This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet Explorer pops up and connects to random sites

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm sorry if this has been resolved x times. I've tried to search the forum, but not found anything of direct concern to me.

So like I wrote, IE (7) pops up uninvited and tries to access a variety of websites (Blueseek, xmlppc.com, what do I know).
I never use IE except when I have to. This was the case recenlty, some company having asked me to use their online test-case logging software, which runs only on IE.

The pop-ups have started before I started working with IE. I unfortunately tried to open a divx file which turned out to be a total fake. I'm afraid I might have gotten infected through there.

Thanks for any help!

I've run HijackThis and DDS. Here is my HJT log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 09:34:43, on 19.08.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17080)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\SDL International\License Server\Lmgrd.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SDL International\License Server\Lmgrd.exe
C:\Program Files\SDL International\License Server\trados.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\taskswitch.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\T2\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\T2\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files\SDL International\T2007\TT\TW4Win.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\SDL International\T2007\TT\SingletonResource.exe
C:\WINDOWS\system32\calc.exe
C:\DOCUMENTS AND SETTINGS\T2\DESKTOP\PROCEXP.EXE
C:\Documents and Settings\T2\Desktop\HijackThis.exe
C:\WINDOWS\system32\notepad.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…08&m=aoa150
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…08&m=aoa150
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…08&m=aoa150
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 193.120.222.150:5900
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Boingo Wi-Fi] "C:\Program Files\Boingo\Boingo Wi-Fi\Boingo.lnk"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\T2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O8 - Extra context menu item: Send by Bluetooth - C:\Program Files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
O8 - Extra context menu item: Send via &Message… - C:\Program Files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} (Loader Class v3) - http://qc.nokia.com/qcbin/Spider90.ocx
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Service Google Update (gupdate1c991f559cd37ea) (gupdate1c991f559cd37ea) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NewServiceInstall1 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SDL FLEXlm License Server - Macrovision Corporation - C:\Program Files\SDL International\License Server\Lmgrd.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 11920 bytes
Hello,

My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message to me on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________

Scanning with GMER

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

Notes:
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



NEXT:



Please download MBRCheck.exe to your Desktop. Run the application.

If no infection is found, it will produce a report on the desktop. Post that report in your next reply.

If an infection is found, you will be presented with the following dialog:

Enter 'Y' and hit ENTER for more options, or 'N' to exit:


Type N and press Enter. A report will be produced on the desktop. Post that report in your next reply.



NEXT:



  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Thank you for your answer. I hope I am not replying too late! I was quite busy and I'd rolled back IE to v. 6 which seemed to have solved the problem… I decided to do the process anyway. Never fear!

Attachments:

Hello,

Would you happen to have the OTL logs?

Also please do the following:

Please do the following:



Run MBRCheck again



When prompted, Enter 'Y' and hit ENTER for more options



When you see: "Enter your choice: Enter the physical disk number to dump (0-99, -1 to exit):"



Enter 0 to dump the MBR to the physical disk.



Name the dumped file as dump0.dat

Enter -1 to exit

A log file named "dump.dat" will be located in the same folder as MBRCheck was saved, please zip it up and attach in your next reply.
Here is the OTL.txt
I will post the second OTL report and then run MBRCheck again.
————————
OTL logfile created on: 23.08.2010 21:32:57 - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\T2\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000100C | Country: Switzerland | Language: FRS | Date Format: dd.MM.yyyy

1'012.00 Mb Total Physical Memory | 424.00 Mb Available Physical Memory | 42.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.17 Gb Total Space | 53.36 Gb Free Space | 37.01% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PEQUENINO
Current User Name: T2
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\T2\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\Documents and Settings\T2\Local Settings\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Documents and Settings\T2\Desktop\procexp.exe (Sysinternals - www.sysinternals.com)
PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\SDL International\License Server\trados.exe ()
PRC - C:\Program Files\SDL International\License Server\lmgrd.exe (Macrovision Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (SafeNet, Inc)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\T2\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (ServiceLayer) – C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (BlueSoleilCS) – C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe ()
SRV - (BsHelpCS) – C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe ()
SRV - (BsMobileCS) – C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe ()
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (lxdi_device) – C:\WINDOWS\System32\lxdicoms.exe ( )
SRV - (lxdiCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe ()
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (NewServiceInstall1) – C:\Program Files\SDL International\T2007\TT\Lng\Dialogs1031.lng ()
SRV - (SDL FLEXlm License Server) – C:\Program Files\SDL International\License Server\lmgrd.exe (Macrovision Corporation)
SRV - (SentinelProtectionServer) – C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (SafeNet, Inc)


========== Driver Services (SafeList) ==========

DRV - (upperdev) – C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (mcdbus) – C:\WINDOWS\System32\DRIVERS\mcdbus.sys File not found
DRV - (Wpsnuio) – C:\WINDOWS\system32\drivers\wpsnuio.sys (Skyhook Wireless)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (BtHidBus) – C:\WINDOWS\System32\Drivers\BtHidBus.sys (IVT Corporation.)
DRV - (JMCR) – C:\WINDOWS\system32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - (IvtBtBUs) – C:\WINDOWS\system32\drivers\IvtBtBus.sys (IVT Corporation.)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation.)
DRV - (Btcsrusb) – C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation.)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (BT) – C:\WINDOWS\system32\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation.)
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (Sentinel) – C:\WINDOWS\System32\Drivers\SENTINEL.SYS (SafeNet, Inc.)
DRV - (sfcure01) StarForce Cure Driver (version 1.x) – C:\WINDOWS\system32\drivers\sfcure01.sys ()
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (int15.sys) – C:\Acer\Empowering Technology\eRecovery\int15.sys ()
DRV - (DKbFltr) – C:\WINDOWS\system32\drivers\DKbFltr.SYS (Dritek System Inc.)
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (prohlp02) – C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (sfhlp01) – C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (prodrv06) – C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (prosync1) – C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…08&m=aoa150
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 193.120.222.150:5900

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ch/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.10 07:57:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.08.21 08:09:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.08.09 23:44:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010.08.09 23:44:17 | 000,000,000 | —D | M]

[2008.11.15 16:33:58 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Mozilla\Extensions
[2010.08.22 19:01:06 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\extensions
[2010.04.28 07:16:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009.03.04 15:30:50 | 000,001,504 | —- | M] () – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\searchplugins\imdb.xml
[2008.11.17 05:01:06 | 000,001,032 | —- | M] () – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\searchplugins\wikipedia-eng.xml
[2010.08.22 19:01:06 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010.03.29 09:55:27 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.05.25 15:43:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.04.12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009.11.30 18:59:59 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2008.11.20 13:04:50 | 000,239,432 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2010.03.13 16:49:04 | 000,001,516 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-france.xml
[2010.03.13 16:49:04 | 000,001,822 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\cnrtl-tlfi-fr.xml
[2010.03.13 16:49:04 | 000,000,757 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-france.xml
[2008.11.17 14:06:34 | 000,000,748 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\MediaDICO-fr.xml
[2010.03.13 16:49:06 | 000,001,426 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fr.xml
[2010.03.24 13:18:59 | 000,000,956 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-france.xml

