Hello,
I am stucked with this Click.Giftload and do not find any easy way to get rid of it (do not want to risk any hazardous manipulation either).
I found this forum 2 weeks ago and would be grateful if somebody could help me with this annoying thing...
Here the story in case it might help :
Previous config : Vista SP2 Pro - IE8.0
2-3 weeks ago, my system began to slow down drastically and IE wouldn't load a few pages (I am normally using Opera). CPU usage was always above 60% even as no program was running and memory load had doubled...
So, I ran Spybot S&D and it found this Hijacker. Removed it but nothing changed. Did a full scan with Avira which found iertutil.dll corrupted and placed it in quarantine.
I tried to replace the file from original CD but it did not have the same version nr. (?) Tried from the net : nothing to do.
I then downloaded IE9 and installed it but it was not better.
Ran a scan with MBAM : found 1 adware only.
Ran a scan with Spysweeper : found another adware (only).
I finally tried a repair from Windows recovery CD and it crashed the system.
So I took the opportunity to format the system partition and to downgrade Vista to XP Pro (had been thinking to do this for a few months anyway).
Everything was OK during the 2-3 first start up but then again Click.Giftload reappeared...
As I am using this laptop for business I can not stop working with it. So here is the way I am running it :
Immediately after log on I terminate the "explorer.exe" process from the task manager => new task => C:\windows\explorer.exe
And everything is running fine as long as I turn off the laptop in sleep mode except that IE7 is not starting any more (I do not use it anyway).
I can check that the system is running "normally" by the memory load of the 8 "svchost.exe" processes : if only one of them is going above 12Mb the system does not slow down and there is no problem to browse the net...
Can someone please help me to clean my system ? Thanks in advance.
Here is the last DDS log :
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Etienne at 15:00:24,54 on mar. 05/04/2011
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.3001.2139 [GMT 2:00]
.
AV: AntiVir Desktop *Enabled/Updated* {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
svchost.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Spy Sweeper\SpySweeper.exe
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\CounterPath\X-Lite 4\X-Lite4.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Documents and Settings\Etienne\Bureau\dds.scr
C:\Program Files\Avira\AntiVir Desktop\checkt.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=0&o=xpp&d=0311&m=travelmate_5730
mDefault_Page_URL = hxxp://global.acer.com/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=0&o=xpp&d=0311&m=travelmate_5730
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\fichiers communs\adobe\acrobat\activex\AcroIEHelper.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: Copernic Desktop Search 2: {968631b6-4729-440d-9bf4-251f5593ec9a} - c:\program files\copernic desktop search 2\DesktopSearchBand203000030.dll
TB: {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No File
EB: Copernic Desktop Search 2: {968631b6-4729-440d-9bf4-251f5593ec9a} - c:\program files\copernic desktop search 2\DesktopSearchBand203000030.dll
EB: Copernic Desktop Search 2: {9c3fca1f-99e3-48f2-a7f4-dd3931b2f99a} - c:\program files\copernic desktop search 2\DesktopSearchBand203000030.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [Copernic Desktop Search 2] "c:\program files\copernic desktop search 2\DesktopSearchService.exe" /tray
