This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My pc sends tons of spam

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
it's few days now that I'm searching for a malware that infected my mailbox, sends spam and furthemore hide my safe and ordinary mails.
My mail box is hotmail.
I'm on xp pro sp3.
I've ran many soft in order to clean the machine without success.
first I defragmented and cleansed the registry then c cleaner, adaware, spybot, antmalwarebyte.
I have no antivirus or firewall for yeaers and it seems that it's time for it, would any of you experienced pc user would give a hint for a reliable free version of that kind of soft.

thank a lot.

azert.

P.S. : here is my hjt log for hieroglyphs readers, thanks again for your help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:48:02, on 13/06/2009
Platform: Windows XP SP3, v.5657 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20900)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Taskix\Taskix32.exe
C:\Program Files\VirtuaWin\VirtuaWin.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\WinRoll\winroll.exe
C:\Program Files\EXPERTool\TBPanel.exe
C:\WINDOWS\system32\hasplms.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Notepad++\notepad++.exe
C:\Documents and Settings\Administrateur\Bureau\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Taskix] C:\Program Files\Taskix\Taskix32.exe start
O4 - HKLM\..\Run: [VirtuaWin] C:\Program Files\VirtuaWin\VirtuaWin.exe
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [WinRoll] "C:\Program Files\WinRoll\winroll.exe"
O4 - HKCU\..\Run: [GAINWARD] C:\Program Files\EXPERTool\TBPanel.exe /A
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O20 - AppInit_DLLs: acaptuser32.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SolidWorks SolidNetWork License Manager - Macrovision Corporation - C:\Program Files\SolidWorks SolidNetWork License Manager\lmgrd.exe

–
End of file - 4624 bytes
hi,

I would first get a anti-virus app. This will scan and protect you from threats that anti-malware apps like Adaware or Malwarebytes dont.
Then you can read this article, but i wouldnt change any passwords just yet. We want to make sure your machine is free of malware first.

A few AV links, some offer free versions, others have trial versions you can try. Install one and try it out for its ease of use etc. dont like it? uninstall it via add/remove programs panel, reboot machine and install another. some of these, mainly the paid ones may come as "suites" which means they may have antivirus, anti-malware and/or firewall bundled in them.

http://www.avast.com/eng/avast_4_home.html
http://www.eset.com/
http://free.avg.com/
http://usa.kaspersky.com/?c_id=FDS_SSP_TLP
http://www.clamwin.com/
http://www.bitdefender.com/
http://home.mcafee.com/Default.aspx
http://www.free-av.com/

The article to read:
http://windowslivehelp.com/solutions/accou…een-stolen.aspx
hi shelf life, Thanks for your answer, Ivé read it and I don't think that someone phisycally living is using my adress : here is a copy of the message that is sent thru my pc. I've just installed avast for it is the most common but it's ten years I'm using a computer without ever having the necessity for an av. This is an automatically generated Delivery Status Notification. THIS IS A WARNING MESSAGE ONLY. YOU DO NOT NEED TO RESEND YOUR MESSAGE. Delivery to the following recipients has been delayed. Subject: RE: Date: Sun, 14 Jun 2009 05:44:20 +0000 Dear friend: This is the greeting from ndhir LTD.,one of the biggest Electrical wholesaler and Retailer in China.We mainly sell electrical product such as Mobile Phones, Digital Cameras, LCD TVs,Xboxes, Laptops,DV,Mp4, GPS,and so on.if you have free time please visit our website: ndhir.com We can offer you both high quality products and good price .All items we list on this website are brand new and original with sealed box. and come with official international warranty . As you said in your post Iwould be quite annoyed to change either my password or erase my adress for I use it very often. I scan my pc and tell you if avast spots anything. Thanks AZERT
Hi again, after a scan with avast, it seems that my pc is free of any infection, yet my hotmail account is still used to send spam and furthemore, I even can't receive authentic mails from my friends. Do I have to resign my mail adrees ? I'm I still in the right forum ? THank you all. Ph.
hi,

lets get another tool to check for any possible on board malware. Its called combofix. there is a guide to read first. Read through the guide, download combofix to your desktop, disable your AV as explained in the guide, double click the combofix icon and follow the prompts. Post the log in reply.

the guide:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Hi shelf life, Sorry for my silence but I had hard days work far from the computer. I've tried to run combofix but it says that it's only compatible with xp system, well I'm on xp system, maybe another software ? ciao. azert.
hi,

I've tried to run combofix but it says that it's only compatible with xp system

never seen that problem before. lets see if DDS can cough up anything.

hotmail is web based. somebody must know your password to be able to send (and read) from your account. What we are trying to do is make sure theres no malware present on your computer that would have allowed them to get that information. They could have gotten it another way like a via phising.
If your computer seems to be malware free then you should change your log in password and follow the advice given here:

http://forums.whatthetech.com/redirect.php…een-stolen.aspx

Please download DDS and save it to your desktop.
Double click dds.scr to run the tool.

When done, DDS.txt will open.
Save both reports
to your desktop. Copy/paste only the first log in your reply. (not the attach.txt)
Hi shelf life, when I run the .scr file it opens this windows that I am attaching to my post but it doesnt look like an executable in any way. Nota : the path and especially the extension mentionned at the top of the window is .scr and not txt yet it's txt alike (I'm not quite clear but you'll understand when opening attached file). Thanks for you concern. Azert OUch ! the file is too big to be attached, it's 351 K how could I send it to you, I can't paste it in this very window for there are non unicode signs in it (I guess it's the reason why).
ok, Lets try this one instead:

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Ok shelf life !
at last it works, I started to worry. Here is th log.
See you.

AZERT

Logfile of random's system information tool 1.06 (written by random/random)
Run by [removed] at 2009-06-19 19:31:27
Microsoft Windows XP Professionnel Service Pack 3, v.5657
System drive C: has 404 GB (85%) free of 477 GB
Total RAM: 2047 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:31:32, on 19/06/2009
Platform: Windows XP SP3, v.5657 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20900)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Taskix\Taskix32.exe
C:\Program Files\VirtuaWin\VirtuaWin.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\WinRoll\winroll.exe
C:\Program Files\EXPERTool\TBPanel.exe
C:\WINDOWS\system32\hasplms.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
C:\Program Files\trend micro\Administrateur.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Taskix] C:\Program Files\Taskix\Taskix32.exe start
O4 - HKLM\..\Run: [VirtuaWin] C:\Program Files\VirtuaWin\VirtuaWin.exe
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [WinRoll] "C:\Program Files\WinRoll\winroll.exe"
O4 - HKCU\..\Run: [GAINWARD] C:\Program Files\EXPERTool\TBPanel.exe /A
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O20 - AppInit_DLLs: acaptuser32.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SolidWorks SolidNetWork License Manager - Macrovision Corporation - C:\Program Files\SolidWorks SolidNetWork License Manager\lmgrd.exe