O1 HOSTS File: ([2008.04.15 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Boingo Wi-Fi] C:\Program Files\Boingo\Boingo Wi-Fi\Boingo.lnk ()
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NokiaMusic FastStart] C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe (Nokia)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe File not found
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files\DAEMON Tools Pro\DTProAgent.exe (DT Soft Ltd.)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Send by Bluetooth - C:\Program Files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm ()
O8 - Extra context menu item: Send via &Message… - C:\Program Files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm ()
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} http://qc.nokia.com/qcbin/Spider90.ocx (Loader Class v3)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO: )
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\T2\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\T2\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O27 - HKLM IFEO\taskmgr.exe: Debugger - "C:\DOCUMENTS AND SETTINGS\T2\DESKTOP\PROCEXP.EXE" (Sysinternals - www.sysinternals.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.08.15 19:37:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{97e97b45-1570-11de-a42c-00234e802370}\Shell\AutoRun\command - "" = setupSNK.exe
O33 - MountPoints2\{bf7c498d-002f-11de-a423-00234e802370}\Shell\AutoRun\command - "" = E:\wd_windows_tools\setup.exe – File not found
O33 - MountPoints2\{f3e75971-0a79-11df-a491-00234e802370}\Shell\AutoRun\command - "" = F:\SamsungSoftware\APPInst.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2010.08.23 21:27:29 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\T2\Desktop\OTL.exe
[2010.08.23 16:56:17 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Local Settings\Application Data\IsolatedStorage
[2010.08.23 16:52:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nokia
[2010.08.23 16:52:10 | 000,018,816 | —- | C] (Nokia) – C:\WINDOWS\System32\drivers\pccsmcfd.sys
[2010.08.23 16:50:49 | 000,000,000 | —D | C] – C:\Program Files\Nokia
[2010.08.23 16:19:50 | 001,102,624 | —- | C] (Nokia) – C:\Documents and Settings\T2\Desktop\SetupOviPlayer.exe
[2010.08.20 16:48:46 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Desktop\muzic putain
[2010.08.19 09:17:45 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\T2\Desktop\HijackThis.exe
[2010.08.19 08:43:34 | 000,017,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2010.08.18 16:56:50 | 000,000,000 | —D | C] – C:\Program Files\Safari
[2010.08.18 15:21:15 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Local Settings\Application Data\Nokia
[2010.08.18 15:21:06 | 000,000,000 | —D | C] – C:\WINDOWS\Globalization
[2010.08.18 15:20:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NokiaMusic
[2010.08.18 15:17:38 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2010.08.15 21:03:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Data
[2010.08.15 21:01:11 | 000,197,632 | —- | C] (Microsoft) – C:\Program Files\Common Files\OnlineFilesManager.dll
[2010.08.09 23:51:15 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010.08.09 23:50:59 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010.08.09 23:50:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010.08.09 23:43:09 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010.08.09 23:34:54 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2009.08.21 18:28:50 | 000,356,352 | —- | C] ( ) – C:\WINDOWS\System32\lxdiinpa.dll
[2009.08.21 18:28:50 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdiiesc.dll
[2009.08.21 18:28:50 | 000,311,296 | —- | C] ( ) – C:\WINDOWS\System32\lxdihcp.dll
[2009.08.21 18:28:49 | 001,187,840 | —- | C] ( ) – C:\WINDOWS\System32\lxdiserv.dll
[2009.08.21 18:28:49 | 000,942,080 | —- | C] ( ) – C:\WINDOWS\System32\lxdiusb1.dll
[2009.08.21 18:28:48 | 000,614,400 | —- | C] ( ) – C:\WINDOWS\System32\lxdipmui.dll
[2009.08.21 18:28:48 | 000,532,480 | —- | C] ( ) – C:\WINDOWS\System32\lxdilmpm.dll
[2009.08.21 18:28:48 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdiprox.dll
[2009.08.21 18:28:48 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdipplc.dll
[2009.08.21 18:28:47 | 000,671,744 | —- | C] ( ) – C:\WINDOWS\System32\lxdihbn3.dll
[2009.08.21 18:28:45 | 000,765,952 | —- | C] ( ) – C:\WINDOWS\System32\lxdicomc.dll
[2009.08.21 18:28:45 | 000,360,448 | —- | C] ( ) – C:\WINDOWS\System32\lxdicomm.dll
[2007.04.02 06:40:54 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2005.11.23 01:55:32 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[19 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\T2\My Documents\*.tmp files -> C:\Documents and Settings\T2\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.08.23 21:27:30 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\T2\Desktop\OTL.exe
[2010.08.23 21:27:08 | 000,080,384 | —- | M] () – C:\Documents and Settings\T2\Desktop\MBRCheck.exe
[2010.08.23 21:09:02 | 000,001,054 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.08.23 21:06:01 | 000,001,134 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2094639727-349796869-1728803408-1006UA.job
[2010.08.23 20:40:45 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010.08.23 20:22:19 | 000,024,832 | —- | M] () – C:\WINDOWS\System32\18221926541.dll
[2010.08.23 20:20:30 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010.08.23 20:20:08 | 000,001,050 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.08.23 20:20:03 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010.08.23 20:19:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010.08.23 20:19:42 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2010.08.23 19:14:30 | 000,284,915 | —- | M] () – C:\Documents and Settings\T2\Desktop\gmer.zip
[2010.08.23 19:09:55 | 000,332,280 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.23 16:56:47 | 000,084,184 | —- | M] () – C:\Documents and Settings\T2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010.08.23 16:53:22 | 008,388,608 | -H– | M] () – C:\Documents and Settings\T2\NTUSER.DAT
[2010.08.23 16:53:12 | 000,526,486 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010.08.23 16:53:12 | 000,451,768 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010.08.23 16:53:12 | 000,075,906 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010.08.23 16:52:55 | 000,001,880 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Nokia Ovi Player.lnk
[2010.08.23 16:52:55 | 000,001,876 | —- | M] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\Nokia Ovi Player.lnk
[2010.08.23 16:19:51 | 001,102,624 | —- | M] (Nokia) – C:\Documents and Settings\T2\Desktop\SetupOviPlayer.exe
[2010.08.23 13:46:15 | 000,043,266 | —- | M] () – C:\Documents and Settings\T2\Desktop\4917217001L_1.jpg
[2010.08.23 11:51:44 | 000,162,816 | —- | M] () – C:\Documents and Settings\T2\Desktop\intervenants I-2-pro.doc
[2010.08.23 08:00:02 | 000,000,374 | —- | M] () – C:\WINDOWS\tasks\WakeywakeyHandsoffSnakey.job
[2010.08.23 01:06:00 | 000,001,082 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2094639727-349796869-1728803408-1006Core.job
[2010.08.21 08:18:06 | 000,055,096 | —- | M] () – C:\Documents and Settings\T2\Desktop\2426363_20100820130300.zip