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [SpybotSD TeaTimer] "c:\program files\spybot - search & destroy\TeaTimer.exe"
uRun: [X-Lite 4] "c:\program files\counterpath\x-lite 4\X-Lite4.exe" -bootload
mRun: [preload] c:\windows\RUNXMLPL.exe
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\iaanotif.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [BluetoothAuthenticationAgent] "rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [PLFSetL] c:\windows\PLFSetL.exe
mRun: [ZPdtWzdVitaKey MC3000] "c:\program files\acer\acer bio protection\PdtWzd.exe" show
mRun: [Apoint] "c:\program files\apoint2k\Apoint.exe"
mRun: [AzMixerSel] "c:\program files\realtek\audio\installshield\AzMixerSel.exe"
mRun: [ePower_DMC] "c:\program files\acer\empowering technology\epower\ePower_DMC.exe"
mRun: [Boot] "c:\program files\acer\empowering technology\epower\Boot.exe"
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Talk] "c:\program files\nch swift sound\talk\talk.exe" -logon
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [EEventManager] "c:\program files\epson\creativity suite\event manager\EEventManager.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\adobeg~1.lnk - c:\program files\fichiers communs\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\bttray.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: E&xporter vers Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\program files\acer\acer bio protection\PwdBank.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\program files\avira\antivir desktop\avsda.dll
TCP: {D1339E03-3B20-4221-B23C-331EC7B923AE} = 192.74.208.65,194.119.228.67
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\fichie~1\skype\SKYPE4~1.DLL
Notify: AWinNotifyVitaKey MC3000 - c:\program files\acer\acer bio protection\WinNotify.dll
Notify: igfxcui - igfxdev.dll
Notify: spba - c:\program files\fichiers communs\spba\homefus2.dll
Notify: WRNotifier - WRLogonNTF.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-3-14 11608]
R1 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2007-7-21 201288]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\avira\antivir desktop\avmailc.exe [2011-3-14 339624]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\avira\antivir desktop\sched.exe [2011-3-14 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-3-14 269480]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\avira\antivir desktop\avwebgrd.exe [2011-3-14 421032]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-3-14 61960]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-6 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-4 131072]
R2 WebrootSpySweeperService;Moteur Webroot Spy Sweeper;c:\program files\spy sweeper\SpySweeper.exe [2006-1-25 3379264]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2011-3-14 108032]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2008-5-13 51288]
R3 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2008-6-12 43608]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\drivers\TpChoice.sys [2007-12-26 17968]
S2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe --> c:\progra~1\mcafee\viruss~1\mcshield.exe [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-3-16 1691480]
S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe --> c:\progra~1\mcafee\viruss~1\mcsysmon.exe [?]
S3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2007-7-24 79304]
S3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2007-7-21 35240]
