alsbot
2011-06-10, 21:12
Hi,
About a month ago I started having this problem. Almost every time I click a link from a google search it redirects me to a different page instead of the page I clicked on. I have been getting around this by just copying the link directly into the url bar. I usually use chrome but it happens when I use internet explorer also. I don't know what could have caused the problem; I don't think I visited any creepy sites or ran anything blatantly bad.
I ran a full scan of malwarebytes and nothing came up. Then I tried kaspersky rescue disk 2010 and nothing came up at all. Again with Spybot nothing unusual came up. And with TDSSkiller nothing came up.
When it redirects me it usually goes to scour.com or different fake anti-virus sites.
I have windows 7 32 bit.
Thanks for your help
DDS:
.
DDS (Ver_2011-06-03.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Alyssa at 12:06:31 on 2011-06-10
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2038.906 [GMT -6:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\AsusService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\windows\System32\svchost.exe -k HPZ12
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\windows\System32\svchost.exe -k HPZ12
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Windows\AsScrPro.exe
C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\EeePC\CapsHook\CapsHook.exe
C:\Program Files\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DAEMON Tools\DTLite.exe
C:\Users\Alyssa\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\windows\system32\SearchIndexer.exe
C:\Users\Alyssa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\Alyssa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\rundll32.exe
C:\Users\Alyssa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alyssa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\taskeng.exe
C:\Users\Alyssa\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\Alyssa\AppData\Local\Google\Update\GoogleUpdate.exe
C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\windows\system32\sppsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\taskhost.exe
C:\Users\Alyssa\AppData\Local\Google\Update\Install\{CCF4C376-B71B-40B6-A232-5172382910F9}\chrome_updater.exe
C:\Users\Alyssa\AppData\Local\Temp\CR_E1450.tmp\setup.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://asus.msn.com
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools\DTLite.exe" -autorun
uRun: [SansaDispatch] c:\users\alyssa\appdata\roaming\sandisk\sansa updater\SansaDispatch.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Google Update] "c:\users\alyssa\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
mRun: [ASUS Screen Saver Protector] c:\windows\AsScrPro.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0"
mRun: [HotkeyMon] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotKeyMon.exe
mRun: [HotkeyService] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotkeyService.exe
mRun: [SuperHybridEngine] AsusSender.exe c:\program files\eeepc\she\SuperHybridEngine.exe
mRun: [LiveUpdate] AsusSender.exe c:\program files\asus\liveupdate\LiveUpdate.exe auto
mRun: [CapsHook] AsusSender.exe c:\program files\eeepc\capshook\CapsHook.exe
mRun: [Eee Docking] c:\program files\asus\eee docking\Eee Docking.exe autorun
mRun: [ASUS WebStorage] c:\program files\asus\asus webstorage\service\AsusWSService.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [OOBESetup] c:\program files\asus\ooberegbackup\ooberegbackup.exe /restore -"c:\program files\asus\ooberegbackup\OOBEReg.ini"
mRun: [Boingo Wi-Fi] "c:\program files\boingo\boingo wi-fi\Boingo.lnk"
mRun: [ASUSPRP] c:\program files\asus\aprp\APRP.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\alyssa\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{0A8AA83C-B92B-4DBE-9470-69B093A37B1E} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{0A8AA83C-B92B-4DBE-9470-69B093A37B1E}\157756374775966496 : DhcpNameServer = 192.168.9.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{0A8AA83C-B92B-4DBE-9470-69B093A37B1E}\45869637D416368696E656 : DhcpNameServer = 68.87.85.102 68.87.69.150
TCP: Interfaces\{0A8AA83C-B92B-4DBE-9470-69B093A37B1E}\66F627564586F6577686470284F6473707F647 : DhcpNameServer = 192.168.30.2 192.168.31.2
TCP: Interfaces\{0A8AA83C-B92B-4DBE-9470-69B093A37B1E}\C696E6B6379737F5353484 : DhcpNameServer = 68.87.85.102 68.87.69.150
TCP: Interfaces\{99D99479-53FF-461A-BCC8-D80652D0FF75} : DhcpNameServer = 10.0.96.10 205.171.3.65 205.171.2.65
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\aibelive\voice command\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\nvinit.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nvpciflt;nvpciflt;c:\windows\system32\drivers\nvpciflt.sys [2010-7-12 19656]
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-6-24 11448]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AsusService;Asus Launcher Service;c:\windows\system32\AsusService.exe [2010-6-24 219136]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2010-9-19 1616488]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\drivers\L1C62x86.sys [2010-6-21 68208]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-5-17 1153368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-11-1 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-6-22 68200]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-7 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-9-15 1343400]
.
=============== Created Last 30 ================
.