[2010.08.20 18:08:50 | 000,000,347 | —- | M] () – C:\WINDOWS\mercury.ini
[2010.08.20 12:49:57 | 000,022,900 | —- | M] () – C:\Documents and Settings\T2\Desktop\item_2_010_010_fr.xml.ttx
[2010.08.20 07:42:24 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010.08.19 11:34:06 | 000,000,819 | —- | M] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010.08.19 11:32:11 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\T2\ntuser.ini
[2010.08.19 09:17:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\T2\Desktop\HijackThis.exe
[2010.08.18 17:59:50 | 000,000,000 | -H– | M] () – C:\Documents and Settings\T2\My Documents\Default.rdp
[2010.08.18 16:57:43 | 000,057,896 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010.08.18 15:27:02 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010.08.18 15:20:08 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010.08.18 15:17:41 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010.08.15 21:01:11 | 000,197,632 | —- | M] (Microsoft) – C:\Program Files\Common Files\OnlineFilesManager.dll
[2010.08.15 20:59:01 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010.08.06 11:34:22 | 000,017,408 | —- | M] () – C:\Documents and Settings\T2\My Documents\Budgetisation.xls
[2010.07.30 19:20:28 | 004,768,204 | -H– | M] () – C:\Documents and Settings\T2\Local Settings\Application Data\IconCache.db
[2010.07.27 08:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[19 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\T2\My Documents\*.tmp files -> C:\Documents and Settings\T2\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.08.23 21:27:07 | 000,080,384 | —- | C] () – C:\Documents and Settings\T2\Desktop\MBRCheck.exe
[2010.08.23 20:40:45 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010.08.23 20:22:19 | 000,024,832 | —- | C] () – C:\WINDOWS\System32\18221926541.dll
[2010.08.23 19:15:13 | 000,293,376 | —- | C] () – C:\Documents and Settings\T2\Desktop\gmer.exe
[2010.08.23 19:14:28 | 000,284,915 | —- | C] () – C:\Documents and Settings\T2\Desktop\gmer.zip
[2010.08.23 16:52:55 | 000,001,880 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Nokia Ovi Player.lnk
[2010.08.23 16:52:55 | 000,001,876 | —- | C] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\Nokia Ovi Player.lnk
[2010.08.23 13:46:14 | 000,043,266 | —- | C] () – C:\Documents and Settings\T2\Desktop\4917217001L_1.jpg
[2010.08.23 11:46:44 | 000,162,816 | —- | C] () – C:\Documents and Settings\T2\Desktop\intervenants I-2-pro.doc
[2010.08.21 08:17:37 | 000,055,096 | —- | C] () – C:\Documents and Settings\T2\Desktop\2426363_20100820130300.zip
[2010.08.20 12:48:48 | 000,022,900 | —- | C] () – C:\Documents and Settings\T2\Desktop\item_2_010_010_fr.xml.ttx
[2010.08.18 17:59:50 | 000,000,000 | -H– | C] () – C:\Documents and Settings\T2\My Documents\Default.rdp
[2010.08.18 16:57:43 | 000,057,896 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010.08.18 16:20:35 | 000,002,528 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2010.08.18 16:18:18 | 000,518,520 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010.08.18 15:27:02 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010.08.18 15:17:41 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010.06.28 09:25:22 | 000,000,347 | —- | C] () – C:\WINDOWS\mercury.ini
[2010.04.14 14:24:45 | 000,036,352 | —- | C] () – C:\WINDOWS\System32\SX32W.DLL
[2010.01.19 18:45:14 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010.01.19 18:45:14 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2010.01.18 21:36:36 | 000,002,143 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010.01.18 21:18:39 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009.10.10 16:22:40 | 000,002,528 | —- | C] () – C:\Documents and Settings\T2\Application Data\$_hpcst$.hpc
[2009.08.21 18:31:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdivs.dll
[2009.08.21 18:31:18 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\lxdicoin.dll
[2009.08.21 18:30:11 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\lxdicaps.dll
[2009.08.21 18:30:10 | 000,692,224 | —- | C] () – C:\WINDOWS\System32\lxdidrs.dll
[2009.08.21 18:30:10 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdicnv4.dll
[2009.08.21 18:28:50 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\lxdiinst.dll
[2009.08.21 18:28:47 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdigrd.dll
[2009.05.05 21:40:31 | 000,002,686 | —- | C] () – C:\WINDOWS\System32\SHORTCUT.INI
[2009.05.05 21:39:48 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\REMOTEDEVICE.INI
[2009.05.05 21:38:30 | 000,004,535 | —- | C] () – C:\WINDOWS\System32\LOCALSERVICE.INI
[2009.05.05 21:38:28 | 000,000,101 | —- | C] () – C:\WINDOWS\System32\LOCALDEVICE.INI
[2009.05.05 21:30:46 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\BSPRINT.INI
[2009.04.17 19:18:12 | 000,685,816 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009.04.16 21:12:45 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\drivers\sfcure01.sys
[2009.02.06 11:01:24 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS45.DLL
[2008.11.17 15:38:34 | 000,052,736 | —- | C] () – C:\Documents and Settings\T2\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.11.16 18:40:00 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008.11.16 03:39:04 | 000,000,125 | —- | C] () – C:\Documents and Settings\T2\Local Settings\Application Data\fusioncache.dat
[2008.08.30 09:36:18 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008.08.04 18:04:44 | 000,000,951 | —- | C] () – C:\WINDOWS\System32\bscs.ini
[2008.08.04 17:36:50 | 000,405,589 | —- | C] () – C:\WINDOWS\System32\BsUI.dll
[2008.08.01 15:58:50 | 000,278,647 | —- | C] () – C:\WINDOWS\System32\outlookAddin.dll
[2008.08.01 15:58:30 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\HtmPrintHelper.dll
[2008.08.01 15:58:14 | 000,622,693 | —- | C] () – C:\WINDOWS\System32\BSShell.dll
[2008.08.01 15:56:14 | 000,098,403 | —- | C] () – C:\WINDOWS\System32\Bs2Res.dll
[2008.08.01 15:55:40 | 000,118,880 | —- | C] () – C:\WINDOWS\System32\BsMobileSDK.dll
[2008.08.01 15:55:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\BsMobileCSps.dll
[2008.08.01 15:46:30 | 017,907,824 | —- | C] () – C:\WINDOWS\System32\BsLangInDepRes.dll
[2008.08.01 15:46:30 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\BsVistaCommon.dll
[2008.07.31 04:37:26 | 000,006,782 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008.05.16 10:12:30 | 000,000,036 | —- | C] () – C:\WINDOWS\PidList.ini
[2008.04.15 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008.02.15 07:21:56 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2007.10.01 08:59:46 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2007.05.09 09:16:40 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2006.09.18 15:37:50 | 000,000,530 | —- | C] () – C:\WINDOWS\System32\tx12_ic.ini
[2006.09.18 15:37:48 | 000,667,280 | —- | C] () – C:\WINDOWS\System32\tx12.dll
[2005.03.29 00:45:26 | 000,000,153 | —- | C] () – C:\WINDOWS\ALaunch.ini
[2004.06.07 00:00:00 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\XVIDCORE.DLL
[2004.06.07 00:00:00 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\XVIDVFW.DLL

