JoshM94
2011-05-03, 22:16
Cannot get rid of click.giftload with SSD. Here is a DDS log:
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Josh at 18:43:23.02 on 03/05/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Starter 6.1.7600.0.1252.44.1033.18.1013.132 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\system32\conhost.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\windows\Explorer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\windows\system32\conhost.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\windows\system32\igfxtray.exe
C:\windows\system32\igfxsrvc.exe
C:\windows\system32\igfxpers.exe
C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files\Samsung\SFB\SmartRestarter.exe
C:\windows\system32\igfxext.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\PROGRA~1\samsung\SAMSUN~3\SUPNOT~1.EXE
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\rundll32.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Users\Josh\Downloads\dds.com
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://samsung.msn.com
uDefault_Page_URL = hxxp://samsung.msn.com
uInternet Settings,ProxyServer = 10.207.37.166:8080
uWinlogon: Shell=c:\program files\oceanis\systemsetting\WallPaperAgent.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [Google Update] "c:\users\josh\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 32464]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 296400]
R1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\drivers\SABI.sys [2010-11-12 10752]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-3-30 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 21968]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2011-3-30 297000]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2011-3-30 33320]
R3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [2010-11-13 109056]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2010-4-24 550760]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2010-4-24 195944]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2010-4-24 21864]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2010-4-24 19304]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2010-7-8 322336]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
.
=============== Created Last 30 ================
.
2011-05-03 06:03:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-05-03 06:03:00 -------- d-----w- c:\progra~2\Spybot - Search & Destroy
2011-05-02 21:12:14 26768 ----a-w- c:\windows\system\CTL3D.DLL
2011-05-02 21:12:14 247664 ----a-w- c:\windows\UNINST16.EXE
2011-04-27 12:41:10 -------- d-----w- c:\users\josh\appdata\local\{552805BB-3B73-4189-A8CF-7F2C5DDF9C18}
2011-04-25 16:13:14 -------- d-----w- c:\program files\SmartFTP Client
2011-04-25 16:10:47 -------- d-----w- c:\program files\SmartFTP Client 4.0 Setup Files
2011-04-25 15:26:04 -------- d-----w- c:\program files\common files\Steam
2011-04-25 15:25:34 -------- d-----w- c:\program files\Steam
2011-04-25 14:21:10 -------- d-----w- c:\users\josh\appdata\local\{6597CEDC-7386-485C-ABF4-6DF9F88323BC}
2011-04-24 10:22:04 -------- d-----w- C:\.jagex_cache_32
2011-04-23 18:45:55 -------- d-----w- c:\users\josh\appdata\local\{1DF57B73-1CAD-45B5-AB49-62ADE97EB4D0}
2011-04-21 18:58:55 -------- d-----w- c:\users\josh\appdata\local\{C095C838-85E0-4F7B-AB29-02FC8FF51C12}
2011-04-20 18:50:29 -------- d-----w- c:\users\josh\appdata\local\{E7BC8E2A-1069-4FEA-834B-A68EF540485E}
2011-04-18 14:34:07 -------- d-----w- c:\users\josh\appdata\local\{FC3CE3E1-F9D6-4B2F-A491-43CB14676890}
2011-04-18 10:11:12 -------- d-----w- c:\users\josh\appdata\local\{6F10FF9F-7B2C-480A-B30D-AFBB5B869BD5}
2011-04-15 11:21:15 -------- d-----w- c:\users\josh\appdata\local\{5DC852A6-ABCF-4D51-9FC0-0A6296451383}
2011-04-14 19:41:59 -------- d-----w- c:\users\josh\appdata\local\{1855264F-1847-41A4-B85D-1EA2D090114C}
2011-04-14 07:40:12 -------- d-----w- c:\users\josh\appdata\local\{04CCB43A-ADD6-4AAD-9B22-DC3D21D7D8A8}
2011-04-13 19:51:33 2331136 ----a-w- c:\windows\system32\win32k.sys
2011-04-13 19:51:32 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-13 19:51:30 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-13 19:51:28 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-13 19:51:25 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-13 19:51:25 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-04-13 19:51:22 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-13 19:51:22 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-13 19:51:22 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-13 19:51:21 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-13 19:38:31 -------- d-----w- c:\users\josh\appdata\local\{336D6D53-513B-475E-ADFB-348AE903DE1E}
2011-04-12 15:25:33 -------- d-----w- c:\users\josh\appdata\local\{5381F63C-3B32-4A81-80B2-D55B2DC9B61D}
2011-04-12 10:54:22 -------- d-----w- c:\users\josh\appdata\local\{B0C3EE01-57EE-4F6E-B9C8-B8BC04142C40}
2011-04-12 08:30:04 -------- d-----w- c:\users\josh\appdata\local\{9485AAA5-6080-47B3-B7EA-76E95FB1AE1C}
2011-04-11 17:13:08 -------- d-----w- c:\users\josh\appdata\local\{1B48D5FC-CFD4-4B57-B6C0-8CAD54FC8609}
2011-04-11 11:32:52 -------- d-----w- c:\users\josh\appdata\local\{A11115E6-05D4-4EF4-B378-71CB4341865B}
2011-04-11 10:18:09 -------- d-----w- c:\users\josh\appdata\local\{8AC26F55-9BD9-49AF-891D-E4ED3AAAA813}
2011-04-10 19:30:49 -------- d-----w- c:\users\josh\appdata\local\{44C869F3-ADAD-4F28-81A4-9A558E4D1C51}
2011-04-10 06:16:23 -------- d-----w- c:\users\josh\appdata\local\{FDD79B28-88C7-44DA-8239-B5B389656E07}
2011-04-09 19:22:39 -------- d-----w- c:\windows\system32\Adobe
2011-04-09 16:15:45 -------- d-----w- c:\users\josh\appdata\local\{7204D8CB-40EA-417C-A1E3-EFA2DAC2A130}
2011-04-08 17:20:04 -------- d-----w- c:\users\josh\appdata\local\{F1348E43-E96F-4E62-BF4D-246922E39DE7}
2011-04-08 10:23:11 -------- d-----w- c:\users\josh\appdata\local\{E1891852-CB2A-49FB-977B-7C0E09D8782C}
2011-04-07 21:42:09 -------- d-----w- c:\users\josh\appdata\local\{49510B45-F971-47B2-BD65-70C2E22A472A}
2011-04-07 12:06:49 -------- d-----w- c:\users\josh\appdata\local\{D96BC50B-FFAF-4331-BA04-F2CAC2C3D0FC}
2011-04-07 10:57:38 -------- d-----w- c:\users\josh\appdata\local\{4B9F5676-9C5B-41E2-BB72-3EDD93F79B8D}
2011-04-07 08:11:48 -------- d-----w- c:\users\josh\appdata\local\{8F7902E9-5E1E-49BD-BF8A-55DABE692D5E}
2011-04-05 13:10:51 -------- d-----w- c:\users\josh\appdata\local\{570E7D08-FEAB-4F83-B437-5764D03BD5A6}
2011-04-04 11:34:22 -------- d-----w- c:\users\josh\appdata\local\{5308B628-518A-456D-B1DB-5716F2982F93}
2011-04-04 10:17:25 -------- d-----w- c:\users\josh\appdata\local\{BE860F2F-B3C6-43F6-A22F-A5721D9B230D}
2011-04-04 07:54:34 -------- d-----w- c:\users\josh\appdata\local\{5B4E70C6-7689-46F7-B7C2-995AAB030CE5}
.
==================== Find3M ====================
.
2011-04-03 15:18:07 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-03-12 11:31:58 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2011-03-11 05:39:35 1686016 ----a-w- c:\windows\system32\esent.dll
2011-03-11 05:37:34 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-03-03 05:29:23 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 05:27:30 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-02-26 05:33:07 2614784 ----a-w- c:\windows\explorer.exe
2011-02-24 05:32:44 981504 ----a-w- c:\windows\system32\wininet.dll
2011-02-24 05:30:16 44544 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-24 04:23:48 386048 ----a-w- c:\windows\system32\html.iec
2011-02-24 03:50:26 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-02-19 23:03:12 4422992 ----a-w- c:\windows\mfc100u.dll
2011-02-19 22:03:12 64336 ----a-w- c:\windows\system32\mfc100fra.dll
2011-02-19 22:03:12 64336 ----a-w- c:\windows\system32\mfc100deu.dll
2011-02-19 22:03:12 63824 ----a-w- c:\windows\system32\mfc100esn.dll
2011-02-19 22:03:12 62288 ----a-w- c:\windows\system32\mfc100ita.dll
2011-02-19 22:03:12 60752 ----a-w- c:\windows\system32\mfc100rus.dll
2011-02-19 22:03:12 55120 ----a-w- c:\windows\system32\mfc100enu.dll
2011-02-19 22:03:12 43856 ----a-w- c:\windows\system32\mfc100jpn.dll
2011-02-19 22:03:12 43344 ----a-w- c:\windows\system32\mfc100kor.dll
2011-02-19 22:03:12 421200 ----a-w- c:\windows\system32\msvcp100.dll
2011-02-19 22:03:12 36176 ----a-w- c:\windows\system32\mfc100cht.dll
2011-02-19 22:03:12 36176 ----a-w- c:\windows\system32\mfc100chs.dll
2011-02-19 05:33:11 802304 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 05:32:48 1074176 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 05:32:35 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 05:32:08 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-02-19 03:37:02 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-02-18 23:40:50 773968 ----a-w- c:\windows\system32\msvcr100.dll
2011-02-18 05:36:26 428032 ----a-w- c:\windows\system32\vbscript.dll
2011-02-18 05:33:29 31232 ----a-w- c:\windows\system32\prevhost.exe
.
============= FINISH: 18:45:59.03 ===============
Bumpity bump.
FYI: Bump and Topic May Be Closed (http://forums.spybot.info/showpost.php?p=219168&postcount=6)
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Josh at 18:43:23.02 on 03/05/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Starter 6.1.7600.0.1252.44.1033.18.1013.132 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\system32\conhost.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\windows\Explorer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\windows\system32\conhost.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\windows\system32\igfxtray.exe
C:\windows\system32\igfxsrvc.exe
C:\windows\system32\igfxpers.exe
C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files\Samsung\SFB\SmartRestarter.exe
C:\windows\system32\igfxext.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\PROGRA~1\samsung\SAMSUN~3\SUPNOT~1.EXE
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\rundll32.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Users\Josh\Downloads\dds.com
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://samsung.msn.com
uDefault_Page_URL = hxxp://samsung.msn.com
uInternet Settings,ProxyServer = 10.207.37.166:8080
uWinlogon: Shell=c:\program files\oceanis\systemsetting\WallPaperAgent.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [Google Update] "c:\users\josh\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 32464]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 296400]
R1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\drivers\SABI.sys [2010-11-12 10752]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-3-30 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 21968]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2011-3-30 297000]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2011-3-30 33320]
R3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [2010-11-13 109056]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2010-4-24 550760]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2010-4-24 195944]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2010-4-24 21864]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2010-4-24 19304]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2010-7-8 322336]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
.
=============== Created Last 30 ================
.
2011-05-03 06:03:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-05-03 06:03:00 -------- d-----w- c:\progra~2\Spybot - Search & Destroy
2011-05-02 21:12:14 26768 ----a-w- c:\windows\system\CTL3D.DLL
2011-05-02 21:12:14 247664 ----a-w- c:\windows\UNINST16.EXE
2011-04-27 12:41:10 -------- d-----w- c:\users\josh\appdata\local\{552805BB-3B73-4189-A8CF-7F2C5DDF9C18}
2011-04-25 16:13:14 -------- d-----w- c:\program files\SmartFTP Client
2011-04-25 16:10:47 -------- d-----w- c:\program files\SmartFTP Client 4.0 Setup Files
2011-04-25 15:26:04 -------- d-----w- c:\program files\common files\Steam
2011-04-25 15:25:34 -------- d-----w- c:\program files\Steam
2011-04-25 14:21:10 -------- d-----w- c:\users\josh\appdata\local\{6597CEDC-7386-485C-ABF4-6DF9F88323BC}
2011-04-24 10:22:04 -------- d-----w- C:\.jagex_cache_32
2011-04-23 18:45:55 -------- d-----w- c:\users\josh\appdata\local\{1DF57B73-1CAD-45B5-AB49-62ADE97EB4D0}
2011-04-21 18:58:55 -------- d-----w- c:\users\josh\appdata\local\{C095C838-85E0-4F7B-AB29-02FC8FF51C12}
2011-04-20 18:50:29 -------- d-----w- c:\users\josh\appdata\local\{E7BC8E2A-1069-4FEA-834B-A68EF540485E}
2011-04-18 14:34:07 -------- d-----w- c:\users\josh\appdata\local\{FC3CE3E1-F9D6-4B2F-A491-43CB14676890}
2011-04-18 10:11:12 -------- d-----w- c:\users\josh\appdata\local\{6F10FF9F-7B2C-480A-B30D-AFBB5B869BD5}
2011-04-15 11:21:15 -------- d-----w- c:\users\josh\appdata\local\{5DC852A6-ABCF-4D51-9FC0-0A6296451383}
2011-04-14 19:41:59 -------- d-----w- c:\users\josh\appdata\local\{1855264F-1847-41A4-B85D-1EA2D090114C}
2011-04-14 07:40:12 -------- d-----w- c:\users\josh\appdata\local\{04CCB43A-ADD6-4AAD-9B22-DC3D21D7D8A8}
2011-04-13 19:51:33 2331136 ----a-w- c:\windows\system32\win32k.sys
2011-04-13 19:51:32 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-13 19:51:30 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-13 19:51:28 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-13 19:51:25 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-13 19:51:25 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-04-13 19:51:22 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-13 19:51:22 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-13 19:51:22 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-13 19:51:21 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-13 19:38:31 -------- d-----w- c:\users\josh\appdata\local\{336D6D53-513B-475E-ADFB-348AE903DE1E}
2011-04-12 15:25:33 -------- d-----w- c:\users\josh\appdata\local\{5381F63C-3B32-4A81-80B2-D55B2DC9B61D}
2011-04-12 10:54:22 -------- d-----w- c:\users\josh\appdata\local\{B0C3EE01-57EE-4F6E-B9C8-B8BC04142C40}
2011-04-12 08:30:04 -------- d-----w- c:\users\josh\appdata\local\{9485AAA5-6080-47B3-B7EA-76E95FB1AE1C}
2011-04-11 17:13:08 -------- d-----w- c:\users\josh\appdata\local\{1B48D5FC-CFD4-4B57-B6C0-8CAD54FC8609}
2011-04-11 11:32:52 -------- d-----w- c:\users\josh\appdata\local\{A11115E6-05D4-4EF4-B378-71CB4341865B}
2011-04-11 10:18:09 -------- d-----w- c:\users\josh\appdata\local\{8AC26F55-9BD9-49AF-891D-E4ED3AAAA813}
2011-04-10 19:30:49 -------- d-----w- c:\users\josh\appdata\local\{44C869F3-ADAD-4F28-81A4-9A558E4D1C51}
2011-04-10 06:16:23 -------- d-----w- c:\users\josh\appdata\local\{FDD79B28-88C7-44DA-8239-B5B389656E07}
2011-04-09 19:22:39 -------- d-----w- c:\windows\system32\Adobe
2011-04-09 16:15:45 -------- d-----w- c:\users\josh\appdata\local\{7204D8CB-40EA-417C-A1E3-EFA2DAC2A130}
2011-04-08 17:20:04 -------- d-----w- c:\users\josh\appdata\local\{F1348E43-E96F-4E62-BF4D-246922E39DE7}
2011-04-08 10:23:11 -------- d-----w- c:\users\josh\appdata\local\{E1891852-CB2A-49FB-977B-7C0E09D8782C}
2011-04-07 21:42:09 -------- d-----w- c:\users\josh\appdata\local\{49510B45-F971-47B2-BD65-70C2E22A472A}
2011-04-07 12:06:49 -------- d-----w- c:\users\josh\appdata\local\{D96BC50B-FFAF-4331-BA04-F2CAC2C3D0FC}
2011-04-07 10:57:38 -------- d-----w- c:\users\josh\appdata\local\{4B9F5676-9C5B-41E2-BB72-3EDD93F79B8D}
2011-04-07 08:11:48 -------- d-----w- c:\users\josh\appdata\local\{8F7902E9-5E1E-49BD-BF8A-55DABE692D5E}
2011-04-05 13:10:51 -------- d-----w- c:\users\josh\appdata\local\{570E7D08-FEAB-4F83-B437-5764D03BD5A6}
2011-04-04 11:34:22 -------- d-----w- c:\users\josh\appdata\local\{5308B628-518A-456D-B1DB-5716F2982F93}
2011-04-04 10:17:25 -------- d-----w- c:\users\josh\appdata\local\{BE860F2F-B3C6-43F6-A22F-A5721D9B230D}
2011-04-04 07:54:34 -------- d-----w- c:\users\josh\appdata\local\{5B4E70C6-7689-46F7-B7C2-995AAB030CE5}
.
==================== Find3M ====================
.
2011-04-03 15:18:07 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-03-12 11:31:58 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2011-03-11 05:39:35 1686016 ----a-w- c:\windows\system32\esent.dll
2011-03-11 05:37:34 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-03-03 05:29:23 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 05:27:30 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-02-26 05:33:07 2614784 ----a-w- c:\windows\explorer.exe
2011-02-24 05:32:44 981504 ----a-w- c:\windows\system32\wininet.dll
2011-02-24 05:30:16 44544 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-24 04:23:48 386048 ----a-w- c:\windows\system32\html.iec
2011-02-24 03:50:26 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-02-19 23:03:12 4422992 ----a-w- c:\windows\mfc100u.dll
2011-02-19 22:03:12 64336 ----a-w- c:\windows\system32\mfc100fra.dll
2011-02-19 22:03:12 64336 ----a-w- c:\windows\system32\mfc100deu.dll
2011-02-19 22:03:12 63824 ----a-w- c:\windows\system32\mfc100esn.dll
2011-02-19 22:03:12 62288 ----a-w- c:\windows\system32\mfc100ita.dll
2011-02-19 22:03:12 60752 ----a-w- c:\windows\system32\mfc100rus.dll
2011-02-19 22:03:12 55120 ----a-w- c:\windows\system32\mfc100enu.dll
2011-02-19 22:03:12 43856 ----a-w- c:\windows\system32\mfc100jpn.dll
2011-02-19 22:03:12 43344 ----a-w- c:\windows\system32\mfc100kor.dll
2011-02-19 22:03:12 421200 ----a-w- c:\windows\system32\msvcp100.dll
2011-02-19 22:03:12 36176 ----a-w- c:\windows\system32\mfc100cht.dll
2011-02-19 22:03:12 36176 ----a-w- c:\windows\system32\mfc100chs.dll
2011-02-19 05:33:11 802304 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 05:32:48 1074176 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 05:32:35 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 05:32:08 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-02-19 03:37:02 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-02-18 23:40:50 773968 ----a-w- c:\windows\system32\msvcr100.dll
2011-02-18 05:36:26 428032 ----a-w- c:\windows\system32\vbscript.dll
2011-02-18 05:33:29 31232 ----a-w- c:\windows\system32\prevhost.exe
.
============= FINISH: 18:45:59.03 ===============
Bumpity bump.
FYI: Bump and Topic May Be Closed (http://forums.spybot.info/showpost.php?p=219168&postcount=6)