–
End of file - 5259 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-05-29 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-05-29 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-05-29 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Taskix"=C:\Program Files\Taskix\Taskix32.exe [2008-04-02 124416]
"VirtuaWin"=C:\Program Files\VirtuaWin\VirtuaWin.exe [2008-04-24 116224]
"HDAudDeck"=C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [2008-11-11 33521664]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2008-01-20 217088]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-05-01 13750272]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-05-01 86016]
"Adobe Acrobat Speed Launcher"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2008-06-12 37232]
""= []
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2008-06-11 640376]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2009-06-14 198160]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WinRoll"=C:\Program Files\WinRoll\winroll.exe [2004-04-07 15360]
"GAINWARD"=C:\Program Files\EXPERTool\TBPanel.exe [2009-03-17 2181672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="acaptuser32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2008-10-19 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=1
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=95
"NoDesktopCleanupWizard"=1
"NoInstrumentation"=1
"NoResolveSearch"=1
"NoResolveTrack"=1
"NoSMBalloonTip"=1
"NoSMConfigurePrograms"=1
"NoStartMenuMFUprogramsList"=1
"NoStrCmpLogical"=0
"NoWelcomeScreen"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HideRunAsVerb"=
"NoActiveDesktop"=
"NoDriveTypeAutoRun"=
"NoInstrumentation"=
"NoResolveTrack"=
"NoSetActiveDesktop"=
"NoStartMenuMFUprogramsList"=
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{099893f4-506e-11de-96b0-001fc6d1f4c9}]
shell\AutoRun\command - F:\sm.exe
shell\open\command - F:\sm.exe


======File associations======

.reg - edit -
.reg - open -
.scr - open - C:\WINDOWS\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2009-06-19 19:31:27 —-D—- C:\rsit
2009-06-19 19:31:27 —-D—- C:\Program Files\trend micro
2009-06-19 02:31:50 —-D—- C:\TeklaStructures
2009-06-19 02:24:59 —-D—- C:\Program Files\RegCleaner
2009-06-19 01:51:52 —-D—- C:\Program Files\TeklaStructures
2009-06-19 01:50:32 —-D—- C:\Tekla
2009-06-19 01:39:59 —-D—- C:\Program Files\UnH Solutions
2009-06-19 01:33:03 —-D—- C:\Program Files\foobar2000
2009-06-19 01:31:33 —-D—- C:\Program Files\Monkey's Audio
2009-06-18 10:27:17 —-D—- C:\32788R22FWJFW
2009-06-15 11:39:40 —-A—- C:\WINDOWS\system32\aswBoot.exe
2009-06-15 11:39:38 —-D—- C:\Program Files\Alwil Software
2009-06-14 05:40:29 —-A—- C:\Bug.txt
2009-06-14 05:40:27 —-A—- C:\WINDOWS\system32\cmd.execf
2009-06-14 01:35:12 —-D—- C:\Program Files\Fichiers communs\xing shared
2009-06-14 01:17:16 —-A—- C:\WINDOWS\system32\rmoc3260.dll
2009-06-14 01:17:14 —-D—- C:\Program Files\Fichiers communs\Real
2009-06-14 01:17:14 —-A—- C:\WINDOWS\system32\pndx5032.dll
2009-06-14 01:17:14 —-A—- C:\WINDOWS\system32\pndx5016.dll
2009-06-14 01:17:14 —-A—- C:\WINDOWS\system32\pncrt.dll
2009-06-14 01:17:11 —-D—- C:\Program Files\Real
2009-06-14 01:16:28 —-D—- C:\Documents and Settings\Administrateur\Application Data\Real
2009-06-13 22:03:46 —-D—- C:\Program Files\Encore
2009-06-13 21:06:49 —-D—- C:\Program Files\ERUNT
2009-06-11 09:27:08 —-D—- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2009-06-11 09:27:05 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-11 09:27:05 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-06-10 10:10:10 —-RA—- C:\WINDOWS\system32\AdobePDFUI.dll
2009-06-10 10:10:10 —-RA—- C:\WINDOWS\system32\AdobePDF.dll
2009-06-10 10:08:49 —-D—- C:\Program Files\Fichiers communs\Adobe
2009-06-10 10:08:49 —-D—- C:\Program Files\Adobe
2009-06-10 10:08:49 —-D—- C:\Documents and Settings\All Users\Application Data\Adobe
2009-06-10 10:02:47 —-D—- C:\Program Files\Fichiers communs\EZB Systems
2009-06-10 10:02:46 —-D—- C:\Program Files\UltraISO
2009-06-10 09:01:06 —-D—- C:\Program Files\Lavasoft
2009-06-10 09:01:06 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-06-07 08:52:34 —-D—- C:\Program Files\Spybot - Search & Destroy
2009-06-07 08:52:34 —-D—- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-07 08:03:41 —-D—- C:\Documents and Settings\Administrateur\Application Data\Micro Application
2009-06-07 07:52:30 —-D—- C:\Documents and Settings\Administrateur\Application Data\mirkes.de
2009-06-07 04:35:43 —-D—- C:\Documents and Settings\All Users\Application Data\FLEXnet
2009-06-07 03:37:00 —-D—- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-07 02:25:58 —-D—- C:\WINDOWS\Sun
2009-06-02 10:18:26 —-D—- C:\Program Files\Fichiers communs\Autodesk Shared
2009-06-02 10:18:26 —-D—- C:\Program Files\AutoCAD 2010
2009-06-02 10:18:26 —-D—- C:\Documents and Settings\All Users\Application Data\Autodesk
2009-06-02 10:18:26 —-D—- C:\Documents and Settings\Administrateur\Application Data\Autodesk
2009-06-02 10:14:45 —-HDC—- C:\WINDOWS\$NtUninstallKB942288-v3$
2009-06-02 09:36:42 —-A—- C:\WINDOWS\system32\CSVer.dll
2009-06-02 09:34:53 —-D—- C:\WINDOWS\1C4551A64743409391E41477CD655043.TMP
2009-06-02 09:34:28 —-D—- C:\NVIDIA
2009-06-02 09:19:04 —-D—- C:\Documents and Settings\Administrateur\Application Data\vlc
2009-06-02 09:18:37 —-D—- C:\Program Files\VideoLAN
2009-06-02 09:07:56 —-N—- C:\WINDOWS\system32\spmsg.dll
2009-06-02 09:07:51 —-A—- C:\WINDOWS\system32\wmpns.dll
2009-06-02 09:07:06 —-D—- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-06-01 20:13:39 —-D—- C:\Program Files\JDownloader_0.4.533_Portable
2009-06-01 20:12:52 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2009-06-01 20:12:50 —-D—- C:\Program Files\Micro Application
2009-06-01 11:03:08 —-D—- C:\WINDOWS\RegisteredPackages
2009-06-01 11:02:56 —-A—- C:\WINDOWS\system32\psisdecd.dll
2009-06-01 11:02:55 —-A—- C:\WINDOWS\system32\dxdllreg.exe
2009-06-01 10:48:01 —-N—- C:\WINDOWS\system32\spmsg2.dll
2009-06-01 10:48:00 —-HDC—- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2009-06-01 10:46:51 —-D—- C:\WINDOWS\system32\XPSViewer
2009-06-01 10:46:50 —-D—- C:\Program Files\MSBuild
2009-06-01 10:46:49 —-D—- C:\WINDOWS\system32\en-US
2009-06-01 10:46:48 —-D—- C:\Program Files\Reference Assemblies
2009-06-01 10:46:35 —-N—- C:\WINDOWS\system32\xpsshhdr.dll
2009-06-01 10:46:35 —-N—- C:\WINDOWS\system32\prntvpt.dll
2009-06-01 10:46:34 —-N—- C:\WINDOWS\system32\xpssvcs.dll
2009-06-01 10:46:31 —-D—- C:\Documents and Settings\Administrateur\Application Data\Macromedia
2009-06-01 10:46:31 —-D—- C:\Documents and Settings\Administrateur\Application Data\Adobe
2009-06-01 10:21:14 —-D—- C:\Documents and Settings\All Users\Application Data\Macrovision
2009-06-01 10:20:15 —-D—- C:\Program Files\Fichiers communs\Macrovision Shared
2009-06-01 10:19:50 —-D—- C:\Program Files\Fichiers communs\Aladdin Shared
2009-06-01 10:19:50 —-A—- C:\WINDOWS\system32\hasplms.exe
2009-06-01 10:19:50 —-A—- C:\WINDOWS\system32\aksllmtp.exe
2009-06-01 10:19:47 —-D—- C:\WINDOWS\system32\RNBOSENT
2009-06-01 10:19:47 —-A—- C:\WINDOWS\system32\SNTI386.DLL
2009-06-01 10:19:47 —-A—- C:\WINDOWS\system32\RNBOVDD.DLL
2009-06-01 10:19:44 —-D—- C:\Program Files\SolidWorks SolidNetWork License Manager
2009-06-01 10:13:21 —-D—- C:\Program Files\Microsoft Works
2009-06-01 10:13:16 —-D—- C:\Program Files\Fichiers communs\DESIGNER
2009-06-01 10:13:10 —-D—- C:\Program Files\Microsoft.NET
2009-06-01 10:11:50 —-D—- C:\WINDOWS\SHELLNEW
2009-06-01 10:11:44 —-D—- C:\Program Files\Microsoft Office
2009-06-01 10:11:44 —-D—- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-06-01 10:05:44 —-RHD—- C:\MSOCache
2009-06-01 09:43:32 —-A—- C:\WINDOWS\system32\XceedZip.dll
2009-06-01 09:43:30 —-D—- C:\Program Files\Driver-Soft
2009-06-01 09:31:30 —-D—- C:\PHIL
2009-06-01 09:22:20 —-D—- C:\Documents and Settings\Administrateur\Application Data\Notepad++
2009-05-29 13:04:09 —-A—- C:\WINDOWS\system32\usbui.dll
2009-05-29 13:03:22 —-SHD—- C:\WINDOWS\Installer
2009-05-29 13:03:22 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2009-05-29 13:03:21 —-D—- C:\Program Files\Fichiers communs\ODBC
2009-05-29 13:03:21 —-A—- C:\WINDOWS\ODBCINST.INI
2009-05-29 13:03:19 —-D—- C:\Program Files\Fichiers communs\SpeechEngines
2009-05-29 13:03:19 —-D—- C:\Program Files\Fichiers communs\Microsoft Shared
2009-05-29 13:03:19 —-D—- C:\Program Files\Fichiers communs
2009-05-29 13:03:19 —-D—- C:\Program Files
2009-05-29 13:03:17 —-RA—- C:\WINDOWS\system32\kbdtuq.dll
2009-05-29 13:03:17 —-RA—- C:\WINDOWS\system32\kbdtuf.dll
2009-05-29 13:03:17 —-RA—- C:\WINDOWS\system32\kbdazel.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdycc.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbduzb.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdur.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdtat.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdru1.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdru.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdmon.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdkyr.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdkaz.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdbu.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdblr.dll
2009-05-29 13:03:16 —-RA—- C:\WINDOWS\system32\kbdaze.dll
2009-05-29 13:03:15 —-RA—- C:\WINDOWS\system32\kbdhept.dll
2009-05-29 13:03:15 —-RA—- C:\WINDOWS\system32\kbdhela3.dll
2009-05-29 13:03:15 —-RA—- C:\WINDOWS\system32\kbdhela2.dll
2009-05-29 13:03:15 —-RA—- C:\WINDOWS\system32\kbdhe319.dll
2009-05-29 13:03:15 —-RA—- C:\WINDOWS\system32\kbdhe220.dll
2009-05-29 13:03:15 —-RA—- C:\WINDOWS\system32\kbdhe.dll
2009-05-29 13:03:15 —-RA—- C:\WINDOWS\system32\kbdgkl.dll
2009-05-29 13:03:14 —-RA—- C:\WINDOWS\system32\kbdlv1.dll
2009-05-29 13:03:14 —-RA—- C:\WINDOWS\system32\kbdlv.dll
2009-05-29 13:03:14 —-RA—- C:\WINDOWS\system32\kbdlt1.dll
2009-05-29 13:03:14 —-RA—- C:\WINDOWS\system32\kbdlt.dll
2009-05-29 13:03:14 —-RA—- C:\WINDOWS\system32\kbdest.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdycl.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdsl1.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdsl.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdro.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdpl1.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdpl.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdhu1.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdhu.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdcz2.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdcz1.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdcz.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\kbdcr.dll
2009-05-29 13:03:13 —-RA—- C:\WINDOWS\system32\KBDAL.DLL
2009-05-29 13:03:11 —-A—- C:\WINDOWS\system32\irclass.dll
2009-05-29 13:03:10 —-A—- C:\WINDOWS\system32\spxcoins.dll
2009-05-29 13:03:10 —-A—- C:\WINDOWS\system32\EqnClass.Dll
2009-05-29 13:03:10 —-A—- C:\WINDOWS\system32\dgsetup.dll
2009-05-29 13:03:10 —-A—- C:\WINDOWS\system32\dgrpsetu.dll
2009-05-29 13:03:09 —-A—- C:\WINDOWS\TASKMAN.EXE
2009-05-29 13:03:09 —-A—- C:\WINDOWS\system32\batt.dll
2009-05-29 13:03:08 —-A—- C:\WINDOWS\NOTEPAD.EXE
2009-05-29 13:03:06 —-A—- C:\WINDOWS\system32\storprop.dll
2009-05-29 13:03:00 —-ASH—- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-05-29 13:01:11 —-D—- C:\WINDOWS\system32\CatRoot2
2009-05-29 13:01:11 —-D—- C:\WINDOWS\system32\CatRoot
2009-05-29 13:01:06 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-05-29 13:00:46 —-SHD—- C:\System Volume Information
2009-05-29 13:00:46 —-D—- C:\Documents and Settings
2009-05-29 12:59:19 —-SH—- C:\boot.ini
2009-05-29 12:57:15 —-SD—- C:\WINDOWS\Downloaded Program Files
2009-05-29 12:57:15 —-RSD—- C:\WINDOWS\Fonts
2009-05-29 12:57:15 —-RD—- C:\WINDOWS\Offline Web Pages
2009-05-29 12:57:15 —-D—- C:\WINDOWS\WinSxS
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Web
2009-05-29 12:57:15 —-D—- C:\WINDOWS\WBEM
2009-05-29 12:57:15 —-D—- C:\WINDOWS\twain_32
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Temp
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\wins
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\wbem
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\usmt
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\spool
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\ShellExt
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\Setup
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\ras
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\npp
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\mui
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\inetsrv
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\IME
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\icsxml
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\ias
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\fr-fr
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\fr
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\export
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\drivers
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\dhcp
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\config
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\3com_dmi
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\3076
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\2052
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\1054
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\1042
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\1041
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\1037
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\1036
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\1033
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\1031
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\1028
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32\1025
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system32
2009-05-29 12:57:15 —-D—- C:\WINDOWS\system
2009-05-29 12:57:15 —-D—- C:\WINDOWS\security
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Resources
2009-05-29 12:57:15 —-D—- C:\WINDOWS\repair
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Provisioning
2009-05-29 12:57:15 —-D—- C:\WINDOWS\PeerNet
2009-05-29 12:57:15 —-D—- C:\WINDOWS\pchealth
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Network Diagnostic
2009-05-29 12:57:15 —-D—- C:\WINDOWS\mui
2009-05-29 12:57:15 —-D—- C:\WINDOWS\msapps
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Media
2009-05-29 12:57:15 —-D—- C:\WINDOWS\L2Schemas
2009-05-29 12:57:15 —-D—- C:\WINDOWS\java
2009-05-29 12:57:15 —-D—- C:\WINDOWS\inf
2009-05-29 12:57:15 —-D—- C:\WINDOWS\ime
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Help
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Driver Cache
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Debug
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Cursors
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Connection Wizard
2009-05-29 12:57:15 —-D—- C:\WINDOWS\Config
2009-05-29 12:57:15 —-D—- C:\WINDOWS\AppPatch
2009-05-29 12:57:15 —-D—- C:\WINDOWS\addins
2009-05-29 12:57:15 —-D—- C:\WINDOWS
2009-05-29 12:13:31 —-D—- C:\Program Files\PowerISO
2009-05-29 12:05:32 —-D—- C:\Program Files\Astonsoft
2009-05-29 12:03:47 —-D—- C:\Program Files\ImgBurn
2009-05-29 11:59:50 —-D—- C:\WINDOWS\system32\AGEIA
2009-05-29 11:59:50 —-D—- C:\Program Files\AGEIA Technologies