2011-06-09 02:08:10 388096 ----a-r- c:\users\alyssa\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-06-09 02:08:10 -------- d-----w- c:\program files\Trend Micro
2011-06-07 14:17:11 -------- d-----w- c:\windows\system32\SPReview
2011-06-07 14:15:31 -------- d-----w- c:\windows\system32\EventProviders
2011-06-07 13:59:59 9166336 ----a-w- c:\program files\dvd maker\OmdBase.dll
2011-06-07 13:58:58 97280 ----a-w- c:\windows\system32\dwmredir.dll
2011-06-07 13:57:27 780288 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-07 13:57:27 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-06-07 13:57:27 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2011-06-07 13:57:27 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-07 13:57:19 697344 ----a-w- c:\windows\system32\SmiEngine.dll
2011-06-07 13:57:12 209920 ----a-w- c:\windows\system32\PkgMgr.exe
2011-06-07 13:57:12 189952 ----a-w- c:\windows\system32\wdscore.dll
2011-06-07 13:56:39 323072 ----a-w- c:\windows\system32\drvstore.dll
2011-06-07 13:56:39 257024 ----a-w- c:\windows\system32\dpx.dll
2011-06-06 19:17:20 -------- d-----w- C:\$RECYCLE.BIN
2011-06-06 19:15:23 -------- d-----w- c:\users\alyssa\appdata\local\temp
2011-06-06 19:03:39 98816 ----a-w- c:\windows\sed.exe
2011-06-06 19:03:39 518144 ----a-w- c:\windows\SWREG.exe
2011-06-06 19:03:39 256512 ----a-w- c:\windows\PEV.exe
2011-06-06 19:03:39 208896 ----a-w- c:\windows\MBR.exe
2011-06-06 10:11:50 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2011-05-25 13:57:12 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-18 17:46:49 -------- d-----w- c:\users\alyssa\appdata\local\ElevatedDiagnostics
2011-05-18 17:32:29 -------- d-----w- c:\program files\Microsoft Security Client
2011-05-18 17:14:33 219136 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-05-18 17:14:33 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-05-18 17:14:23 123904 ----a-w- c:\windows\system32\poqexec.exe
2011-05-18 00:39:37 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-05-18 00:39:37 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-05-11 19:00:54 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-11 19:00:53 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
.
==================== Find3M ====================
.
2011-06-07 14:27:09 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-05-04 10:52:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-09 05:02:04 390656 ----a-w- c:\windows\system32\ipcoin815.dll
.
============= FINISH: 12:09:06.65 ===============
About a month ago I started having this problem. Almost every time I click a link from a google search it redirects me to a different page instead of the page I clicked on. I have been getting around this by just copying the link directly into the url bar. I usually use chrome but it happens when I use internet explorer also. I don't know what could have caused the problem; I don't think I visited any creepy sites or ran anything blatantly bad.
I ran a full scan of malwarebytes and nothing came up. Then I tried kaspersky rescue disk 2010 and nothing came up at all. Again with Spybot nothing unusual came up. And with TDSSkiller nothing came up.
When it redirects me it usually goes to scour.com or different fake anti-virus sites.
I have windows 7 32 bit.
Thanks for your help
DDS:
.
DDS (Ver_2011-06-03.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Alyssa at 12:06:31 on 2011-06-10
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2038.906 [GMT -6:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\AsusService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\windows\System32\svchost.exe -k HPZ12
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\windows\System32\svchost.exe -k HPZ12
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\Windows\AsScrPro.exe
C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\EeePC\CapsHook\CapsHook.exe
C:\Program Files\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DAEMON Tools\DTLite.exe
C:\Users\Alyssa\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\windows\system32\SearchIndexer.exe
C:\Users\Alyssa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\Alyssa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\rundll32.exe
C:\Users\Alyssa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Alyssa\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\taskeng.exe
C:\Users\Alyssa\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\Alyssa\AppData\Local\Google\Update\GoogleUpdate.exe
C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\windows\system32\sppsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\taskhost.exe
C:\Users\Alyssa\AppData\Local\Google\Update\Install\{CCF4C376-B71B-40B6-A232-5172382910F9}\chrome_updater.exe
C:\Users\Alyssa\AppData\Local\Temp\CR_E1450.tmp\setup.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://asus.msn.com
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools\DTLite.exe" -autorun
uRun: [SansaDispatch] c:\users\alyssa\appdata\roaming\sandisk\sansa updater\SansaDispatch.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Google Update] "c:\users\alyssa\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
mRun: [ASUS Screen Saver Protector] c:\windows\AsScrPro.exe
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0"
