Symptons: When I google or yahoo search something, the first couple results are redirected to other websites
Unwanted pop-ups even when I am not using internet explorer, espicially www.google.com/webhp , possibly fake google site
Both IE and firefox have similar symptons
I have AVG free on my computer and tried the following spyware removers from cnet:
spybot s&d
hitman pro 3.5
malwarebytes
superantispyware
All of the scanners tells me that there are no threats.
I'm using:
windows vista home premium service pack one
The laptop was purchased in Taiwan
DDS log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by User at 15:30:36.13 on 2010/05/01 星期六
Internet Explorer: 8.0.6001.18904
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\ehome\ehmsas.exe
c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Windows\System32\rundll32.exe
C:\Users\User\AppData\Local\Temp\RtkBtMnt.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\rundll32.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\User\Desktop\dds.scr
C:\Windows\system32\conime.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://zh.tw.acer.yahoo.com
mDefault_Page_URL = hxxp://zh.tw.acer.yahoo.com
mDefault_Search_URL = hxxp://tw.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://tw.search.yahoo.com
mSearch Page = hxxp://tw.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://tw.search.yahoo.com
uURLSearchHooks: Yahoo! 工具列: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live 登入小幫手: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0988.2\msneshellx.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
TB: Yahoo! 工具列: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0988.2\msneshellx.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe
mRun: [PLFSetL] c:\windows\PLFSetL.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
dRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\bttray.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Sothink SWF Catcher - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: 傳送影像到 Bluetooth 裝置(&

IE: 傳送頁面到 Bluetooth 裝置(&

IE: 匯出至 Microsoft Excel(&X) - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {09BA8F6D-CB54-424B-839C-C2A6C8E6B436}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
AppInit_DLLs: avgrsstx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-4-28 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-26 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-26 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-26 242896]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-4-27 61440]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-12 308064]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\sitead~1\mcsacore.exe [2010-4-28 93320]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-4-27 1153368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-11-20 24652]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2007-8-3 32256]
S2 gupdate;Google 更新服務 (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-28 135664]
S2 自動 LiveUpdate 排程器;自動 LiveUpdate 排程器;"c:\program files\symantec\liveupdate\aluschedulersvc.exe" --> c:\program files\symantec\liveupdate\ALUSchedulerSvc.exe [?]
=============== Created Last 30 ================
2010-05-01 22:24:19 20 ----a-w- c:\users\user\defogger_reenable
2010-05-01 19:52:23 0 d-----w- c:\program files\Hitman Pro 3.5
2010-05-01 01:48:25 0 d-----w- c:\program files\Trend Micro
2010-04-30 06:29:28 2 --shatr- c:\windows\winstart.bat
2010-04-30 06:15:56 8576 ----a-w- c:\windows\system32\drivers\aopgprguwkcv.sys
2010-04-30 06:10:53 8576 ----a-w- c:\windows\system32\drivers\aeksfjlwfhml.sys
2010-04-30 06:08:45 0 d-----w- c:\users\user\Pavark
2010-04-30 05:04:46 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-04-30 05:04:39 0 d-----w- c:\users\user\appdata\roaming\SUPERAntiSpyware.com
2010-04-30 05:04:39 0 d-----w- c:\program files\SUPERAntiSpyware
2010-04-29 04:33:26 293283638 ----a-w- c:\windows\MEMORY.DMP
2010-04-29 04:31:43 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-04-29 04:31:37 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-29 04:22:46 0 d-----w- c:\programdata\Lavasoft
2010-04-29 03:16:00 0 d-----w- c:\users\user\appdata\roaming\Malwarebytes
2010-04-29 03:15:44 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 03:15:42 0 d-----w- c:\programdata\Malwarebytes
2010-04-29 03:15:41 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-29 03:15:41 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-29 03:04:58 12872 ----a-w- c:\windows\system32\bootdelete.exe
2010-04-29 02:02:35 15944 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-04-29 02:02:25 0 d-----w- c:\programdata\Hitman Pro
2010-04-29 01:17:35 0 d-----w- c:\program files\common files\McAfee
2010-04-29 01:17:19 0 d-----w- c:\program files\McAfee
2010-04-28 03:41:00 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-04-28 03:41:00 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-04-25 22:47:49 0 d-----w- c:\users\user\appdata\roaming\GetRightToGo
2010-04-22 23:26:36 0 d-----w- c:\program files\Steam
2010-04-22 04:10:37 0 d-----w- c:\program files\common files\Steam
2010-04-18 18:48:03 0 d-----w- c:\programdata\ALM
2010-04-13 23:28:58 78848 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-13 23:28:58 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-13 23:28:58 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-13 23:28:53 3598216 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-13 23:28:52 3545992 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-13 23:28:49 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-04-13 23:28:41 62464 ----a-w- c:\windows\system32\l3codeca.acm
2010-04-13 23:28:06 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-13 23:28:06 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-13 23:28:06 190464 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-04-13 23:27:40 171520 ----a-w- c:\windows\system32\wintrust.dll
2010-04-13 23:27:06 98304 ----a-w- c:\windows\system32\cabview.dll
2010-04-10 18:24:32 524288 --sha-w- c:\users\user\ntuser.dat{9b5f677c-44c9-11df-9617-001b386a7e48}.TMContainer00000000000000000002.regtrans-ms
2010-04-10 18:24:31 65536 --sha-w- c:\users\user\ntuser.dat{9b5f677c-44c9-11df-9617-001b386a7e48}.TM.blf
2010-04-10 18:24:31 524288 --sha-w- c:\users\user\ntuser.dat{9b5f677c-44c9-11df-9617-001b386a7e48}.TMContainer00000000000000000001.regtrans-ms
2010-04-10 17:51:45 65536 --sha-w- c:\users\user\ntuser.dat{5d61a669-44c3-11df-951b-001b386a7e48}.TM.blf
2010-04-10 17:51:45 524288 --sha-w- c:\users\user\ntuser.dat{5d61a669-44c3-11df-951b-001b386a7e48}.TMContainer00000000000000000002.regtrans-ms
2010-04-10 17:51:45 524288 --sha-w- c:\users\user\ntuser.dat{5d61a669-44c3-11df-951b-001b386a7e48}.TMContainer00000000000000000001.regtrans-ms
2010-04-10 05:56:54 0 d-----w- c:\program files\common files\SourceTec
2010-04-10 05:36:52 23 ----a-w- c:\windows\SWFDecompiler.INI
2010-04-09 19:06:02 815104 ----a-w- c:\windows\system32\xvidcore.dll
2010-04-09 19:06:02 77824 ----a-w- c:\windows\system32\xvid.ax
2010-04-09 19:06:02 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-04-06 17:35:53 0 d-----w- c:\programdata\McAfee
2010-04-04 17:22:28 0 d-----w- c:\users\user\appdata\roaming\ComodoGroup
2010-04-04 17:18:59 0 d-----w- c:\program files\COMODO
2010-04-04 02:47:47 0 d-----w- c:\program files\common files\Blizzard Entertainment
2010-04-04 02:47:25 0 d-----w- c:\programdata\Blizzard
2010-04-03 18:36:26 0 d-----w- c:\users\user\Library
2010-04-03 18:36:26 0 d-----w- c:\users\user\appdata\roaming\com.adobe.ExMan
2010-04-03 00:50:38 0 d-----w- c:\program files\common files\Akamai
==================== Find3M ====================
2010-05-01 21:05:43 27240 ----a-w- c:\users\user\appdata\roaming\nvModes.dat
2010-04-21 03:41:19 331232 ----a-w- c:\windows\system32\prfh0404.dat
2010-04-21 03:41:19 101932 ----a-w- c:\windows\system32\prfc0404.dat
2010-04-20 19:38:29 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-07 16:37:53 51200 ----a-w- c:\windows\inf\infpub.dat
2010-03-12 18:32:38 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-12 18:31:53 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-24 17:16:06 181632 ----a-w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39:13 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33:45 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33:45 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55:36 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:39:35 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:37:20 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-02-04 17:01:14 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-02-04 17:01:14 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-02-04 17:01:14 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-02-04 17:01:14 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-01-28 01:48:44 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-01-28 01:48:43 86016 ----a-w- c:\windows\inf\infstor.dat
2008-09-14 16:38:41 174 --sha-w- c:\program files\desktop.ini
2008-09-14 04:59:40 665600 ----a-w- c:\windows\inf\drvindex.dat
2006-11-08 09:46:23 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-08 09:46:23 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-08 09:46:23 30674 ----a-w- c:\windows\inf\perflib\0404\perfd.dat
2006-11-08 09:46:23 30674 ----a-w- c:\windows\inf\perflib\0404\perfc.dat
2006-11-08 09:46:23 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-08 09:46:23 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-08 09:46:23 116540 ----a-w- c:\windows\inf\perflib\0404\perfi.dat
2006-11-08 09:46:23 116540 ----a-w- c:\windows\inf\perflib\0404\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-10-18 16:34:11 245760 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-10-20 04:41:10 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
============= FINISH: 15:34:24.19 ===============
Whenever I attempt to run GMER, the processor usage increased to 100 percent and I got the blue screen.
Please help me asap, thank you for your help.