2009-05-29 11:59:38 —-D—- C:\Program Files\Fichiers communs\Wise Installation Wizard
2009-05-29 11:59:10 —-D—- C:\WINDOWS\nview
2009-05-29 11:59:09 —-A—- C:\WINDOWS\system32\nvudisp.exe
2009-05-29 11:58:33 —-A—- C:\WINDOWS\system32\NVUNINST.EXE
2009-05-29 11:58:22 —-A—- C:\WINDOWS\system32\XAudio2_3.dll
2009-05-29 11:58:22 —-A—- C:\WINDOWS\system32\XAPOFX1_2.dll
2009-05-29 11:58:22 —-A—- C:\WINDOWS\system32\xactengine3_3.dll
2009-05-29 11:58:22 —-A—- C:\WINDOWS\system32\D3DX9_40.dll
2009-05-29 11:58:22 —-A—- C:\WINDOWS\system32\d3dx10_40.dll
2009-05-29 11:58:22 —-A—- C:\WINDOWS\system32\D3DCompiler_40.dll
2009-05-29 11:58:21 —-A—- C:\WINDOWS\system32\X3DAudio1_5.dll
2009-05-29 11:57:47 —-D—- C:\WINDOWS\system32\DirectX
2009-05-29 11:57:37 —-D—- C:\WINDOWS\Logs
2009-05-29 11:57:34 —-D—- C:\Program Files\EXPERTool
2009-05-29 11:48:43 —-D—- C:\WINDOWS\system32\Atheros_L1e
2009-05-29 11:47:30 —-A—- C:\WINDOWS\AS_Debug.txt
2009-05-29 11:45:00 —-DC—- C:\WINDOWS\system32\DRVSTORE
2009-05-29 11:44:59 —-D—- C:\Program Files\Intel
2009-05-29 11:44:47 —-D—- C:\Intel
2009-05-29 11:44:13 —-D—- C:\WINDOWS\system32\ReinstallBackups
2009-05-29 11:43:35 —-HD—- C:\Program Files\InstallShield Installation Information
2009-05-29 11:42:53 —-A—- C:\WINDOWS\system32\ksuser.dll
2009-05-29 11:42:30 —-N—- C:\WINDOWS\system32\difxapi.dll
2009-05-29 11:42:30 —-D—- C:\Program Files\VIA
2009-05-29 11:42:27 —-D—- C:\Program Files\Fichiers communs\InstallShield
2009-05-29 11:28:13 —-SHD—- C:\RECYCLER
2009-05-29 11:18:58 —-D—- C:\Documents and Settings\Administrateur\Application Data\Mozilla
2009-05-29 11:16:47 —-D—- C:\Documents and Settings\Administrateur\Application Data\VirtuaWin
2009-05-29 11:13:59 —-D—- C:\Program Files\VirtuaWin
2009-05-29 11:13:59 —-D—- C:\Program Files\7-Zip
2009-05-29 11:13:56 —-A—- C:\WINDOWS\system32\javaws.exe
2009-05-29 11:13:56 —-A—- C:\WINDOWS\system32\javaw.exe
2009-05-29 11:13:56 —-A—- C:\WINDOWS\system32\java.exe
2009-05-29 11:13:56 —-A—- C:\WINDOWS\system32\deploytk.dll
2009-05-29 11:13:50 —-D—- C:\Program Files\Java
2009-05-29 11:13:49 —-D—- C:\Documents and Settings\Administrateur\Application Data\Sun
2009-05-29 11:13:48 —-D—- C:\Program Files\WinRoll
2009-05-29 11:13:48 —-D—- C:\Program Files\Taskix
2009-05-29 11:13:48 —-D—- C:\Program Files\CCleaner
2009-05-29 11:13:46 —-D—- C:\Program Files\uTorrent
2009-05-29 11:13:46 —-D—- C:\Documents and Settings\Administrateur\Application Data\uTorrent
2009-05-29 11:13:43 —-D—- C:\Program Files\Mozilla Firefox
2009-05-29 11:13:41 —-D—- C:\Documents and Settings\Administrateur\Application Data\WinRAR
2009-05-29 11:13:40 —-D—- C:\Program Files\WinRAR
2009-05-29 11:13:38 —-A—- C:\WINDOWS\system32\ifsdrives.dll
2009-05-29 11:13:37 —-D—- C:\Program Files\GeekBox
2009-05-29 11:13:36 —-D—- C:\Program Files\IZArc
2009-05-29 11:11:34 —-D—- C:\Documents and Settings\Administrateur\Application Data\Identities
2009-05-29 11:11:32 —-HD—- C:\Program Files\Uninstall Information
2009-05-29 11:11:27 —-ASH—- C:\Documents and Settings\Administrateur\Application Data\desktop.ini
2009-05-29 11:11:26 —-SD—- C:\Documents and Settings\Administrateur\Application Data\Microsoft
2009-05-29 11:11:25 —-D—- C:\WINDOWS\SoftwareDistribution
2009-05-29 11:11:24 —-SD—- C:\WINDOWS\system32\Microsoft
2009-05-29 11:11:24 —-D—- C:\WINDOWS\Prefetch
2009-05-29 11:11:23 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-05-29 11:09:47 —-A—- C:\WINDOWS\system32\UnWTCC.exe
2009-05-29 11:09:17 —-RSD—- C:\WINDOWS\assembly
2009-05-29 11:09:09 —-D—- C:\WINDOWS\Microsoft.NET
2009-05-29 11:08:46 —-A—- C:\WINDOWS\control.ini
2009-05-29 11:08:46 —-A—- C:\AUTOEXEC.BAT
2009-05-29 11:08:32 —-D—- C:\WINDOWS\system32\dllcache
2009-05-29 11:08:32 —-A—- C:\WINDOWS\system32\mapi32.dll
2009-05-29 11:08:31 —-D—- C:\Program Files\Windows Trust
2009-05-29 11:08:29 —-D—- C:\WINDOWS\system32\LangDLLs
2009-05-29 11:08:24 —-D—- C:\Program Files\Paint.NET
2009-05-29 11:07:59 —-RAH—- C:\WINDOWS\system32\logonui.exe.manifest
2009-05-29 11:07:57 —-RAH—- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-05-29 11:07:54 —-HD—- C:\Program Files\WindowsUpdate
2009-05-29 11:07:45 —-D—- C:\Program Files\Windows Media Connect 2
2009-05-29 11:07:38 —-A—- C:\WINDOWS\system32\desktop.ini
2009-05-29 11:07:38 —-A—- C:\WINDOWS\desktop.ini
2009-05-29 11:07:36 —-D—- C:\Program Files\Fichiers communs\Services
2009-05-29 11:07:36 —-A—- C:\WINDOWS\system32\acctres.dll
2009-05-29 11:07:34 —-SD—- C:\WINDOWS\Tasks
2009-05-29 11:07:34 —-D—- C:\Program Files\Fichiers communs\MSSoap
2009-05-29 11:07:34 —-A—- C:\WINDOWS\system32\icfgnt5.dll
2009-05-29 11:07:31 —-A—- C:\WINDOWS\system32\wuweb.dll
2009-05-29 11:07:31 —-A—- C:\WINDOWS\system32\wuauserv.dll
2009-05-29 11:07:31 —-A—- C:\WINDOWS\system32\wuaueng1.dll
2009-05-29 11:07:30 —-A—- C:\WINDOWS\system32\wuauclt1.exe
2009-05-29 11:07:30 —-A—- C:\WINDOWS\system32\qmgrprxy.dll
2009-05-29 11:07:30 —-A—- C:\WINDOWS\system32\qmgr.dll
2009-05-29 11:07:30 —-A—- C:\WINDOWS\system32\bitsprx4.dll
2009-05-29 11:07:30 —-A—- C:\WINDOWS\system32\bitsprx3.dll
2009-05-29 11:07:30 —-A—- C:\WINDOWS\system32\bitsprx2.dll
2009-05-29 11:07:29 —-D—- C:\WINDOWS\system32\Restore
2009-05-29 11:07:29 —-A—- C:\WINDOWS\system32\srrstr.dll
2009-05-29 11:07:29 —-A—- C:\WINDOWS\system32\fltMc.exe
2009-05-29 11:07:29 —-A—- C:\WINDOWS\system32\fltlib.dll
2009-05-29 11:07:28 —-A—- C:\WINDOWS\system32\srsvc.dll
2009-05-29 11:07:28 —-A—- C:\WINDOWS\system32\srclient.dll
2009-05-29 11:07:28 —-A—- C:\WINDOWS\system32\msoert2.dll
2009-05-29 11:07:28 —-A—- C:\WINDOWS\system32\msoeacct.dll
2009-05-29 11:07:27 —-A—- C:\WINDOWS\system32\inetres.dll
2009-05-29 11:07:27 —-A—- C:\WINDOWS\system32\inetcomm.dll
2009-05-29 11:07:26 —-D—- C:\Program Files\Outlook Express
2009-05-29 11:07:26 —-A—- C:\WINDOWS\system32\schedsvc.dll
2009-05-29 11:07:26 —-A—- C:\WINDOWS\system32\mstinit.exe
2009-05-29 11:07:26 —-A—- C:\WINDOWS\system32\mstask.dll
2009-05-29 11:07:26 —-A—- C:\WINDOWS\system32\isign32.dll
2009-05-29 11:07:26 —-A—- C:\WINDOWS\system32\inetcfg.dll
2009-05-29 11:07:26 —-A—- C:\WINDOWS\system32\icwphbk.dll
2009-05-29 11:07:26 —-A—- C:\WINDOWS\system32\icwdial.dll
2009-05-29 11:07:22 —-D—- C:\Program Files\Internet Explorer
2009-05-29 11:07:22 —-D—- C:\Program Files\Fichiers communs\System
2009-05-29 11:06:55 —-D—- C:\Program Files\ComPlus Applications
2009-05-29 11:06:54 —-A—- C:\WINDOWS\vbaddin.ini
2009-05-29 11:06:54 —-A—- C:\WINDOWS\vb.ini
2009-05-29 11:06:51 —-D—- C:\WINDOWS\Registration
2009-05-29 11:06:44 —-D—- C:\Program Files\Windows Media Player
2009-05-29 11:06:37 —-D—- C:\Program Files\Unlocker
2009-05-29 11:06:37 —-D—- C:\Program Files\Notepad++
2009-05-29 11:06:30 —-D—- C:\Program Files\WTInstaller
2009-05-29 11:06:29 —-D—- C:\WINDOWS\system32\Macromed
2009-05-29 11:06:29 —-A—- C:\WINDOWS\system32\sndvol32.exe