S3 mferkdk;McAfee Inc.;c:\windows\system32\drivers\mferkdk.sys [2007-7-24 33800]
S3 mfesmfk;McAfee Inc.;c:\windows\system32\drivers\mfesmfk.sys [2007-7-21 40488]
.
=============== Created Last 30 ================
.
2011-04-04 13:51:52 -------- d-----w- c:\program files\MSECache
2011-03-31 16:43:40 -------- d-----w- c:\docume~1\etienne\locals~1\applic~1\CounterPath Corporation
2011-03-31 16:43:33 -------- d-----w- c:\docume~1\etienne\locals~1\applic~1\CounterPath
2011-03-31 16:43:00 -------- d-----w- c:\program files\CounterPath
2011-03-31 16:40:32 14048 ------w- c:\windows\system32\spmsg2.dll
2011-03-31 16:38:21 -------- d-----w- c:\windows\system32\XPSViewer
2011-03-31 16:37:49 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-03-31 16:37:28 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-03-31 16:37:28 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-03-31 16:37:28 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-03-31 16:37:28 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-03-31 16:37:28 575488 ------w- c:\windows\system32\xpsshhdr.dll
2011-03-31 16:37:28 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2011-03-31 16:37:28 1676288 ------w- c:\windows\system32\xpssvcs.dll
2011-03-31 16:37:28 117760 ------w- c:\windows\system32\prntvpt.dll
2011-03-31 15:02:04 178176 ----a-r- c:\windows\system32\CNMIUA1.DLL
2011-03-31 15:01:47 70656 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPPA1.DLL
2011-03-31 15:01:47 27648 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPDA1.DLL
2011-03-31 15:01:46 272384 ----a-w- c:\windows\system32\CNMLMA1.DLL
2011-03-29 14:09:06 282624 ----a-w- c:\program files\fichiers communs\installshield\updateservice\agent.exe
2011-03-29 14:06:22 57344 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\0701\intel32\ctor.dll
2011-03-29 14:06:22 5632 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\0701\intel32\DotNetInstaller.exe
2011-03-29 14:06:22 237568 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\0701\intel32\iscript.dll
2011-03-29 14:06:22 155648 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\0701\intel32\iuser.dll
2011-03-29 14:06:21 696320 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\0701\intel32\iKernel.dll
2011-03-29 14:06:21 282756 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\0701\intel32\setup.dll
2011-03-29 14:06:21 163972 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\0701\intel32\iGdi.dll
2011-03-29 14:05:42 -------- d-----w- c:\program files\ABBYY FineReader 5.0 Sprint
2011-03-29 14:05:32 65536 ----a-w- c:\windows\system32\EPPicMgr.dll
2011-03-29 14:05:32 413696 ----a-w- c:\windows\system32\PICSDK.dll
2011-03-29 14:05:32 114688 ----a-w- c:\windows\system32\EpPicPrt.dll
2011-03-29 14:05:27 724992 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\09\00\intel32\iKernel.dll
2011-03-29 14:05:27 69715 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\09\00\intel32\ctor.dll
2011-03-29 14:05:27 5632 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\09\00\intel32\DotNetInstaller.exe
2011-03-29 14:05:27 266240 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\09\00\intel32\iscript.dll
2011-03-29 14:05:27 192512 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\09\00\intel32\iuser.dll
2011-03-29 14:05:26 311428 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\09\00\intel32\Setup.dll
2011-03-29 14:05:26 184452 ----a-w- c:\program files\fichiers communs\installshield\professional\runtime\09\00\intel32\iGdi.dll