========== LOP Check ==========

[2008.12.04 13:57:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2DBoy
[2010.02.08 20:36:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010.02.04 18:57:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2009.04.19 08:34:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010.05.18 07:42:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoBoingo
[2010.02.01 11:23:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2010.08.18 15:20:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NokiaMusic
[2010.07.27 20:01:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010.04.14 14:15:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SDL International
[2008.11.17 05:29:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TRADOS
[2010.05.21 11:34:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEngineLite
[2010.08.09 23:52:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009.09.26 12:54:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.07.06 18:18:33 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Ableton
[2010.05.26 19:57:53 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\avidemux
[2009.10.10 12:31:45 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.04.19 08:33:45 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\DAEMON Tools Pro
[2009.10.20 17:56:23 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\FileZilla
[2010.05.08 12:05:51 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\foobar2000
[2009.11.30 19:00:08 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Foxit
[2010.01.04 15:32:26 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Foxit Software
[2010.03.22 11:39:20 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\GCMSWorkbench.2C30485F6B8C679517FCFDBDF0D73C7F278DFACC.1
[2009.05.05 21:04:27 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\GetRightToGo
[2009.08.21 18:35:17 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Lexmark Productivity Studio
[2010.08.18 15:22:01 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Nokia
[2010.04.12 17:58:39 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Notepad++
[2009.09.03 00:35:17 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\OpenOffice.org
[2008.12.11 07:47:54 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Opera
[2010.02.15 16:56:12 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\PC Suite
[2009.11.18 01:04:32 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\ScummVM
[2009.02.26 13:40:03 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\SDL International
[2010.06.16 13:18:29 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\SystemRequirementsLab
[2008.11.21 04:44:08 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Thunderbird
[2008.12.03 15:09:13 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Trados
[2010.08.23 13:19:49 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\uTorrent
[2010.06.05 11:51:22 | 000,000,564 | —- | M] () – C:\WINDOWS\Tasks\12-March_to_the_Shore-FYU.job
[2010.08.23 08:00:02 | 000,000,374 | —- | M] () – C:\WINDOWS\Tasks\WakeywakeyHandsoffSnakey.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008.08.15 19:37:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010.01.26 11:43:41 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2008.08.15 19:37:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010.08.23 20:19:42 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2008.08.15 19:37:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010.02.11 11:14:28 | 000,003,163 | —- | M] () – C:\license.lic
[2008.08.15 19:37:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008.04.15 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008.04.15 05:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010.08.23 20:19:40 | 1585,446,912 | -HS- | M] () – C:\pagefile.sys
[2008.08.30 09:40:32 | 000,000,080 | —- | M] () – C:\Preload.aaa
[2008.08.15 19:57:08 | 000,000,542 | —- | M] () – C:\RHDSetup.log
[2010.04.14 14:13:15 | 145,245,184 | —- | M] () – C:\SDLT2007.msi
[2009.04.20 18:20:23 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009.04.20 18:45:49 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009.04.20 18:50:41 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009.04.20 19:05:00 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009.04.20 19:08:33 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009.04.20 19:41:06 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009.04.21 20:58:05 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009.10.10 14:48:25 | 000,000,292 | -H– | M] () – C:\sqmdata07.sqm
[2009.11.05 20:28:09 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009.03.12 04:08:03 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009.04.14 17:03:07 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009.04.16 16:45:39 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009.04.16 20:41:01 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009.04.17 17:54:07 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009.04.19 08:27:34 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2009.04.19 08:58:38 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009.04.20 18:04:40 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2009.04.20 18:07:28 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009.04.20 18:11:36 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009.04.20 18:17:50 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009.04.20 18:20:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009.04.20 18:45:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009.04.20 18:50:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009.04.20 19:04:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009.04.20 19:08:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009.04.20 19:41:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009.04.21 20:58:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009.10.10 14:48:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009.11.05 20:28:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009.03.12 04:08:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009.04.14 17:03:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009.04.16 16:45:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009.04.16 20:41:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009.04.17 17:54:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009.04.19 08:27:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009.04.19 08:58:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009.04.20 18:04:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009.04.20 18:07:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009.04.20 18:11:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009.04.20 18:17:49 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[1999.11.11 09:17:54 | 000,000,049 | —- | M] () – C:\XPH.TAG

< %systemroot%\Fonts\*.com >
[2006.04.18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006.06.29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006.04.18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006.06.29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008.08.15 19:37:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002.02.11 23:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD45.DLL
[2002.02.11 23:00:00 | 000,043,008 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP45.DLL
[2008.07.06 14:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007.03.15 23:08:12 | 000,113,664 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdidrpp.dll
[2007.04.09 07:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006.10.27 04:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008.07.06 12:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008.08.15 12:29:32 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008.08.15 12:29:32 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008.08.15 12:29:32 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008.08.15 19:37:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008.11.16 07:22:48 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008.08.15 19:43:46 | 000,000,079 | —- | M] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009.12.15 11:24:48 | 000,293,376 | —- | M] () – C:\Documents and Settings\T2\Desktop\gmer.exe
[2010.08.19 09:17:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\T2\Desktop\HijackThis.exe
[2010.08.23 21:27:08 | 000,080,384 | —- | M] () – C:\Documents and Settings\T2\Desktop\MBRCheck.exe
[2010.08.23 21:27:30 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\T2\Desktop\OTL.exe
[2008.08.06 11:27:08 | 003,520,552 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Documents and Settings\T2\Desktop\procexp.exe
[2010.08.23 16:19:51 | 001,102,624 | —- | M] (Nokia) – C:\Documents and Settings\T2\Desktop\SetupOviPlayer.exe

< %PROGRAMFILES%\Common Files\*.* >
[2010.08.15 21:01:11 | 000,197,632 | —- | M] (Microsoft) – C:\Program Files\Common Files\OnlineFilesManager.dll

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-21 06:03:07
< End of report >
OTL report #2: Extras.txt
———–
OTL Extras logfile created on: 23.08.2010 21:32:57 - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\T2\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000100C | Country: Switzerland | Language: FRS | Date Format: dd.MM.yyyy