2009-05-29 11:06:28 —-A—- C:\WINDOWS\system32\winmine.exe
2009-05-29 11:06:28 —-A—- C:\WINDOWS\system32\sol.exe
2009-05-29 11:06:28 —-A—- C:\WINDOWS\system32\getuname.dll
2009-05-29 11:06:28 —-A—- C:\WINDOWS\system32\charmap.exe
2009-05-29 11:06:28 —-A—- C:\WINDOWS\system32\calc.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\usrlogon.cmd
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\tsshutdn.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\tslabels.ini
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\tskill.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\tsdiscon.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\tscon.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\shadow.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\rwinsta.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\reset.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\regini.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\rdpcfgex.dll
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\qwinsta.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\qappsrv.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\mshearts.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\msg.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\logoff.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\freecell.exe
2009-05-29 11:06:27 —-A—- C:\WINDOWS\system32\cdmodem.dll
2009-05-29 11:06:26 —-A—- C:\WINDOWS\system32\msdtcprf.ini
2009-05-29 11:06:23 —-A—- C:\WINDOWS\system32\wmimgmt.msc
2009-05-29 11:06:23 —-A—- C:\WINDOWS\system32\spider.exe
2009-05-29 11:06:23 —-A—- C:\WINDOWS\system32\mplay32.exe
2009-05-29 11:06:22 —-A—- C:\WINDOWS\system32\tsgqec.dll
2009-05-29 11:06:22 —-A—- C:\WINDOWS\system32\tscfgwmi.dll
2009-05-29 11:06:22 —-A—- C:\WINDOWS\system32\rhttpaa.dll
2009-05-29 11:06:22 —-A—- C:\WINDOWS\system32\mstscax.dll
2009-05-29 11:06:22 —-A—- C:\WINDOWS\system32\mstsc.exe
2009-05-29 11:06:22 —-A—- C:\WINDOWS\system32\aaclient.dll
2009-05-29 11:06:21 —-D—- C:\WINDOWS\system32\MsDtc
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\termsrv.dll
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\remotepg.dll
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\rdshost.exe
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\rdsaddin.exe
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\rdpwsx.dll
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\rdpsnd.dll
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\rdpclip.exe
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\rdchost.dll
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\qprocess.exe
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\mtxoci.dll
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\msdtcuiu.dll
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\icaapi.dll
2009-05-29 11:06:21 —-A—- C:\WINDOWS\system32\cfgbkend.dll
2009-05-29 11:06:20 —-D—- C:\WINDOWS\system32\Com
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\xolehlp.dll
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\mtxlegih.dll
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\mtxex.dll
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\mtxdm.dll
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\msdtctm.dll
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\msdtcprx.dll
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\msdtclog.dll
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\msdtc.exe
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\dcomcnfg.exe
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\comrepl.dll
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\comaddin.dll
2009-05-29 11:06:20 —-A—- C:\WINDOWS\system32\colbact.dll
2009-05-29 11:06:19 —-A—- C:\WINDOWS\system32\stclient.dll
2009-05-29 11:06:19 —-A—- C:\WINDOWS\system32\comuid.dll
2009-05-29 11:06:19 —-A—- C:\WINDOWS\system32\comsvcs.dll
2009-05-29 11:06:19 —-A—- C:\WINDOWS\system32\comsnap.dll
2009-05-29 11:06:19 —-A—- C:\WINDOWS\system32\clbcatq.dll
2009-05-29 11:06:19 —-A—- C:\WINDOWS\system32\clbcatex.dll
2009-05-29 11:06:19 —-A—- C:\WINDOWS\system32\catsrvut.dll
2009-05-29 11:06:19 —-A—- C:\WINDOWS\system32\catsrvps.dll
2009-05-29 11:06:19 —-A—- C:\WINDOWS\system32\catsrv.dll
2009-05-29 11:06:15 —-A—- C:\WINDOWS\system32\servdeps.dll
2009-05-29 11:06:15 —-A—- C:\WINDOWS\system32\mmfutil.dll
2009-05-29 11:06:15 —-A—- C:\WINDOWS\system32\licwmi.dll
2009-05-29 11:06:15 —-A—- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2009-06-14 01:35:08 —-A—- C:\WINDOWS\system32\msvcr71.dll
2009-05-29 13:03:18 —-A—- C:\WINDOWS\system.ini
2009-05-29 11:08:43 —-A—- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-02-05 26944]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-02-05 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-02-05 51376]
R1 Ext2fs;Ext2fs; C:\WINDOWS\system32\DRIVERS\ext2fs.sys [2008-01-20 179584]
R1 IfsMount;IfsMount; C:\WINDOWS\system32\DRIVERS\ifsmount.sys [2007-12-29 49536]
R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2008-01-20 33292]
R2 aksfridge;aksfridge; \??\C:\WINDOWS\system32\drivers\aksfridge.sys []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-02-05 94032]
R2 Hardlock;Hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [1999-07-20 73216]
R2 TBPanel;TBPanel; C:\WINDOWS\system32\drivers\TBPanel.sys [2007-03-16 12256]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2009-03-31 38400]
R3 monfilt;monfilt; C:\WINDOWS\system32\drivers\monfilt.sys [2008-02-14 1389056]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-04-30 8055584]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\WINDOWS\system32\drivers\viahduaa.sys [2008-10-27 878976]
S1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys []
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-02-05 23152]
S3 Cardex;Cardex; \??\C:\WINDOWS\system32\drivers\TBPANEL.SYS []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-10-19 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-10-19 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Pilote de filtre de restauration système; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73600]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-05-12 611664]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 hasplms;HASP License Manager; C:\WINDOWS\system32\hasplms.exe [2008-03-19 2558464]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-05-29 152984]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-05-01 168004]
S2 SolidWorks SolidNetWork License Manager;SolidWorks SolidNetWork License Manager; C:\Program Files\SolidWorks SolidNetWork License Manager\lmgrd.exe [2007-05-11 1372160]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-06-02 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-24 918016]

—————–EOF—————–
Right, and this is the info file info.txt logfile of random's system information tool 1.06 2009-06-19 19:31:33 ======Uninstall list====== –>MsiExec /X{DD1865F0-AD73-40FB-B23E-1822E02396FF} 7-Zip 4.60 beta–>"C:\Program Files\7-Zip\Uninstall.exe" Ad-Aware–>MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF} Adobe Acrobat 9 Pro Extended - English, Français, Deutsch–>msiexec /I {AC76BA86-1033-F400-7761-000000000004} Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver–>"C:\Program Files\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\Setup.exe" -runfromtemp -l0x040c -removeonly AutoCAD 2010 - Français–>C:\Program Files\AutoCAD 2010\Setup\Setup.exe /P {5783F2D7-8001-040C-0002-0060B0CE6BBA} /M ACAD /language fr-FR AutoCAD 2010 - Français–>C:\Program Files\AutoCAD 2010\Setup\Setup.exe /P {5783F2D7-8001-040C-0002-0060B0CE6BBA} /M ACAD /language fr-FR avast! Antivirus–>C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup CCleaner–>"C:\Program Files\CCleaner\uninst.exe" Correctif pour Windows XP (KB942288-v3)–>"C:\WINDOWS\$NtUninstallKB942288-v3$\spuninst\spuninst.exe" DeepBurner Pro v1.9.0.228–>"C:\Program Files\Astonsoft\DeepBurner Pro\Uninstall.exe" "C:\Program Files\Astonsoft\DeepBurner Pro\install.log" -u Driver Genius Professional Edition–>"C:\Program Files\Driver-Soft\DriverGenius\unins000.exe" ERUNT 1.1j–>"C:\Program Files\ERUNT\unins000.exe" EXPERTool 7.3–>"C:\Program Files\EXPERTool\unins000.exe" Ext2IFS 1.11 XP–>RunDll32 setupapi.dll,InstallHinfSection DefaultUninstall 130 Ext2Ifs_for_NT501.inf GeekBox–>"C:\Program Files\GeekBox\Désinstaller.exe" HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)–>C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT="" ImgBurn–>"C:\Program Files\ImgBurn\uninstall.exe" IZArc 3.81–>"C:\Program Files\IZArc\uninstall.exe" Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF} Lecteur Windows Media 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA–>MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C} Microsoft .NET Framework 2.0 Service Pack 2–>MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA–>MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128} Microsoft .NET Framework 3.0 Service Pack 2–>MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7} Microsoft .NET Framework 3.5 Language Pack SP1 - fra–>MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31} Microsoft .NET Framework 3.5 SP1–>C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe Microsoft .NET Framework 3.5 SP1–>MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} Microsoft Office Access MUI (French) 2007–>MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE} Microsoft Office Excel MUI (French) 2007–>MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE} Microsoft Office InfoPath MUI (French) 2007–>MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE} Microsoft Office Outlook MUI (French) 2007–>MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE} Microsoft Office PowerPoint MUI (French) 2007–>MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE} Microsoft Office Professional Plus 2007–>"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL Microsoft Office Professional Plus 2007–>MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE} Microsoft Office Proof (Arabic) 2007–>MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE} Microsoft Office Proof (Dutch) 2007–>MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE} Microsoft Office Proof (English) 2007–>MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE} Microsoft Office Proof (French) 2007–>MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE} Microsoft Office Proof (German) 2007–>MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE} Microsoft Office Proof (Spanish) 2007–>MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE} Microsoft Office Proofing (French) 2007–>MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE} Microsoft Office Publisher MUI (French) 2007–>MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE} Microsoft Office Shared MUI (French) 2007–>MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE} Microsoft Office Word MUI (French) 2007–>MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE} Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17–>MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475} Module linguistique Microsoft .NET Framework 3.5 SP1- fra–>C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe Monkey's Audio–>"C:\Program Files\Monkey's Audio\unins000.exe" Mozilla Firefox (3.0.10)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe NVIDIA Drivers–>C:\WINDOWS\system32\nvuninst.exe UninstallGUI NVIDIA PhysX–>MsiExec.exe /X{DD1865F0-AD73-40FB-B23E-1822E02396FF} PC Optimiseur–>"C:\Program Files\Micro Application\PC Optimiseur\unins000.exe" PowerISO–>"C:\Program Files\PowerISO\uninstall.exe" Sentinel System Driver–>C:\WINDOWS\SYSTEM32\RNBOSENT\SETUPX86.EXE /U /q SolidWorks SolidNetWork License Manager–>MsiExec.exe /I{EDA561A4-9455-4FD7-9506-077040E0B78D} Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins000.exe" SWF Opener–>"C:\Program Files\UnH Solutions\SWF Opener\unins000.exe" Taskix–>"C:\Program Files\Taskix\Désinstaller.exe" Tekla Structures 14.0–>"C:\Program Files\InstallShield Installation Information\{FD750D58-13D4-4906-8847-48C63B9DB082}\setup.exe" -runfromtemp -l0x040c -removeonly UltraISO Premium V9.31–>"C:\Program Files\UltraISO\unins000.exe" Unlocker 1.8.7–>C:\Program Files\Unlocker\uninst.exe uTorrent–>"C:\Program Files\uTorrent\Désinstaller.exe" VIA Gestionnaire de périphériques de plate-forme–>C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169} VirtuaWin–>"C:\Program Files\VirtuaWin\Désinstaller.exe" VLC media player 0.9.9–>C:\Program Files\VideoLAN\VLC\uninstall.exe Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll Windows Trust Core Codecs–>"C:\WINDOWS\System32\UnWTCC.exe" Windows Trust Installer–>"C:\Program Files\WTInstaller\Désinstaller.exe" WinRAR–>"C:\Program Files\WinRAR\uninstall.exe" WinRoll–>"C:\Program Files\WinRoll\Désinstaller.exe" XML Paper Specification Shared Components Language Pack 1.0–>"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe" ======Hosts File====== 127.0.0.1 localhost 127.0.0.1 mpa.one.microsoft.com 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com Securitycenter WMI appears to be broken ======System event log====== Computer Name: R-DE1361BD3AE04 Event Code: 15007 Message: La réservation de l'espace de nom identifié par le préfixe d'URL http://*:2869/ a été correctement ajoutée. Record Number: 5 Source Name: HTTP Time Written: 20090529110753.000000+120 Event Type: Informations User: Computer Name: R-DE1361BD3AE04 Event Code: 6011 Message: Le nom NetBIOS et le nom de l'hôte DNS de cet ordinateur ont été modifiés de MACHINENAME vers R-DE1361BD3AE04. Record Number: 4 Source Name: EventLog Time Written: 20090529110540.000000+120 Event Type: Informations User: Computer Name: MACHINENAME Event Code: 2 Message: Pendant la validation de \Device\Serial0 en tant que port série, une FIFO a été détectée. La FIFO sera utilisée. Record Number: 3 Source Name: Serial Time Written: 20090529130113.000000+120 Event Type: Informations User: Computer Name: MACHINENAME Event Code: 6005 Message: Le service d'Enregistrement d'événement a démarré. Record Number: 2 Source Name: EventLog Time Written: 20090529130051.000000+120 Event Type: Informations User: Computer Name: MACHINENAME Event Code: 6009 Message: Microsoft ® Windows ® 5.01. 2600 Service Pack 3 Multiprocessor Free. Record Number: 1 Source Name: EventLog Time Written: 20090529130051.000000+120 Event Type: Informations User: =====Application event log===== Computer Name: R-DE1361BD3AE04 Event Code: 1000 Message: Les compteurs de performances pour le service MSDTC (MSDTC) ont été chargés. Les données d'enregistrement contiennent les nouvelles valeurs d'index assignées à ce service. Record Number: 5 Source Name: LoadPerf Time Written: 20090529110647.000000+120 Event Type: Informations User: Computer Name: R-DE1361BD3AE04 Event Code: 1000 Message: Les compteurs de performances pour le service TermService (Services Terminal Server) ont été chargés. Les données d'enregistrement contiennent les nouvelles valeurs d'index assignées à ce service. Record Number: 4 Source Name: LoadPerf Time Written: 20090529110644.000000+120 Event Type: Informations User: Computer Name: R-DE1361BD3AE04 Event Code: 1000 Message: Les compteurs de performances pour le service RemoteAccess (Routage et accès distant) ont été chargés. Les données d'enregistrement contiennent les nouvelles valeurs d'index assignées à ce service. Record Number: 3 Source Name: LoadPerf Time Written: 20090529110609.000000+120 Event Type: Informations User: Computer Name: R-DE1361BD3AE04 Event Code: 1000 Message: Les compteurs de performances pour le service PSched (PSched) ont été chargés. Les données d'enregistrement contiennent les nouvelles valeurs d'index assignées à ce service. Record Number: 2 Source Name: LoadPerf Time Written: 20090529110554.000000+120 Event Type: Informations User: Computer Name: R-DE1361BD3AE04 Event Code: 1000 Message: Les compteurs de performances pour le service RSVP (QoS RSVP) ont été chargés. Les données d'enregistrement contiennent les nouvelles valeurs d'index assignées à ce service. Record Number: 1 Source Name: LoadPerf Time Written: 20090529110547.000000+120 Event Type: Informations User: ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem "windir"=%SystemRoot% "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=6 "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 6, GenuineIntel "PROCESSOR_REVISION"=1706 "NUMBER_OF_PROCESSORS"=2 "SysDir"=C:\WINDOWS\system32 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "EDM_LIC13_4_5"=9GElXKtBOo3Pn'nSOzlg'fFqLnrsoc7Z-Gn_W)e24yPnET5x,GYMFwlj_zy —————–EOF—————–
hi,