mRun: [HotkeyMon] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotKeyMon.exe
mRun: [HotkeyService] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotkeyService.exe
mRun: [SuperHybridEngine] AsusSender.exe c:\program files\eeepc\she\SuperHybridEngine.exe
mRun: [LiveUpdate] AsusSender.exe c:\program files\asus\liveupdate\LiveUpdate.exe auto
mRun: [CapsHook] AsusSender.exe c:\program files\eeepc\capshook\CapsHook.exe
mRun: [Eee Docking] c:\program files\asus\eee docking\Eee Docking.exe autorun
mRun: [ASUS WebStorage] c:\program files\asus\asus webstorage\service\AsusWSService.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [OOBESetup] c:\program files\asus\ooberegbackup\ooberegbackup.exe /restore -"c:\program files\asus\ooberegbackup\OOBEReg.ini"
mRun: [Boingo Wi-Fi] "c:\program files\boingo\boingo wi-fi\Boingo.lnk"
mRun: [ASUSPRP] c:\program files\asus\aprp\APRP.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\alyssa\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{0A8AA83C-B92B-4DBE-9470-69B093A37B1E} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{0A8AA83C-B92B-4DBE-9470-69B093A37B1E}\157756374775966496 : DhcpNameServer = 192.168.9.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{0A8AA83C-B92B-4DBE-9470-69B093A37B1E}\45869637D416368696E656 : DhcpNameServer = 68.87.85.102 68.87.69.150
TCP: Interfaces\{0A8AA83C-B92B-4DBE-9470-69B093A37B1E}\66F627564586F6577686470284F6473707F647 : DhcpNameServer = 192.168.30.2 192.168.31.2
TCP: Interfaces\{0A8AA83C-B92B-4DBE-9470-69B093A37B1E}\C696E6B6379737F5353484 : DhcpNameServer = 68.87.85.102 68.87.69.150
TCP: Interfaces\{99D99479-53FF-461A-BCC8-D80652D0FF75} : DhcpNameServer = 10.0.96.10 205.171.3.65 205.171.2.65
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\aibelive\voice command\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\nvinit.dll
.
============= SERVICES / DRIVERS ===============
.
R0 nvpciflt;nvpciflt;c:\windows\system32\drivers\nvpciflt.sys [2010-7-12 19656]
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-6-24 11448]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AsusService;Asus Launcher Service;c:\windows\system32\AsusService.exe [2010-6-24 219136]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2010-9-19 1616488]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\drivers\L1C62x86.sys [2010-6-21 68208]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-5-17 1153368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-11-1 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-6-22 68200]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-7 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-9-15 1343400]
.
=============== Created Last 30 ================
.
2011-06-09 02:08:10 388096 ----a-r- c:\users\alyssa\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-06-09 02:08:10 -------- d-----w- c:\program files\Trend Micro
2011-06-07 14:17:11 -------- d-----w- c:\windows\system32\SPReview
2011-06-07 14:15:31 -------- d-----w- c:\windows\system32\EventProviders
2011-06-07 13:59:59 9166336 ----a-w- c:\program files\dvd maker\OmdBase.dll
2011-06-07 13:58:58 97280 ----a-w- c:\windows\system32\dwmredir.dll
2011-06-07 13:57:27 780288 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-07 13:57:27 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2011-06-07 13:57:27 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2011-06-07 13:57:27 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-06-07 13:57:19 697344 ----a-w- c:\windows\system32\SmiEngine.dll
2011-06-07 13:57:12 209920 ----a-w- c:\windows\system32\PkgMgr.exe
2011-06-07 13:57:12 189952 ----a-w- c:\windows\system32\wdscore.dll
2011-06-07 13:56:39 323072 ----a-w- c:\windows\system32\drvstore.dll
2011-06-07 13:56:39 257024 ----a-w- c:\windows\system32\dpx.dll
2011-06-06 19:17:20 -------- d-----w- C:\$RECYCLE.BIN
2011-06-06 19:15:23 -------- d-----w- c:\users\alyssa\appdata\local\temp
2011-06-06 19:03:39 98816 ----a-w- c:\windows\sed.exe
2011-06-06 19:03:39 518144 ----a-w- c:\windows\SWREG.exe
2011-06-06 19:03:39 256512 ----a-w- c:\windows\PEV.exe
2011-06-06 19:03:39 208896 ----a-w- c:\windows\MBR.exe
2011-06-06 10:11:50 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2011-05-25 13:57:12 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-05-18 17:46:49 -------- d-----w- c:\users\alyssa\appdata\local\ElevatedDiagnostics
2011-05-18 17:32:29 -------- d-----w- c:\program files\Microsoft Security Client
2011-05-18 17:14:33 219136 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-05-18 17:14:33 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-05-18 17:14:23 123904 ----a-w- c:\windows\system32\poqexec.exe
2011-05-18 00:39:37 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-05-18 00:39:37 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-05-11 19:00:54 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-11 19:00:53 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
.
==================== Find3M ====================
.
2011-06-07 14:27:09 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-05-04 10:52:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-09 05:02:04 390656 ----a-w- c:\windows\system32\ipcoin815.dll
.
============= FINISH: 12:09:06.65 ===============