1'012.00 Mb Total Physical Memory | 424.00 Mb Available Physical Memory | 42.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.17 Gb Total Space | 53.36 Gb Free Space | 37.01% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PEQUENINO
Current User Name: T2
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"56753:TCP" = 56753:TCP:*:Enabled:Pando P2P TCP Listening Port
"56753:UDP" = 56753:UDP:*:Enabled:Pando P2P UDP Listening Port
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Lexmark 3500-4500 Series\app4r.exe" = C:\Program Files\Lexmark 3500-4500 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio – ()
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – File not found
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Pando Networks\Pando\pando.exe" = C:\Program Files\Pando Networks\Pando\pando.exe:*:Enabled:Pando Application – (Pando Networks)
"C:\Documents and Settings\T2\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\T2\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\T2\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\T2\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – File not found
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe" = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:*:Enabled:BlueSoleilCS – ()
"C:\WINDOWS\system32\lxdicoms.exe" = C:\WINDOWS\system32\lxdicoms.exe:*:Enabled:3500-4500 Series Server – ( )
"C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe" = C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe:*:Enabled:Device Monitor – ()
"C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe" = C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe:*:Enabled:Device Monitor Application – ()
"C:\Program Files\Lexmark 3500-4500 Series\App4R.exe" = C:\Program Files\Lexmark 3500-4500 Series\App4R.exe:*:Enabled:Printing Application – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdipswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdipswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdijswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdijswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxditime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxditime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe:*:Enabled:QuickBooks 2008 Data Manager – (iAnywhere Solutions, Inc.)
"C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe" = C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe:*:Disabled:Sentinel Protection Server – (SafeNet, Inc)
"C:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe" = C:\Program Files\Real Alternative\Media Player Classic\mplayerc.exe:*:Enabled:Media Player Classic – (Gabest)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0FA44E79-CD7D-4E8D-A2EE-26FE05F509B6}" = OpenOffice.org 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Outil de téléchargement Windows Live
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{235C31BC-BBAE-4932-9F17-15395C65907B}" = Boingo Wi-Fi
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 20
"{26B878A8-5704-3B64-BDBC-4F0EACA38121}" = Google Talk Plugin
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros for Acer Driver v7.6.0.224_Foxconn Installation Program
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36BC9F01-8A14-11DB-8605-005056C00008}" = Boingo SDK Lite (Fiberlinkcomm)
"{36E71ED6-AC20-4AED-8C51-0030EE7FB55B}" = SDLX
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Acer Crystal Eye webcam
"{3A08B59E-A9F0-4F4D-B7E5-6875D7F13327}" = Brother MFL-Pro Suite DCP-145C
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{465B20FE-0674-4399-AA03-98E1FDA47CA9}" = SDL FLEXlm License Server
"{46ABBC54-1872-4AA3-95E2-F2C063A63F31}" = Installation Windows Live
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E074808-1B86-4230-A9EB-0904942EC4AE}" = LEGO Star Wars II
"{50D25574-2C48-4AEC-8FFC-32AEAD2EAEFF}" = Nokia Ovi Player
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{679068CA-C9E9-4C22-A90D-2C4F2881EF9C}" = Bluesoleil [removed]
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69C76448-D4B8-4886-A848-61CD4EB4B2C7}" = SDL Trados 2007
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6DC0632A-A838-4B34-AC19-0FA18E1C533C}" = Sentinel Protection Installer 7.2.2
"{70737F2A-A6C7-2D27-1ED8-E9F535CD6408}" = GCMS Workbench
"{70B31335-50EE-4834-8431-27412CDE62BD}" = Nokia_Multimedia_Common_Components_2_5
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{770F1BEC-2871-4E70-B837-FB8525FFA3B1}" = Windows Live Messenger
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{80A27BF9-6D38-4218-9648-CB8314475123}" = Chinese Homework
"{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}" = Windows Live Call
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8ECB8220-F423-4BEB-9596-97033C533702}" = QuickBooks Premier: Accountant Edition 2008
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A7050037-F0EA-4BAB-BCD5-FC05507D6147}" = Alt-Tab Task Switcher Powertoy for Windows XP
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{AC76BA86-7AD7-2447-0000-900000000003}" = Chinese Simplified Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5760-0000-900000000003}" = Japanese Fonts Support For Adobe Reader 9
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{B9C9DB4C-6D77-4AE9-AD1C-C708C23239A0}" = Nokia Connectivity Cable Driver
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE98383B-7BB4-457C-AEAB-D89E9537628F}" = SDLX
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DCBC91E4-B72B-4E0A-97C9-D4EF389A132A}" = PC Connectivity Solution
"{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}" = Assistant de connexion Windows Live
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EAFEF30E-3789-49C7-A6D9-77C12E005BAC}" = Safari
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"ApSIC Xbench" = ApSIC Xbench 2.7
"AudioShell_is1" = AudioShell 1.3.5
"avast5" = avast! Free Antivirus
"Avidemux 2.5" = Avidemux 2.5
"Banana50_is1" = Banana Accounting 5.0
"C5A76DC11BABDA0A881E7BE8DDEB641365A77FFD" = Windows Driver Package - Nokia Modem (05/22/2008 3.8)
"CDDB MP3 Tool" = CDDB MP3 Tool (remove only)
"CDisplay_is1" = CDisplay 1.8
"Coda" = Coda codec pack
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"FileZilla Client" = FileZilla Client [removed]
"foobar2000" = foobar2000 v1.0.3
"Foxit Reader" = Foxit Reader
"GCMSWorkbench.2C30485F6B8C679517FCFDBDF0D73C7F278DFACC.1" = GCMS Workbench
"GeTax PP 2009" = GeTax PP 2009
"Google Updater" = Google Updater
"HDMI" = Intel® Graphics Media Accelerator Driver
"Homeworld2" = Homeworld2
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{4E074808-1B86-4230-A9EB-0904942EC4AE}" = LEGO Star Wars II
"Lexmark 3500-4500 Series" = Lexmark 3500-4500 Series
"LManager" = Launch Manager
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Morphyre" = Morphyre
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"Mozilla Thunderbird (2.0.0.24)" = Mozilla Thunderbird (2.0.0.24)
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notepad++" = Notepad++
"OTIS·trans" = OTIS·trans v2.3
"Picasa 3" = Picasa 3
"Postal Fudge Pack" = Postal Fudge Pack
"Psych" = The Psychedelic Screen Saver
"RealAlt_is1" = Real Alternative 1.9.0
"ScummVM_is1" = ScummVM 1.0.0
"Skyhook Wireless Wi-Fi Service" = Skyhook Wireless Wi-Fi Service
"SMAC 2.0" = SMAC 2.0
"SubtitleWorkshop" = Subtitle Workshop 2.51
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"VLC media player" = VLC media player 1.1.0
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"WinLiveSuite_Wave3" = Installation Windows Live
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"Wordfast" = Wordfast
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player
"pdfsam" = pdfsam
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 08.10.2009 14:57:30 | Computer Name = PEQUENINO | Source = avast! | ID = 33554522
Description =

Error - 08.10.2009 14:58:49 | Computer Name = PEQUENINO | Source = avast! | ID = 33554522
Description =

Error - 08.10.2009 14:59:07 | Computer Name = PEQUENINO | Source = avast! | ID = 33554522
Description =

Error - 09.11.2009 17:12:02 | Computer Name = PEQUENINO | Source = avast! | ID = 33554522
Description =

Error - 09.11.2009 17:20:22 | Computer Name = PEQUENINO | Source = avast! | ID = 33554522
Description =

[ Application Events ]
Error - 23.08.2010 10:25:56 | Computer Name = PEQUENINO | Source = Nokia Software Installer | ID = 1
Description = Nokia Software Installer 3.1.414 (NLib 0.7.487) Permission denied errorcode: 13

Stack
trace: .\NHttpFileDownload.cpp(379) : CNHttpFileDownload::WorkerProc .\NHttpFileDownload.cpp(445)
: CNHttpFileDownloadInfo::WaitForReady .\NHTTPRequest.cpp(56) : CNHTTPRequest::StatusCallback
.\NHTTPRequest.cpp(624)
: CNHTTPRequest::HandleStatusCallback .\NHttpFileDownload.cpp(627) : CNHttpFileDownloadInfo::PartialDataReceived
.\NFile.cpp(46)
: CNFile::Open .\NFile.cpp(86) : CNFile::OpenEx .\NFile.cpp(84) : CNFile::OpenEx

Error - 23.08.2010 10:26:01 | Computer Name = PEQUENINO | Source = Nokia Software Installer | ID = 1
Description = Nokia Software Installer 3.1.414 (NLib 0.7.487) Permission denied Stack
trace: .\NHTTPRequest.cpp(56) : CNHTTPRequest::StatusCallback .\NHTTPRequest.cpp(624)
: CNHTTPRequest::HandleStatusCallback .\NHttpFileDownload.cpp(627) : CNHttpFileDownloadInfo::PartialDataReceived
.\NFile.cpp(46)
: CNFile::Open .\NFile.cpp(86) : CNFile::OpenEx .\NFile.cpp(84) : CNFile::OpenEx

Error - 23.08.2010 10:26:01 | Computer Name = PEQUENINO | Source = Nokia Software Installer | ID = 1
Description = Nokia Software Installer 3.1.414 (NLib 0.7.487) Permission denied errorcode: 13

Stack
trace: .\NHttpFileDownload.cpp(379) : CNHttpFileDownload::WorkerProc .\NHttpFileDownload.cpp(445)
: CNHttpFileDownloadInfo::WaitForReady .\NHTTPRequest.cpp(56) : CNHTTPRequest::StatusCallback
.\NHTTPRequest.cpp(624)
: CNHTTPRequest::HandleStatusCallback .\NHttpFileDownload.cpp(627) : CNHttpFileDownloadInfo::PartialDataReceived
.\NFile.cpp(46)
: CNFile::Open .\NFile.cpp(86) : CNFile::OpenEx .\NFile.cpp(84) : CNFile::OpenEx

Error - 23.08.2010 10:26:07 | Computer Name = PEQUENINO | Source = Nokia Software Installer | ID = 1
Description = Nokia Software Installer 3.1.414 (NLib 0.7.487) Permission denied Stack
trace: .\NHTTPRequest.cpp(56) : CNHTTPRequest::StatusCallback .\NHTTPRequest.cpp(624)
: CNHTTPRequest::HandleStatusCallback .\NHttpFileDownload.cpp(627) : CNHttpFileDownloadInfo::PartialDataReceived
.\NFile.cpp(46)
: CNFile::Open .\NFile.cpp(86) : CNFile::OpenEx .\NFile.cpp(84) : CNFile::OpenEx

Error - 23.08.2010 10:26:07 | Computer Name = PEQUENINO | Source = Nokia Software Installer | ID = 1
Description = Nokia Software Installer 3.1.414 (NLib 0.7.487) Permission denied errorcode: 13

Stack
trace: .\NHttpFileDownload.cpp(379) : CNHttpFileDownload::WorkerProc .\NHttpFileDownload.cpp(445)
: CNHttpFileDownloadInfo::WaitForReady .\NHTTPRequest.cpp(56) : CNHTTPRequest::StatusCallback
.\NHTTPRequest.cpp(624)
: CNHTTPRequest::HandleStatusCallback .\NHttpFileDownload.cpp(627) : CNHttpFileDownloadInfo::PartialDataReceived
.\NFile.cpp(46)
: CNFile::Open .\NFile.cpp(86) : CNFile::OpenEx .\NFile.cpp(84) : CNFile::OpenEx

Error - 23.08.2010 10:27:23 | Computer Name = PEQUENINO | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 nokiaoviplayer.exe, P2 2.1.10304.0, P3 4b8fcac0,
P4 mscorlib, P5 2.0.0.0, P6 4be90358, P7 42d6, P8 34, P9 pszqoadhx1u5zahbhohghldgiy4qixhx,
P10 NIL.