thanks for the info. I dont recognize any malware in the log. You have run Adaware, Spybot, Malwarebytes and your Antivirus.
The point was to make sure your computer is malware free and it appears to be.
Dosnt look like your password was stolen via malware on your machine. The malware would have been detected.
We will get one more tool to use as another check. If it looks ok then you should follow the advice in that link.

download Gmer from one of these links;

http://www.castlecops.com/downloads-file-546.html
http://gmer.net/gmer.zip

unzip the file to your desktop.
doubleclick the gmer icon to start.
if you get a message box that says:

warning!!
Gmer has found system modification….
do you want to fully scan your system?

—>select NO<—

then click on the "scan" button
Dont check the 'show all' option
gmer will scan computer.
If you get a Rootkit warning window during the scan: click OK
When finished click "Save" to save log to your desktop
Copy/Paste the saved Gmer log in your reply.
Hi shelf life, I finally decided to close my hotmail account and create another one on a safer email provider. ANyway, here is the gmaer log. Thank you. Azert
Hi shelf life,
I finally decided to close my hotmail account and create another one on a safer email provider.
ANyway, here is the gmaer log.

Thank you.

Azert

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-20 01:23:24
Windows 5.1.2600 Service Pack 3, v.5657


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB3B1A6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB3B1AA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB3B1A14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB3B1A08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB3B1A0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB3B1A76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB3B1A72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB3B1A8AE]
SSDT \WINDOWS\system32\ntkrnlpa.exe (Noyau et système NT/Microsoft Corporation) ZwCreateKey [0x804D70CC]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D70CC] ZwCreateKey [0x804D70CC]
SSDT \WINDOWS\system32\ntkrnlpa.exe (Noyau et système NT/Microsoft Corporation) ZwOpenKey [0x804D70D1]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D70D1] ZwOpenKey [0x804D70D1]

INT 0x03 \WINDOWS\system32\ntkrnlpa.exe[unknown section] 804D70D6

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINDOWS\system32\services.exe[1120] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[1120] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Disk \Device\Harddisk0\DR0 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)

AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Disk \Device\Harddisk1\DR2 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

—- EOF - GMER 1.0.15 —-
hi azert56,

Your welcome. Looks like you didnt lose your password because of malware present on your machine. Phishing maybe?
You can delete the GMER icon. Here are some tips for reducing your risk to malware:

10 Tips for Reducing Your Risk To Malware:
The Short Version:

1) It is essential to Keep your OS,(Windows) browser (IE, FireFox) and other software up to date to "patch" vulnerabilities that could be exploited. This is also true for web based applications like Java, Adobe Flash/Reader, QuickTime etc. Check there version status here.

2) Know what you are installing to your computer. Alot of software can come bundled with unwanted add-ons, like adware, toolbars and malware. Do not install any files from ads, popups or random links. Do not fall for fake warnings about virus and trojans being found on your computer and your then prompted to install software to remedy this. See also the signs that you may have malware on your computer.

3) Install and keep updated: one antivirus and two or three anti-malware applications. If not updated they will soon be worthless. Scanning frequency is a function of your computer habits.

4) Refrain from clicking on links or attachments you receive via E-Mail, IM, IRC, Chat Rooms or Social Networking Sites, no matter how tempting or legitimate the message may seem.

5) Don't click on ads/pop ups or offers from websites requesting that you need to install software, media players or codecs to your computer–for any reason.

6) Don't click on offers to "scan" your computer. Install ActiveX Objects with care. Do you trust the website?

7) Set up and use limited accounts for everyday use, rather than administrator accounts. Limited accounts can help prevent *malware from installing.*

8) Install and understand the limitations of a software firewall.

9) Consider using an alternate browser and E-mail client. Internet Explorer and OutLook Express are popular targets for malicious code because they are widely used. See also: Hardening or Securing Internet Explorer.

10)Warez, cracks etc are very popular for carrying malware payloads. Avoid. If you install files via p2p networks then you are much more likely to encounter malicious code. Do you trust the source? Do you really need another malware source?

A longer version in link below.

Happy Safe Surfing.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI