I was directed here from a previous post. You can view that information at this link.
http://www.bleepingcomputer.com/forums/topic456487.html
FYI, there is no GMER log because this is a 64 bit Windows.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Karen at 20:25:55 on 2012-06-20
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.aol.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Road Runner Toolbar: {e4878b45-e2c0-4307-b6e8-734922f92f5b} - C:\Program Files (x86)\Road_Runner\prxtbRoad.dll
mURLSearchHooks: Road Runner Toolbar: {e4878b45-e2c0-4307-b6e8-734922f92f5b} - C:\Program Files (x86)\Road_Runner\prxtbRoad.dll
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: TmIEPlugInBHO Class: {1ca1377b-dc1d-4a52-9585-6e06050fac53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1505\6.6.1088\TmIEPlg32.dll
BHO: TmBpIeBHO Class: {bbacbafd-fa5e-4079-8b33-00eb9f13d4ac} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Road Runner Toolbar: {e4878b45-e2c0-4307-b6e8-734922f92f5b} - C:\Program Files (x86)\Road_Runner\prxtbRoad.dll
TB: Road Runner Toolbar: {e4878b45-e2c0-4307-b6e8-734922f92f5b} - C:\Program Files (x86)\Road_Runner\prxtbRoad.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ISUSPM Startup] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
uRun: [Google Update] "C:\Users\Karen\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
uRun: [Advanced SystemCare 5] "C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{545BE5C9-341C-435C-8ACE-8DFE834FED79} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{545BE5C9-341C-435C-8ACE-8DFE834FED79}\65562796A7F6E602143433030253644373 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{545BE5C9-341C-435C-8ACE-8DFE834FED79}\777777E277966696771667A7E236F6D6 : DhcpNameServer = 192.168.1.1
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1505\6.6.1088\TmIEPlg32.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1505\6.6.1088\TmIEPlg32.dll
BHO-X64: Trend Micro NSC BHO - No File
BHO-X64: TmBpIeBHO Class: {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll
BHO-X64: TmBpIeBHO - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: Road Runner Toolbar: {e4878b45-e2c0-4307-b6e8-734922f92f5b} - C:\Program Files (x86)\Road_Runner\prxtbRoad.dll
BHO-X64: Road Runner - No File
TB-X64: Road Runner Toolbar: {e4878b45-e2c0-4307-b6e8-734922f92f5b} - C:\Program Files (x86)\Road_Runner\prxtbRoad.dll
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2012-06-18 21:47:19 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-18 21:47:02 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-18 21:46:47 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-18 21:46:47 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-14 02:56:58 -------- d-----w- C:\Program Files (x86)\ESET
2012-06-14 02:46:17 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-06-14 02:46:17 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-06-14 02:46:17 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-06-14 02:46:12 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-06-14 02:46:11 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-06-14 02:46:11 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-06-14 02:46:03 3146752 ----a-w- C:\Windows\System32\win32k.sys
2012-06-14 02:46:00 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-06-09 16:42:15 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2012-06-09 16:42:15 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
2012-06-09 16:41:39 515584 ----a-w- C:\Windows\System32\timedate.cpl
2012-06-09 16:41:39 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
2012-06-09 16:39:36 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2012-06-09 16:38:40 197120 ----a-w- C:\Windows\System32\d3d10_1.dll
2012-06-09 16:38:40 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
2012-06-09 16:38:27 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2012-06-09 16:38:15 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2012-06-09 16:38:15 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2012-06-09 16:37:22 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2012-06-09 16:37:22 31232 ----a-w- C:\Windows\System32\prevhost.exe
2012-06-09 16:37:09 2871808 ----a-w- C:\Windows\explorer.exe
2012-06-09 16:37:09 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2012-06-09 16:36:52 476160 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
2012-06-09 16:36:52 288256 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2012-06-09 16:36:30 902656 ----a-w- C:\Windows\System32\d2d1.dll
2012-06-09 16:36:30 739840 ----a-w- C:\Windows\SysWow64\d2d1.dll
2012-06-09 16:36:30 1139200 ----a-w- C:\Windows\System32\FntCache.dll
2012-06-09 16:34:08 24448 ----a-w- C:\Windows\System32\RegistryDefragBootTime.exe
2012-06-09 14:48:30 -------- d-----w- C:\ProgramData\IObit
2012-06-09 14:48:21 -------- d-----w- C:\Users\Karen\AppData\Roaming\IObit
2012-06-09 14:48:16 -------- d-----w- C:\Program Files (x86)\IObit
2012-06-09 13:15:40 -------- d-----w- C:\Users\Karen\AppData\Roaming\Malwarebytes
2012-06-09 13:15:09 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-06-09 13:15:09 -------- d-----w- C:\ProgramData\Malwarebytes
2012-06-09 13:15:08 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-05-31 12:30:36 8955792 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CE7350F0-F1FD-4117-B112-E0493AEC0603}\mpengine.dll
2012-05-29 18:23:19 8955792 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
.
==================== Find3M ====================
.
2012-06-09 16:40:15 96768 ----a-w- C:\Windows\System32\fsutil.exe
2012-06-09 16:40:15 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2012-06-09 16:40:15 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2012-06-09 16:40:15 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2012-06-09 16:40:15 2565632 ----a-w- C:\Windows\System32\esent.dll
2012-06-09 16:40:15 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2012-06-09 16:40:15 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2012-06-09 16:40:15 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2012-06-09 16:40:15 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2012-06-09 16:40:15 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2012-06-09 16:40:15 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2012-06-09 16:37:55 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2012-06-09 16:37:55 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2012-05-18 02:06:48 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-05-18 01:59:14 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-05-18 01:58:39 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-05-18 01:55:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-05-18 01:51:30 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-05-17 22:45:37 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-05-17 22:35:47 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-05-17 22:35:39 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-05-17 22:29:45 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-05-17 22:24:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-03-30 11:35:47 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 20:27:43.18 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top