Error - 23.08.2010 10:28:01 | Computer Name = PEQUENINO | Source = MsiInstaller | ID = 11722
Description = Produkt: Nokia Ovi Player – Fehler 1722. Es liegt ein dieses Windows
Installer-Paket betreffendes Problem vor. Ein Programm, das im Rahmen der Installation
ausgeführt wurde, wurde nicht erfolgreich abgeschlossen. Wenden Sie sich an das
Supportpersonal oder den Hersteller des Pakets. Aktion: LAUNCH_NOKIA_MUSIC_INSTALL,
Pfad: C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe, Befehl: /command:install
"1031" "W"

Error - 23.08.2010 10:28:03 | Computer Name = PEQUENINO | Source = Nokia Software Installer | ID = 1
Description = Nokia Software Installer 3.1.414 (NLib 0.7.487) Setup failed with exit
code 1603. Command line used: http://nds2.fds-ncom.nokia.com:80/files/su…_1_10304_de.exe
/L1031 /s /V" /qn REBOOT=ReallySuppress APPLANG=\"1031\" INSTALLSOURCE=\"W\" INSTALLDIR=\"C:\Program
Files\Nokia\Ovi Player\" EULAACCEPTED=True"

Error - 23.08.2010 10:28:18 | Computer Name = PEQUENINO | Source = Application Error | ID = 1000
Description = Faulting application nokiaoviplayer.exe, version 2.1.10304.0, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 23.08.2010 10:28:22 | Computer Name = PEQUENINO | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 nokiaoviplayer.exe, P2 2.1.10304.0, P3 4b8fcac0,
P4 mscorlib, P5 2.0.0.0, P6 4be90358, P7 42d6, P8 34, P9 pszqoadhx1u5zahbhohghldgiy4qixhx,
P10 NIL.

[ System Events ]
Error - 23.08.2010 13:51:41 | Computer Name = PEQUENINO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the SENS service.

Error - 23.08.2010 13:53:31 | Computer Name = PEQUENINO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Apple Mobile Device service.

Error - 23.08.2010 13:54:21 | Computer Name = PEQUENINO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Schedule service.

Error - 23.08.2010 13:54:53 | Computer Name = PEQUENINO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Apple Mobile Device service.

Error - 23.08.2010 13:55:31 | Computer Name = PEQUENINO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Schedule service.

Error - 23.08.2010 13:55:52 | Computer Name = PEQUENINO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Spooler service.

Error - 23.08.2010 13:56:22 | Computer Name = PEQUENINO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Apple Mobile Device service.

Error - 23.08.2010 14:02:01 | Computer Name = PEQUENINO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the wuauserv service.

Error - 23.08.2010 14:02:49 | Computer Name = PEQUENINO | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Bonjour Service service.

Error - 23.08.2010 14:21:10 | Computer Name = PEQUENINO | Source = Service Control Manager | ID = 7000
Description = The NewServiceInstall1 service failed to start due to the following
error: %%193


< End of report >
Hello,

Do you have any idea what this is:

C:\WINDOWS\tasks\WakeywakeyHandsoffSnakey.job ?

or this one:

C:\WINDOWS\Tasks\12-March_to_the_Shore-FYU.job ?

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 193.120.222.150:5900
    FF - prefs.js..network.proxy.type: 0
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O4 - HKLM..\Run: [KernelFaultCheck] File not found
    O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe File not found
    O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O33 - MountPoints2\{97e97b45-1570-11de-a42c-00234e802370}\Shell\AutoRun\command - "" = setupSNK.exe
    O33 - MountPoints2\{bf7c498d-002f-11de-a423-00234e802370}\Shell\AutoRun\command - "" = E:\wd_windows_tools\setup.exe – File not found
    O33 - MountPoints2\{f3e75971-0a79-11df-a491-00234e802370}\Shell\AutoRun\command - "" = F:\SamsungSoftware\APPInst.exe – File not found
    [2010.08.23 20:22:19 | 000,024,832 | —- | M] () – C:\WINDOWS\System32\18221926541.dll
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
OK, will do… WakeywakeyHandsoffsnakey is a schduled task I set where Windows would open a Winamp playlist, working as an alarm clock. Actually, MArch to the shore is also such an "alarm clock" task.
Hello,

Here's my OTL fix report.
You might be interested to know IE opened three of those effing windows after reboot.

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Prefs.js: 0 removed from network.proxy.type
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\snp2uvc deleted successfully.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{97e97b45-1570-11de-a42c-00234e802370}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97e97b45-1570-11de-a42c-00234e802370}\ not found.
File setupSNK.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf7c498d-002f-11de-a423-00234e802370}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7c498d-002f-11de-a423-00234e802370}\ not found.
File E:\wd_windows_tools\setup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f3e75971-0a79-11df-a491-00234e802370}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f3e75971-0a79-11df-a491-00234e802370}\ not found.
File F:\SamsungSoftware\APPInst.exe not found.
C:\WINDOWS\system32\18221926541.dll moved successfully.
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\T2\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\T2\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point (0)

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 41406 bytes

User: Guest
->Temp folder emptied: 1300679 bytes
->Temporary Internet Files folder emptied: 16438319 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 719 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 8310382 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: T2
->Temp folder emptied: 142447631 bytes
->Temporary Internet Files folder emptied: 437299887 bytes
->Java cache emptied: 65853453 bytes
->FireFox cache emptied: 44521539 bytes
->Google Chrome cache emptied: 15359734 bytes
->Apple Safari cache emptied: 14943232 bytes
->Opera cache emptied: 34090961 bytes
->Flash cache emptied: 111059 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 17554449 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 188494588 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 77544512 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 79291 bytes

Total Files Cleaned = 1'015.00 mb


[EMPTYFLASH]

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: Guest
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

User: T2
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.10.0 log created on 08242010_134417

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot…
Running TDSSKiller

Please read carefully and follow these steps.
TDSSKiller found one suspicious file. 2010/08/25 17:24:15.0046 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23 2010/08/25 17:24:15.0046 ================================================================================ 2010/08/25 17:24:15.0046 SystemInfo: 2010/08/25 17:24:15.0046 2010/08/25 17:24:15.0046 OS Version: 5.1.2600 ServicePack: 3.0 2010/08/25 17:24:15.0046 Product type: Workstation 2010/08/25 17:24:15.0046 ComputerName: PEQUENINO 2010/08/25 17:24:15.0046 UserName: T2 2010/08/25 17:24:15.0046 Windows directory: C:\WINDOWS 2010/08/25 17:24:15.0046 System windows directory: C:\WINDOWS 2010/08/25 17:24:15.0046 Processor architecture: Intel x86 2010/08/25 17:24:15.0046 Number of processors: 2 2010/08/25 17:24:15.0046 Page size: 0x1000 2010/08/25 17:24:15.0046 Boot type: Normal boot 2010/08/25 17:24:15.0046 ================================================================================ 2010/08/25 17:24:15.0953 Initialize success 2010/08/25 17:24:18.0828 ================================================================================ 2010/08/25 17:24:18.0828 Scan started 2010/08/25 17:24:18.0828 Mode: Manual; 2010/08/25 17:24:18.0828 ================================================================================ 2010/08/25 17:24:21.0250 Aavmker4 (31a8ab3deb93e3d90717ad8fb0974c3f) C:\WINDOWS\system32\drivers\Aavmker4.sys 2010/08/25 17:24:21.0328 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 2010/08/25 17:24:21.0375 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2010/08/25 17:24:21.0406 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 2010/08/25 17:24:21.0453 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 2010/08/25 17:24:21.0515 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2010/08/25 17:24:21.0593 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 2010/08/25 17:24:21.0640 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 2010/08/25 17:24:21.0687 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 2010/08/25 17:24:21.0718 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 2010/08/25 17:24:21.0781 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 2010/08/25 17:24:21.0812 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 2010/08/25 17:24:21.0859 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 2010/08/25 17:24:21.0906 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 2010/08/25 17:24:21.0937 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 2010/08/25 17:24:21.0968 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 2010/08/25 17:24:22.0078 AR5416 (7cae93fe5511d0c0688cfa56cf241e31) C:\WINDOWS\system32\DRIVERS\athw.sys 2010/08/25 17:24:22.0156 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 2010/08/25 17:24:22.0187 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 2010/08/25 17:24:22.0218 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 2010/08/25 17:24:22.0328 aswFsBlk (a289930e70f3fa3b07df80d2b052794e) C:\WINDOWS\system32\drivers\aswFsBlk.sys 2010/08/25 17:24:22.0375 aswMon2 (1aca2b7efe91ca68ceed9c904ed3310d) C:\WINDOWS\system32\drivers\aswMon2.sys 2010/08/25 17:24:22.0421 aswRdr (cc40b9c301af5d145713b2764eec3907) C:\WINDOWS\system32\drivers\aswRdr.sys 2010/08/25 17:24:22.0484 aswSP (67db88b01fc1d815968230458814eb8d) C:\WINDOWS\system32\drivers\aswSP.sys 2010/08/25 17:24:22.0531 aswTdi (ec8ef1ce2d6ca1071be8b7888ffa48c0) C:\WINDOWS\system32\drivers\aswTdi.sys 2010/08/25 17:24:22.0593 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2010/08/25 17:24:22.0640 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2010/08/25 17:24:22.0718 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2010/08/25 17:24:22.0796 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2010/08/25 17:24:22.0875 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2010/08/25 17:24:23.0000 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys 2010/08/25 17:24:23.0093 BT (32ccf60f6e491a2a931a63e928677403) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys 2010/08/25 17:24:23.0140 Btcsrusb (8f55a8a0b5e3cc98a5b99621a8cab959) C:\WINDOWS\system32\Drivers\btcusb.sys 2010/08/25 17:24:23.0203 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys 2010/08/25 17:24:23.0234 BtHidBus (69511655f2563b3719e0290065369f08) C:\WINDOWS\system32\Drivers\BtHidBus.sys 2010/08/25 17:24:23.0281 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys 2010/08/25 17:24:23.0359 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys 2010/08/25 17:24:23.0437 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys 2010/08/25 17:24:23.0468 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 2010/08/25 17:24:23.0515 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2010/08/25 17:24:23.0562 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2010/08/25 17:24:23.0593 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 2010/08/25 17:24:23.0656 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2010/08/25 17:24:23.0687 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2010/08/25 17:24:23.0734 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2010/08/25 17:24:23.0828 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 2010/08/25 17:24:23.0859 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 2010/08/25 17:24:23.0906 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 2010/08/25 17:24:23.0968 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 2010/08/25 17:24:24.0031 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 2010/08/25 17:24:24.0062 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 2010/08/25 17:24:24.0125 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2010/08/25 17:24:24.0171 DKbFltr (08d30af92c270f2e76787c81589dbad6) C:\WINDOWS\system32\DRIVERS\DKbFltr.sys 2010/08/25 17:24:24.0250 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2010/08/25 17:24:24.0312 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2010/08/25 17:24:24.0359 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2010/08/25 17:24:24.0437 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2010/08/25 17:24:24.0515 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 2010/08/25 17:24:24.0578 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2010/08/25 17:24:24.0687 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2010/08/25 17:24:24.0750 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 2010/08/25 17:24:24.0796 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2010/08/25 17:24:24.0843 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 2010/08/25 17:24:24.0890 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2010/08/25 17:24:24.0937 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2010/08/25 17:24:24.0968 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2010/08/25 17:24:25.0046 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 2010/08/25 17:24:25.0078 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2010/08/25 17:24:25.0171 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2010/08/25 17:24:25.0250 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2010/08/25 17:24:25.0296 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 2010/08/25 17:24:25.0375 HPZid412 (5faba4775d4c61e55ec669d643ffc71f) C:\WINDOWS\system32\DRIVERS\HPZid412.sys 2010/08/25 17:24:25.0453 HPZipr12 (a3c43980ee1f1beac778b44ea65dbdd4) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 2010/08/25 17:24:25.0531 HPZius12 (2906949bd4e206f2bb0dd1896ce9f66f) C:\WINDOWS\system32\DRIVERS\HPZius12.sys 2010/08/25 17:24:25.0609 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2010/08/25 17:24:25.0671 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 2010/08/25 17:24:25.0703 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 2010/08/25 17:24:25.0750 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2010/08/25 17:24:26.0062 ialm (48846b31be5a4fa662ccfde7a1ba86b9) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 2010/08/25 17:24:26.0375 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2010/08/25 17:24:26.0437 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 2010/08/25 17:24:26.0531 int15.sys (4d8d5b1c895ea0f2a721b98a7ce198f1) C:\Acer\Empowering Technology\eRecovery\int15.sys 2010/08/25 17:24:26.0734 IntcAzAudAddService (19afbb8427ce65042599555e578170df) C:\WINDOWS\system32\drivers\RtkHDAud.sys 2010/08/25 17:24:26.0906 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 2010/08/25 17:24:26.0968 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2010/08/25 17:24:27.0031 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2010/08/25 17:24:27.0062 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2010/08/25 17:24:27.0125 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2010/08/25 17:24:27.0187 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2010/08/25 17:24:27.0234 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2010/08/25 17:24:27.0296 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2010/08/25 17:24:27.0328 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2010/08/25 17:24:27.0406 IvtBtBUs (71e1fc547cc488d5cd7bf0860c96f5af) C:\WINDOWS\system32\Drivers\IvtBtBus.sys 2010/08/25 17:24:27.0484 JMCR (da971cfc625d13636e04c405948e9d62) C:\WINDOWS\system32\DRIVERS\jmcr.sys 2010/08/25 17:24:27.0546 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2010/08/25 17:24:27.0640 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2010/08/25 17:24:27.0687 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2010/08/25 17:24:27.0734 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2010/08/25 17:24:27.0953 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2010/08/25 17:24:28.0015 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2010/08/25 17:24:28.0046 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2010/08/25 17:24:28.0109 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2010/08/25 17:24:28.0140 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2010/08/25 17:24:28.0171 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 2010/08/25 17:24:28.0218 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2010/08/25 17:24:28.0296 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2010/08/25 17:24:28.0359 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2010/08/25 17:24:28.0437 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2010/08/25 17:24:28.0468 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2010/08/25 17:24:28.0500 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2010/08/25 17:24:28.0562 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2010/08/25 17:24:28.0656 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2010/08/25 17:24:28.0687 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2010/08/25 17:24:28.0750 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2010/08/25 17:24:28.0812 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2010/08/25 17:24:28.0843 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2010/08/25 17:24:28.0875 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2010/08/25 17:24:28.0937 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2010/08/25 17:24:28.0984 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2010/08/25 17:24:29.0015 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 2010/08/25 17:24:29.0062 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2010/08/25 17:24:29.0140 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2010/08/25 17:24:29.0250 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2010/08/25 17:24:29.0328 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2010/08/25 17:24:29.0390 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2010/08/25 17:24:29.0421 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2010/08/25 17:24:29.0453 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2010/08/25 17:24:29.0531 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 2010/08/25 17:24:29.0562 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2010/08/25 17:24:29.0609 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2010/08/25 17:24:29.0687 PCASp50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\WINDOWS\system32\Drivers\PCASp50.sys 2010/08/25 17:24:29.0750 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys 2010/08/25 17:24:29.0781 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2010/08/25 17:24:29.0843 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2010/08/25 17:24:29.0906 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2010/08/25 17:24:30.0062 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 2010/08/25 17:24:30.0109 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 2010/08/25 17:24:30.0234 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2010/08/25 17:24:30.0328 prodrv06 (5ac2dcbbceb5534bfcd88c2670993f3c) C:\WINDOWS\System32\drivers\prodrv06.sys 2010/08/25 17:24:30.0390 prohlp02 (7a78181cc947cdaa0902e113cfd01e93) C:\WINDOWS\system32\drivers\prohlp02.sys 2010/08/25 17:24:30.0421 prosync1 (f3471e7971ee62420451d958da635064) C:\WINDOWS\system32\drivers\prosync1.sys 2010/08/25 17:24:30.0468 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2010/08/25 17:24:30.0515 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2010/08/25 17:24:30.0578 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2010/08/25 17:24:30.0640 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 2010/08/25 17:24:30.0687 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 2010/08/25 17:24:30.0734 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 2010/08/25 17:24:30.0781 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 2010/08/25 17:24:30.0812 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 2010/08/25 17:24:30.0875 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2010/08/25 17:24:30.0921 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2010/08/25 17:24:30.0968 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2010/08/25 17:24:31.0000 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2010/08/25 17:24:31.0062 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2010/08/25 17:24:31.0125 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2010/08/25 17:24:31.0187 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2010/08/25 17:24:31.0250 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2010/08/25 17:24:31.0312 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2010/08/25 17:24:31.0390 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys 2010/08/25 17:24:31.0500 RTLE8023xp (f0a21c62b9b835e1c96268eaae31d239) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 2010/08/25 17:24:31.0609 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2010/08/25 17:24:31.0703 Sentinel (b3c1b187fefc941f63ce0df93d02eb9f) C:\WINDOWS\System32\Drivers\SENTINEL.SYS 2010/08/25 17:24:31.0765 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 2010/08/25 17:24:31.0890 sfcure01 (d5dcbe1e0ca236fbb3dfcfdc07e14b6f) C:\WINDOWS\system32\drivers\sfcure01.sys 2010/08/25 17:24:31.0937 sfdrv01 (00de597b81b381053cb5b21a7f20e365) C:\WINDOWS\system32\drivers\sfdrv01.sys 2010/08/25 17:24:31.0984 sfhlp01 (91f99f3e331e24c438819a38a1ad049c) C:\WINDOWS\system32\drivers\sfhlp01.sys 2010/08/25 17:24:32.0015 sfhlp02 (64b9ab76f1b16eb059cb6cdd906c067a) C:\WINDOWS\system32\drivers\sfhlp02.sys 2010/08/25 17:24:32.0078 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2010/08/25 17:24:32.0109 sfsync02 (798d918d8f20380008277ce3ce5319d1) C:\WINDOWS\system32\drivers\sfsync02.sys 2010/08/25 17:24:32.0203 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 2010/08/25 17:24:32.0265 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2010/08/25 17:24:32.0406 SNP2UVC (0302bc619d4a723317e7f8eb0c362bd3) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys 2010/08/25 17:24:32.0515 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 2010/08/25 17:24:32.0562 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2010/08/25 17:24:32.0656 sptd (d390675b8ce45e5fb359338e5e649329) C:\WINDOWS\system32\Drivers\sptd.sys 2010/08/25 17:24:32.0671 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d390675b8ce45e5fb359338e5e649329 2010/08/25 17:24:32.0671 sptd - detected Locked file (1) 2010/08/25 17:24:32.0703 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2010/08/25 17:24:32.0781 Srv (da852e3e0bf1cea75d756f9866241e57) C:\WINDOWS\system32\DRIVERS\srv.sys 2010/08/25 17:24:32.0875 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2010/08/25 17:24:32.0937 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2010/08/25 17:24:33.0000 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2010/08/25 17:24:33.0046 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 2010/08/25 17:24:33.0093 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 2010/08/25 17:24:33.0140 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 2010/08/25 17:24:33.0171 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 2010/08/25 17:24:33.0250 SynTP (409f7eeb079d6154ccb26a02e6e27844) C:\WINDOWS\system32\DRIVERS\SynTP.sys 2010/08/25 17:24:33.0281 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2010/08/25 17:24:33.0406 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2010/08/25 17:24:33.0468 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2010/08/25 17:24:33.0500 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2010/08/25 17:24:33.0531 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2010/08/25 17:24:33.0625 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 2010/08/25 17:24:33.0671 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2010/08/25 17:24:33.0718 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 2010/08/25 17:24:33.0781 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2010/08/25 17:24:33.0937 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\WINDOWS\system32\Drivers\usbaapl.sys 2010/08/25 17:24:34.0031 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2010/08/25 17:24:34.0109 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2010/08/25 17:24:34.0140 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2010/08/25 17:24:34.0203 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2010/08/25 17:24:34.0265 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2010/08/25 17:24:34.0312 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2010/08/25 17:24:34.0359 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2010/08/25 17:24:34.0437 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys 2010/08/25 17:24:34.0484 VComm (0955553090e0a88614e5b8a02af9324c) C:\WINDOWS\system32\DRIVERS\VComm.sys 2010/08/25 17:24:34.0531 VcommMgr (d773fd957514550fe72ba8eb6af8c7b6) C:\WINDOWS\system32\Drivers\VcommMgr.sys 2010/08/25 17:24:34.0578 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2010/08/25 17:24:34.0640 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 2010/08/25 17:24:34.0671 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 2010/08/25 17:24:34.0734 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2010/08/25 17:24:34.0828 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2010/08/25 17:24:34.0890 wceusbsh (46a247f6617526afe38b6f12f5512120) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys 2010/08/25 17:24:34.0984 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\Drivers\wdf01000.sys 2010/08/25 17:24:35.0078 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2010/08/25 17:24:35.0218 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 2010/08/25 17:24:35.0296 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\Drivers\wpdusb.sys 2010/08/25 17:24:35.0390 Wpsnuio (904571ee28f8f7d98b3ef1635a77c6d4) C:\WINDOWS\system32\DRIVERS\wpsnuio.sys 2010/08/25 17:24:35.0453 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2010/08/25 17:24:35.0515 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2010/08/25 17:24:35.0578 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2010/08/25 17:24:35.0750 ================================================================================ 2010/08/25 17:24:35.0750 Scan finished 2010/08/25 17:24:35.0750 ================================================================================ 2010/08/25 17:24:35.0781 Detected object count: 1 2010/08/25 17:24:45.0109 Locked file(sptd) - User select action: Skip
Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.



NEXT:



Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI