----a-w- c:\windows\system32\psisdecd.dll
2011-04-14 17:51:01 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-04-14 17:41:12 454656 ----a-w- c:\program files\common files\system\msadc\msadce.dll
2011-04-14 17:36:59 7680 ----a-w- c:\program files\internet explorer\iecompat.dll
2011-04-14 17:34:58 293376 ----a-w- c:\windows\system32\browserchoice.exe
2011-04-14 17:32:36 -------- d-----w- c:\users\matt\appdata\local\Microsoft Help
2011-04-14 17:20:43 97800 ----a-w- c:\windows\system32\infocardapi.dll
2011-04-14 17:20:42 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2011-04-14 17:20:41 622080 ----a-w- c:\windows\system32\icardagt.exe
2011-04-14 17:20:41 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2011-04-14 17:20:41 11264 ----a-w- c:\windows\system32\icardres.dll
2011-04-14 17:20:39 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2011-04-14 17:15:36 158720 ----a-w- c:\windows\system32\mscorier.dll
2011-04-14 17:15:30 83968 ----a-w- c:\windows\system32\mscories.dll
2011-04-14 17:13:07 24064 ----a-w- c:\windows\system32\nshhttp.dll
2011-04-14 17:13:03 411136 ----a-w- c:\windows\system32\drivers\http.sys
2011-04-14 17:13:03 31232 ----a-w- c:\windows\system32\httpapi.dll
2011-04-14 17:12:17 -------- d-----w- c:\program files\MSXML 4.0
2011-04-14 16:46:08 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2011-04-14 16:46:05 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2011-04-14 16:45:57 801280 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2011-04-14 16:38:35 499200 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2011-04-14 16:37:43 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2011-04-14 16:36:56 310784 ----a-w- c:\windows\system32\unregmp2.exe
2011-04-14 16:35:58 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2011-04-14 16:34:20 866816 ----a-w- c:\windows\system32\wmpmde.dll
2011-04-14 16:34:18 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-04-14 16:34:14 24064 ----a-w- c:\windows\system32\amxread.dll
2011-04-14 16:34:14 13824 ----a-w- c:\windows\system32\apilogen.dll
2011-04-14 16:34:07 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2011-04-14 16:34:05 43520 ----a-w- c:\windows\system32\msdxm.tlb
2011-04-14 16:34:05 18432 ----a-w- c:\windows\system32\amcompat.tlb
2011-04-14 16:34:03 603648 ----a-w- c:\windows\system32\schedsvc.dll
2011-04-14 16:34:03 357376 ----a-w- c:\windows\system32\taskschd.dll
2011-04-14 16:34:02 345088 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-04-14 16:34:02 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-04-14 16:34:02 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-04-14 16:31:11 90112 ----a-w- c:\windows\system32\wshext.dll
2011-04-14 16:31:11 180224 ----a-w- c:\windows\system32\scrobj.dll
2011-04-14 16:31:11 172032 ----a-w- c:\windows\system32\scrrun.dll
2011-04-14 16:31:11 155648 ----a-w- c:\windows\system32\wscript.exe
2011-04-14 16:31:11 135168 ----a-w- c:\windows\system32\wshom.ocx
2011-04-14 16:31:11 135168 ----a-w- c:\windows\system32\cscript.exe
2011-04-14 16:27:10 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2011-04-14 16:27:10 31744 ----a-w- c:\windows\system32\msvidc32.dll
2011-04-14 16:27:10 22528 ----a-w- c:\windows\system32\msyuv.dll
2011-04-14 16:27:10 13312 ----a-w- c:\windows\system32\msrle32.dll
2011-04-14 16:27:10 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2011-04-14 16:27:09 91136 ----a-w- c:\windows\system32\avifil32.dll
2011-04-14 16:27:09 82944 ----a-w- c:\windows\system32\mciavi32.dll
2011-04-14 16:27:09 65024 ----a-w- c:\windows\system32\avicap32.dll
2011-04-14 16:27:09 123904 ----a-w- c:\windows\system32\msvfw32.dll
2011-04-14 16:27:06 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2011-04-14 16:23:25 171520 ----a-w- c:\windows\system32\wintrust.dll
2011-04-14 16:23:19 98304 ----a-w- c:\windows\system32\cabview.dll
2011-04-14 16:09:34 2421760 ----a-w- c:\windows\system32\wucltux.dll
2011-04-14 16:09:18 87552 ----a-w- c:\windows\system32\wudriver.dll
2011-04-14 16:09:11 33792 ----a-w- c:\windows\system32\wuapp.exe
2011-04-14 16:09:11 171608 ----a-w- c:\windows\system32\wuwebv.dll
2011-04-14 02:24:20 -------- d-----w- c:\progra~2\Roaming
2011-04-14 02:23:52 -------- d-----w- c:\program files\Cisco
2011-04-14 02:23:51 -------- d-----w- c:\program files\common files\Intel
2011-04-14 02:23:20 -------- d-----w- c:\program files\common files\InterVideo
2011-04-14 02:21:48 1645320 ----a-w- c:\windows\system32\gdiplus.dll
2011-04-14 02:21:38 -------- d-----w- C:\Documentation
2011-04-14 02:16:08 86016 ----a-w- c:\windows\system32\SonyAIwd.dll
2011-04-14 02:16:08 155648 ----a-w- c:\windows\system32\SonyAIwo.dll
2011-04-14 02:16:08 147456 ----a-w- c:\windows\system32\SonyAIds.dll
2011-04-14 02:14:44 -------- d-----w- c:\program files\common files\Sonic Shared
2011-04-14 02:10:24 212480 ----a-w- c:\windows\system32\PCDLIB32.DLL
2011-04-14 02:10:23 55808 ----a-w- c:\windows\system32\ArcSoftKsUFilter.dll
2011-04-14 02:10:23 245408 ----a-w- c:\windows\system32\unicows.dll
2011-04-14 02:10:23 17408 ----a-w- c:\windows\system32\drivers\ArcSoftKsUFilter.sys
2011-04-14 02:10:21 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2011-04-14 02:10:21 32768 ------w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2011-04-14 02:10:21 225280 ------w- c:\program files\common files\installshield\iscript\iscript.dll
2011-04-14 02:10:21 176128 ------w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2011-04-14 02:10:20 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2011-04-14 02:07:33 -------- d-----w- c:\program files\common files\PX Storage Engine
2011-04-14 02:07:18 -------- d-----w- c:\program files\DivX
2011-04-14 02:05:13 -------- d-----w- c:\program files\Google BAE
2011-04-14 02:03:55 -------- d-----w- c:\program files\ATI Technologies
2011-04-14 02:03:52 -------- d-----w- c:\program files\ATI
2011-04-14 01:56:03 129520 ------w- c:\windows\system32\pxafs.dll
2011-04-14 01:55:22 -------- d-----w- c:\progra~2\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2011-04-14 01:55:20 -------- d-----w- c:\program files\Activation Assistant for the 2007 Microsoft Office suites
2011-04-14 01:54:34 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
2011-04-14 01:54:34 32656 ----a-w- c:\windows\system32\msonpmon.dll
2011-04-14 01:53:55 -------- d-----w- c:\windows\PCHEALTH
2011-04-14 01:51:44 -------- d-----w- c:\windows\Sonysys
2011-04-13 20:17:30 -------- d-----w- c:\windows\pss
2011-04-13 19:26:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-04-13 19:26:25 -------- d-----w- c:\progra~2\Spybot - Search & Destroy
2011-04-13 19:23:45 -------- d-----w- c:\users\matt\appdata\roaming\Malwarebytes
2011-04-13 19:23:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-13 19:23:37 -------- d-----w- c:\progra~2\Malwarebytes
2011-04-13 19:23:33 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-13 19:23:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-13 19:22:12 -------- d-----w- c:\program files\CCleaner
2011-04-13 19:19:35 -------- d-----w- C:\Update
2011-04-13 19:18:51 439632 ------w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{a1f1fa77-e5fc-4f57-aec4-483044eaa31b}\gapaengine.dll
2011-04-13 19:04:39 -------- d-----w- c:\program files\Microsoft Security Client
2011-04-13 18:48:30 -------- d-----w- c:\users\matt\appdata\local\Sony_NSCE
2011-04-13 18:48:12 -------- d-----w- c:\users\matt\appdata\local\Google
2011-04-13 18:48:11 -------- d-----w- c:\users\matt\appdata\local\ATI
.
==================== Find3M ====================
.
2011-03-10 16:12:54 1161728 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-10 16:12:54 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-03-03 15:00:15 738816 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 12:53:48 2040832 ----a-w- c:\windows\system32\win32k.sys
2011-03-02 14:49:43 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-02-22 06:21:28 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 06:17:08 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 06:16:53 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 06:16:40 71680 ----a-w- c:\windows\system32\iesetup.dll
2011-02-22 06:16:40 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-02-22 05:20:39 385024 ----a-w- c:\windows\system32\html.iec
2011-02-22 04:43:54 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-02-22 04:42:38 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-02-16 15:29:56 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-02-16 13:24:56 292864 ----a-w- c:\windows\system32\atmfd.dll
.
============= FINISH: 16:34:57.74 ===============
Scan results
Click.GiftLoad: [SBI $89783858] User settings (Registry value, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION\svchost.exe
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2011-04-13 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2011-03-18 Includes\Adware.sbi (*)
2011-03-22 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-03-08 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2011-03-29 Includes\Hijackers.sbi (*)
2011-03-29 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2011-03-08 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2011-04-05 Includes\Malware.sbi (*)
2011-04-12 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2011-03-15 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2011-03-08 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2011-02-24 Includes\Spyware.sbi (*)
2011-03-15 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-12-28 Includes\Trojans.sbi (*)
2011-04-12 Includes\TrojansC-02.sbi (*)
2011-04-11 Includes\TrojansC-03.sbi (*)
2011-03-08 Includes\TrojansC-04.sbi (*)
2011-04-11 Includes\TrojansC-05.sbi (*)
2011-03-08 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll