PDA

View Full Version : Another click.giftload



JoshM94
2011-05-03, 22:16
Cannot get rid of click.giftload with SSD. Here is a DDS log:


.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Josh at 18:43:23.02 on 03/05/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Starter 6.1.7600.0.1252.44.1033.18.1013.132 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\system32\conhost.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
C:\Program Files\Oceanis\SystemSetting\WallPaperAgent.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\windows\Explorer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\windows\system32\conhost.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\windows\system32\igfxtray.exe
C:\windows\system32\igfxsrvc.exe
C:\windows\system32\igfxpers.exe
C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files\Samsung\SFB\SmartRestarter.exe
C:\windows\system32\igfxext.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\PROGRA~1\samsung\SAMSUN~3\SUPNOT~1.EXE
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\rundll32.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Josh\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Users\Josh\Downloads\dds.com
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://samsung.msn.com
uDefault_Page_URL = hxxp://samsung.msn.com
uInternet Settings,ProxyServer = 10.207.37.166:8080
uWinlogon: Shell=c:\program files\oceanis\systemsetting\WallPaperAgent.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [Google Update] "c:\users\josh\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 32464]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 296400]
R1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\drivers\SABI.sys [2010-11-12 10752]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-3-30 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 21968]
R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2011-3-30 297000]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2011-3-30 33320]
R3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [2010-11-13 109056]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2010-4-24 550760]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2010-4-24 195944]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2010-4-24 21864]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2010-4-24 19304]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2010-7-8 322336]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
.
=============== Created Last 30 ================
.
2011-05-03 06:03:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-05-03 06:03:00 -------- d-----w- c:\progra~2\Spybot - Search & Destroy
2011-05-02 21:12:14 26768 ----a-w- c:\windows\system\CTL3D.DLL
2011-05-02 21:12:14 247664 ----a-w- c:\windows\UNINST16.EXE
2011-04-27 12:41:10 -------- d-----w- c:\users\josh\appdata\local\{552805BB-3B73-4189-A8CF-7F2C5DDF9C18}
2011-04-25 16:13:14 -------- d-----w- c:\program files\SmartFTP Client
2011-04-25 16:10:47 -------- d-----w- c:\program files\SmartFTP Client 4.0 Setup Files
2011-04-25 15:26:04 -------- d-----w- c:\program files\common files\Steam
2011-04-25 15:25:34 -------- d-----w- c:\program files\Steam
2011-04-25 14:21:10 -------- d-----w- c:\users\josh\appdata\local\{6597CEDC-7386-485C-ABF4-6DF9F88323BC}
2011-04-24 10:22:04 -------- d-----w- C:\.jagex_cache_32
2011-04-23 18:45:55 -------- d-----w- c:\users\josh\appdata\local\{1DF57B73-1CAD-45B5-AB49-62ADE97EB4D0}
2011-04-21 18:58:55 -------- d-----w- c:\users\josh\appdata\local\{C095C838-85E0-4F7B-AB29-02FC8FF51C12}
2011-04-20 18:50:29 -------- d-----w- c:\users\josh\appdata\local\{E7BC8E2A-1069-4FEA-834B-A68EF540485E}
2011-04-18 14:34:07 -------- d-----w- c:\users\josh\appdata\local\{FC3CE3E1-F9D6-4B2F-A491-43CB14676890}
2011-04-18 10:11:12 -------- d-----w- c:\users\josh\appdata\local\{6F10FF9F-7B2C-480A-B30D-AFBB5B869BD5}
2011-04-15 11:21:15 -------- d-----w- c:\users\josh\appdata\local\{5DC852A6-ABCF-4D51-9FC0-0A6296451383}
2011-04-14 19:41:59 -------- d-----w- c:\users\josh\appdata\local\{1855264F-1847-41A4-B85D-1EA2D090114C}
2011-04-14 07:40:12 -------- d-----w- c:\users\josh\appdata\local\{04CCB43A-ADD6-4AAD-9B22-DC3D21D7D8A8}
2011-04-13 19:51:33 2331136 ----a-w- c:\windows\system32\win32k.sys
2011-04-13 19:51:32 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-13 19:51:30 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-13 19:51:28 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-13 19:51:25 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-13 19:51:25 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-04-13 19:51:22 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-13 19:51:22 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-13 19:51:22 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-13 19:51:21 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-13 19:38:31 -------- d-----w- c:\users\josh\appdata\local\{336D6D53-513B-475E-ADFB-348AE903DE1E}
2011-04-12 15:25:33 -------- d-----w- c:\users\josh\appdata\local\{5381F63C-3B32-4A81-80B2-D55B2DC9B61D}
2011-04-12 10:54:22 -------- d-----w- c:\users\josh\appdata\local\{B0C3EE01-57EE-4F6E-B9C8-B8BC04142C40}
2011-04-12 08:30:04 -------- d-----w- c:\users\josh\appdata\local\{9485AAA5-6080-47B3-B7EA-76E95FB1AE1C}
2011-04-11 17:13:08 -------- d-----w- c:\users\josh\appdata\local\{1B48D5FC-CFD4-4B57-B6C0-8CAD54FC8609}
2011-04-11 11:32:52 -------- d-----w- c:\users\josh\appdata\local\{A11115E6-05D4-4EF4-B378-71CB4341865B}
2011-04-11 10:18:09 -------- d-----w- c:\users\josh\appdata\local\{8AC26F55-9BD9-49AF-891D-E4ED3AAAA813}
2011-04-10 19:30:49 -------- d-----w- c:\users\josh\appdata\local\{44C869F3-ADAD-4F28-81A4-9A558E4D1C51}
2011-04-10 06:16:23 -------- d-----w- c:\users\josh\appdata\local\{FDD79B28-88C7-44DA-8239-B5B389656E07}
2011-04-09 19:22:39 -------- d-----w- c:\windows\system32\Adobe
2011-04-09 16:15:45 -------- d-----w- c:\users\josh\appdata\local\{7204D8CB-40EA-417C-A1E3-EFA2DAC2A130}
2011-04-08 17:20:04 -------- d-----w- c:\users\josh\appdata\local\{F1348E43-E96F-4E62-BF4D-246922E39DE7}
2011-04-08 10:23:11 -------- d-----w- c:\users\josh\appdata\local\{E1891852-CB2A-49FB-977B-7C0E09D8782C}
2011-04-07 21:42:09 -------- d-----w- c:\users\josh\appdata\local\{49510B45-F971-47B2-BD65-70C2E22A472A}
2011-04-07 12:06:49 -------- d-----w- c:\users\josh\appdata\local\{D96BC50B-FFAF-4331-BA04-F2CAC2C3D0FC}
2011-04-07 10:57:38 -------- d-----w- c:\users\josh\appdata\local\{4B9F5676-9C5B-41E2-BB72-3EDD93F79B8D}
2011-04-07 08:11:48 -------- d-----w- c:\users\josh\appdata\local\{8F7902E9-5E1E-49BD-BF8A-55DABE692D5E}
2011-04-05 13:10:51 -------- d-----w- c:\users\josh\appdata\local\{570E7D08-FEAB-4F83-B437-5764D03BD5A6}
2011-04-04 11:34:22 -------- d-----w- c:\users\josh\appdata\local\{5308B628-518A-456D-B1DB-5716F2982F93}
2011-04-04 10:17:25 -------- d-----w- c:\users\josh\appdata\local\{BE860F2F-B3C6-43F6-A22F-A5721D9B230D}
2011-04-04 07:54:34 -------- d-----w- c:\users\josh\appdata\local\{5B4E70C6-7689-46F7-B7C2-995AAB030CE5}
.
==================== Find3M ====================
.
2011-04-03 15:18:07 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-03-12 11:31:58 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2011-03-11 05:39:35 1686016 ----a-w- c:\windows\system32\esent.dll
2011-03-11 05:37:34 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-03-03 05:29:23 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 05:27:30 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-02-26 05:33:07 2614784 ----a-w- c:\windows\explorer.exe
2011-02-24 05:32:44 981504 ----a-w- c:\windows\system32\wininet.dll
2011-02-24 05:30:16 44544 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-24 04:23:48 386048 ----a-w- c:\windows\system32\html.iec
2011-02-24 03:50:26 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-02-19 23:03:12 4422992 ----a-w- c:\windows\mfc100u.dll
2011-02-19 22:03:12 64336 ----a-w- c:\windows\system32\mfc100fra.dll
2011-02-19 22:03:12 64336 ----a-w- c:\windows\system32\mfc100deu.dll
2011-02-19 22:03:12 63824 ----a-w- c:\windows\system32\mfc100esn.dll
2011-02-19 22:03:12 62288 ----a-w- c:\windows\system32\mfc100ita.dll
2011-02-19 22:03:12 60752 ----a-w- c:\windows\system32\mfc100rus.dll
2011-02-19 22:03:12 55120 ----a-w- c:\windows\system32\mfc100enu.dll
2011-02-19 22:03:12 43856 ----a-w- c:\windows\system32\mfc100jpn.dll
2011-02-19 22:03:12 43344 ----a-w- c:\windows\system32\mfc100kor.dll
2011-02-19 22:03:12 421200 ----a-w- c:\windows\system32\msvcp100.dll
2011-02-19 22:03:12 36176 ----a-w- c:\windows\system32\mfc100cht.dll
2011-02-19 22:03:12 36176 ----a-w- c:\windows\system32\mfc100chs.dll
2011-02-19 05:33:11 802304 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 05:32:48 1074176 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 05:32:35 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 05:32:08 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-02-19 03:37:02 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-02-18 23:40:50 773968 ----a-w- c:\windows\system32\msvcr100.dll
2011-02-18 05:36:26 428032 ----a-w- c:\windows\system32\vbscript.dll
2011-02-18 05:33:29 31232 ----a-w- c:\windows\system32\prevhost.exe
.
============= FINISH: 18:45:59.03 ===============

Bumpity bump.


FYI: Bump and Topic May Be Closed (http://forums.spybot.info/showpost.php?p=219168&postcount=6)

Blade81
2011-05-12, 15:57
Hello,

If help still needed post fresh dds logs.

Blade81
2011-05-18, 17:43
Due to inactivity, this thread will now be closed.

Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.