2011-03-29 14:04:04 -------- d-----w- c:\program files\epson
2011-03-29 14:00:59 29696 ----a-w- c:\windows\system32\escwiab.dll
2011-03-29 14:00:58 33280 ----a-w- c:\windows\system32\esccm.dll
2011-03-29 14:00:58 27648 ----a-w- c:\windows\system32\escimg.dll
2011-03-29 14:00:57 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2011-03-29 14:00:57 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-03-24 11:49:13 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2011-03-23 12:36:12 22080 ----a-w- c:\windows\system32\drivers\sshrmd.sys
2011-03-23 12:36:12 21056 ----a-w- c:\windows\system32\drivers\sskbfd.sys
2011-03-23 12:36:12 20544 ----a-w- c:\windows\system32\drivers\SSFS0509.sys
2011-03-23 12:36:12 144960 ----a-w- c:\windows\system32\drivers\ssidrv.sys
2011-03-23 12:36:07 -------- d-----w- c:\docume~1\alluse~1\applic~1\Webroot
2011-03-23 12:34:13 -------- d-----w- c:\docume~1\etienne\applic~1\Webroot
2011-03-23 10:45:31 -------- d-----w- c:\program files\MSSOAP
2011-03-23 10:24:12 1563008 ----a-w- c:\windows\WRSetup.dll
2011-03-23 09:50:39 102912 ----a-w- c:\windows\system32\islzma.dll
2011-03-23 09:50:29 -------- d-----w- c:\program files\Spy Sweeper
2011-03-22 22:13:24 -------- d-----w- c:\docume~1\etienne\applic~1\Malwarebytes
2011-03-22 10:15:29 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-22 10:15:29 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2011-03-21 23:03:19 -------- d-----w- c:\windows\pss
2011-03-21 17:02:58 -------- d-----w- c:\program files\GhostScript
2011-03-21 16:19:45 73216 ----a-w- c:\windows\cadkasdeinst01f.exe
2011-03-19 12:17:56 -------- d-----w- c:\windows\system32\NtmsData
2011-03-16 18:32:44 327168 ----a-w- c:\windows\IsUn040c.exe
2011-03-16 12:06:25 359016 ----a-w- c:\windows\vncutil.exe
2011-03-16 12:06:21 55912 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2011-03-16 12:06:21 129640 ----a-w- c:\windows\RtkAudioService.exe
2011-03-16 12:06:20 1395800 ----a-w- c:\windows\system32\drivers\Monfilt.sys
2011-03-16 12:06:18 1691480 ----a-w- c:\windows\system32\drivers\Ambfilt.sys
2011-03-16 11:34:34 37888 -c--a-w- c:\windows\system32\dllcache\bthmodem.sys
2011-03-16 11:34:34 37888 ----a-w- c:\windows\system32\drivers\bthmodem.sys
2011-03-16 11:17:05 37280 ----a-w- c:\windows\system32\drivers\btwmodem.sys
2011-03-14 21:32:20 199176 ----a-w- c:\windows\GVUni.exe
2011-03-14 21:32:19 5120 ----a-w- c:\windows\system32\FILTRCOI.DLL
2011-03-14 21:32:19 207368 ----a-w- c:\windows\UNINST32.EXE
2011-03-14 21:32:19 17408 ----a-w- c:\windows\system32\drivers\DKbFltr.SYS
2011-03-14 21:31:50 49152 ----a-w- c:\windows\Interop.IWshRuntimeLibrary.dll
2011-03-14 21:31:50 380928 ----a-w- c:\windows\AcerStore.exe
2011-03-14 21:31:20 659456 ----a-w- c:\windows\system32\NETw5c32.dll
2011-03-14 21:31:20 3626112 ----a-w- c:\windows\system32\drivers\NETw5x32.sys
2011-03-14 21:31:20 2756608 ----a-w- c:\windows\system32\NETw5r32.dll
2011-03-14 21:31:19 -------- d-----w- c:\windows\WLAN
2011-03-14 21:30:32 -------- d-----w- c:\windows\VGA
2011-03-14 21:30:24 147456 ----a-w- c:\windows\PLAUNCH.EXE
2011-03-14 21:30:23 -------- d-----w- c:\windows\Lan
2011-03-14 18:17:49 -------- d-----w- C:\TMP
2011-03-14 18:16:40 184320 ----a-w- c:\windows\system32\BDEADMIN.CPL
2011-03-14 18:16:32 -------- d-----w- c:\program files\Common Files
2011-03-14 18:16:13 -------- d-----w- c:\program files\Data-Concept
2011-03-14 18:15:56 304128 ----a-w- c:\windows\unin040c.exe
2011-03-14 18:15:52 -------- d-----w- c:\documents and settings\etienne\WINDOWS
2011-03-14 18:09:33 -------- d-----w- c:\program files\PowerArchiver
2011-03-14 18:02:57 -------- d-----w- c:\docume~1\etienne\applic~1\XnView
2011-03-14 18:02:32 -------- d-----w- c:\program files\XnView
2011-03-14 18:00:06 -------- d-----w- c:\program files\VideoLAN
2011-03-14 17:56:01 -------- d-----w- c:\program files\NK2View
2011-03-14 17:52:49 -------- d-----w- c:\program files\Kyocera
2011-03-14 17:51:13 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2011-03-14 17:51:13 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-03-14 17:47:59 100580 ------w- c:\windows\system32\KMPJLMN.DLL
2011-03-14 17:47:52 46877 ------w- c:\windows\system32\KM-PMKN.DLL
2011-03-14 17:37:22 176235 ----a-w- c:\windows\system32\Primomonnt.dll
2011-03-14 17:37:19 -------- d-----w- c:\windows\PrimoPDF
2011-03-14 17:37:19 -------- d-----w- c:\program files\PrimoPDF
2011-03-14 17:36:40 -------- d-----w- c:\program files\Unlocker
2011-03-14 16:21:42 -------- d-----w- c:\program files\NCH Swift Sound
2011-03-14 16:14:19 -------- d-----r- c:\program files\Skype
2011-03-14 15:47:20 -------- d-----w- c:\docume~1\etienne\applic~1\Avira
2011-03-14 15:37:02 28552 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
2011-03-14 15:37:02 28040 ----a-w- c:\windows\system32\mdimon.dll
2011-03-14 15:35:50 -------- d-----w- c:\windows\SHELLNEW
2011-03-14 14:57:15 -------- d-----w- c:\docume~1\etienne\locals~1\applic~1\Opera
2011-03-14 14:49:05 -------- d-----w- c:\docume~1\etienne\locals~1\applic~1\Copernic
2011-03-14 14:48:49 -------- d-----w- c:\program files\Copernic Desktop Search 2
2011-03-14 14:47:53 -------- d-----w- c:\program files\CCleaner
2011-03-14 14:42:52 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-03-14 14:42:51 -------- d-----w- c:\program files\Avira
2011-03-14 14:42:51 -------- d-----w- c:\docume~1\alluse~1\applic~1\Avira
2011-03-14 14:23:00 -------- d-----w- c:\program files\Acer Inc
2011-03-14 14:09:33 -------- d-----w- c:\program files\Launch Manager
2011-03-14 14:08:47 10368 ----a-w- c:\windows\system32\drivers\iviaspi.sys
2011-03-14 14:08:40 -------- d-----w- c:\docume~1\alluse~1\applic~1\Corel
2011-03-14 14:08:28 -------- d-----w- c:\program files\fichiers communs\InterVideo
2011-03-14 14:08:27 -------- d-----w- c:\program files\fichiers communs\Protexis
2011-03-14 14:06:51 321024 ----a-w- c:\windows\system32\ERUpdateHidden.EXE
2011-03-14 14:06:51 258048 ----a-w- c:\windows\system32\Uninstall_eRecovery.exe
2011-03-14 14:06:50 258048 ----a-w- c:\windows\system32\CheckD2DSystem.exe
2011-03-14 14:06:50 16384 ----a-w- c:\windows\system32\ClearEvent.exe
2011-03-14 14:06:50 159744 ----a-w- c:\windows\system32\CloseProcessWindow.dll
2011-03-14 14:05:56 78208 ----a-w- c:\windows\system32\drivers\epm-shd.sys
2011-03-14 14:05:56 53248 ----a-w- c:\windows\system32\acpimof.dll
2011-03-14 14:05:56 45056 ----a-w- c:\windows\system32\Epm-Po.dll
2011-03-14 14:05:56 4096 ----a-w- c:\windows\system32\drivers\epm-psd.sys
2011-03-14 14:05:16 69632 ----a-w- c:\windows\system32\eRecUtil.dll
2011-03-14 14:05:16 24576 ----a-w- c:\windows\system32\SysMonitor.exe
2011-03-14 14:05:14 1047552 ----a-w- c:\windows\system32\mfc71u.dll
2011-03-14 13:58:54 24578845 ----a-w- c:\windows\system32\acer.exe
2011-03-14 13:58:52 36909056 ----a-w- c:\windows\system32\acer.scr
2011-03-14 13:58:47 -------- d-----w- c:\program files\Acer Incorporated
2011-03-14 13:58:26 -------- d-----w- c:\windows\ACER
2011-03-14 13:58:08 49152 ----a-w- c:\windows\system32\ChCfg.exe
2011-03-14 13:56:54 118784 ----a-w- c:\windows\system32\VMC3KAPI.dll
2011-03-14 13:56:54 114688 ----a-w- c:\windows\system32\VCryptAPI.dll
2011-03-14 13:56:41 23040 ----a-w- c:\windows\system32\ShlCmd.exe
2011-03-14 13:56:40 5632 ----a-w- c:\windows\system32\biologon.dll
2011-03-14 13:56:32 42608 ----a-w- c:\windows\system32\drivers\AlfaFF.sys
2011-03-14 13:56:32 338416 ----a-w- c:\windows\system32\DrvCrypt.dll
2011-03-14 13:56:32 24048 ----a-w- c:\windows\system32\AlfaFF.dll
2011-03-14 13:56:27 1468928 ----a-w- c:\windows\system32\bsapi.dll
2011-03-14 13:56:26 -------- d-----w- c:\program files\Acer
2011-03-14 13:56:16 50576 ----a-w- c:\windows\system32\drivers\tcusb.sys
2011-03-14 13:56:08 -------- d-----w- c:\program files\fichiers communs\SPBA
2011-03-14 13:53:21 101120 -c--a-w- c:\windows\system32\dllcache\bthpan.sys
2011-03-14 13:52:29 141056 -c--a-w- c:\windows\system32\dllcache\ks.sys
2011-03-14 13:52:29 141056 ----a-w- c:\windows\system32\drivers\ks.sys
2011-03-14 13:52:29 108032 ----a-w- c:\windows\system32\drivers\IntcHdmi.sys
2011-03-14 13:52:27 23552 ----a-w- c:\windows\system32\wdmaud.drv
2011-03-14 13:52:27 146048 -c--a-w- c:\windows\system32\dllcache\portcls.sys
2011-03-14 13:52:27 146048 ----a-w- c:\windows\system32\drivers\portcls.sys
2011-03-14 13:52:26 60160 -c--a-w- c:\windows\system32\dllcache\drmk.sys
2011-03-14 13:52:26 60160 ----a-w- c:\windows\system32\drivers\drmk.sys
2011-03-14 13:52:26 4096 ----a-w- c:\windows\system32\ksuser.dll
2011-03-14 13:52:25 49408 -c--a-w- c:\windows\system32\dllcache\stream.sys
2011-03-14 13:52:25 49408 ----a-w- c:\windows\system32\drivers\stream.sys
2011-03-14 13:52:25 129536 ----a-w- c:\windows\system32\ksproxy.ax
2011-03-14 12:37:41 -------- d-----w- c:\windows\system32\LogFiles
2011-03-14 12:35:18 12288 ----a-w- c:\windows\system32\drivers\mouhid.sys
2011-03-14 12:35:14 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2011-03-14 12:35:14 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2011-03-14 12:35:13 56576 ----a-w- c:\windows\system32\drivers\swmidi.sys
2011-03-14 12:35:13 52864 ----a-w- c:\windows\system32\drivers\DMusic.sys
2011-03-14 12:35:12 2944 ----a-w- c:\windows\system32\drivers\drmkaud.sys
2011-03-14 12:35:12 172416 ----a-w- c:\windows\system32\drivers\kmixer.sys
2011-03-14 12:35:12 142592 ----a-w- c:\windows\system32\drivers\aec.sys
2011-03-14 12:35:11 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys
2011-03-14 12:35:10 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2011-03-14 12:34:50 -------- d-----w- c:\program files\CONEXANT
2011-03-14 12:34:29 -------- d-----w- c:\windows\system32\RTCOM
.
==================== Find3M ====================
.
2011-02-17 13:02:04 20029032 ----a-w- c:\windows\RTHDCPL.EXE
2011-02-09 14:56:00 1284712 ----a-w- c:\windows\RtlExUpd.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Hitachi_ rev.FB2O -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A216439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a21c7d0]; MOV EAX, [0x8a21c84c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF196] -> \Device\Harddisk0\DR0[0x8A23F030]
3 CLASSPNP[0xBA1A8FD7] -> ntkrnlpa!IofCallDriver[0x804EF196] -> [0x8ABC8B80]
\Driver\iaStor[0x8ABDC888] -> IRP_MJ_CREATE -> 0x8A216439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x147; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IAAStorageDevice-1 -> \??\IDE#DiskHitachi_HTS543216L9A300_________________FB2OC40C#4&31843f9c&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 312581806 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 15:01:43,03 ===============