This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet Explorer pops up and connects to random sites

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, Here is my Combofix log: After running CF, at startup, Windows Firewall told me he was "blocking some features" of Windows Explorer and if I want to keep blocking. Funny thing, because before I've been getting "Explorer has encountered a problem and needs to close" at random times today. IE was still trying to connect randomly before CF run. Don't know about now… will see… ComboFix 10-08-26.04 - T2 01.09.2010 11:10:17.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.41.1033.18.1012.562 [GMT 2:00] Lancé depuis: c:\documents and settings\T2\Desktop\ComboFix.exe AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} * Un nouveau point de restauration a été créé . (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\85916041.dll . ((((((((((((((((((((((((((((( Fichiers créés du 2010-08-01 au 2010-09-01 )))))))))))))))))))))))))))))))))))) . 2010-08-24 11:44 . 2010-08-24 11:44 ——– d—–w- C:\_OTL 2010-08-23 18:40 . 2010-08-23 18:40 664 —-a-w- c:\windows\system32\d3d9caps.dat 2010-08-23 14:56 . 2010-08-23 14:56 ——– d—–w- c:\documents and settings\T2\Local Settings\Application Data\IsolatedStorage 2010-08-23 14:52 . 2010-08-26 09:00 ——– d—–w- c:\program files\Common Files\Nokia 2010-08-23 14:52 . 2008-08-26 08:26 18816 —-a-w- c:\windows\system32\drivers\pccsmcfd.sys 2010-08-23 14:50 . 2010-08-26 09:00 ——– d—–w- c:\program files\Nokia 2010-08-18 14:57 . 2010-08-18 14:57 57896 —ha-w- c:\windows\system32\mlfcache.dat 2010-08-18 14:56 . 2010-08-18 14:57 ——– d—–w- c:\program files\Safari 2010-08-18 14:18 . 2010-08-27 21:14 690656 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2010-08-18 13:21 . 2010-08-25 15:32 ——– d—–w- c:\documents and settings\T2\Local Settings\Application Data\Nokia 2010-08-18 13:21 . 2010-08-26 08:59 ——– d—–w- c:\windows\Globalization 2010-08-18 13:20 . 2010-08-18 13:20 ——– d—–w- c:\documents and settings\All Users\Application Data\NokiaMusic 2010-08-18 13:17 . 2010-08-18 13:27 ——– d—–w- c:\windows\system32\drivers\UMDF 2010-08-15 19:03 . 2010-09-01 09:14 ——– d—–w- c:\program files\Common Files\Data 2010-08-15 19:01 . 2010-08-15 19:01 197632 —-a-w- c:\program files\Common Files\OnlineFilesManager.dll 2010-08-13 13:20 . 2010-08-13 13:20 503808 —-a-w- c:\documents and settings\T2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-70b90442-n\msvcp71.dll 2010-08-13 13:20 . 2010-08-13 13:20 499712 —-a-w- c:\documents and settings\T2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-70b90442-n\jmc.dll 2010-08-13 13:20 . 2010-08-13 13:20 348160 —-a-w- c:\documents and settings\T2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-70b90442-n\msvcr71.dll 2010-08-13 13:20 . 2010-08-13 13:20 61440 —-a-w- c:\documents and settings\T2\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-16850e93-n\decora-sse.dll 2010-08-13 13:20 . 2010-08-13 13:20 12800 —-a-w- c:\documents and settings\T2\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-16850e93-n\decora-d3d.dll 2010-08-09 21:51 . 2010-08-09 21:51 ——– d—–w- c:\program files\iPod 2010-08-09 21:50 . 2010-08-09 21:52 ——– d—–w- c:\program files\iTunes 2010-08-09 21:50 . 2010-08-09 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521} 2010-08-09 21:43 . 2010-08-09 21:44 ——– d—–w- c:\program files\QuickTime 2010-08-09 21:34 . 2010-08-09 21:34 ——– d—–w- c:\program files\Bonjour 2010-08-09 21:29 . 2010-08-09 21:29 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2010-09-01 08:59 . 2009-06-16 16:02 ——– d—–w- c:\documents and settings\T2\Application Data\Skype 2010-09-01 08:58 . 2009-06-16 16:14 ——– d—–w- c:\documents and settings\T2\Application Data\skypePM 2010-09-01 07:13 . 2008-11-15 15:09 ——– d—–w- c:\documents and settings\T2\Application Data\uTorrent 2010-08-31 19:47 . 2010-07-20 06:21 ——– d—–w- c:\documents and settings\T2\Application Data\vlc 2010-08-31 08:22 . 2009-02-18 18:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater 2010-08-27 13:35 . 2008-11-16 13:52 83768 —-a-w- c:\documents and settings\T2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-08-27 05:54 . 2008-11-21 02:42 ——– d—–w- c:\program files\Mozilla Thunderbird 2010-08-23 17:09 . 2008-11-15 15:09 ——– d—–w- c:\program files\uTorrent 2010-08-18 14:57 . 2009-09-26 10:55 ——– d—–w- c:\documents and settings\T2\Application Data\Apple Computer 2010-08-18 13:22 . 2008-11-17 12:29 ——– d—–w- c:\documents and settings\T2\Application Data\Nokia 2010-08-10 14:50 . 2009-09-02 22:37 1 —-a-w- c:\documents and settings\T2\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2010-08-09 21:51 . 2009-09-26 10:50 ——– d—–w- c:\program files\Common Files\Apple 2010-08-04 07:24 . 2010-05-08 23:56 ——– d—–w- c:\documents and settings\T2\Application Data\Winamp 2010-08-03 14:55 . 2009-05-24 09:52 ——– d—–w- c:\program files\Winamp 2010-07-27 18:01 . 2008-11-17 12:29 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Suite 2010-07-23 04:13 . 2010-07-23 04:13 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe 2010-07-19 19:37 . 2008-11-17 05:01 ——– d—–w- c:\documents and settings\T2\Application Data\dvdcss 2010-07-08 17:03 . 2009-04-29 17:48 ——– d—–w- c:\documents and settings\T2\Application Data\U3 2010-06-30 12:31 . 2008-04-15 03:00 149504 —-a-w- c:\windows\system32\schannel.dll 2010-06-24 12:15 . 2008-04-15 03:00 78336 —-a-w- c:\windows\system32\ieencode.dll 2010-06-24 12:15 . 2008-04-15 03:00 17408 —-a-w- c:\windows\system32\corpol.dll 2010-06-24 12:10 . 2007-08-14 01:54 667136 —-a-w- c:\windows\system32\wininet.dll 2010-06-23 13:44 . 2008-04-15 03:00 1851904 —-a-w- c:\windows\system32\win32k.sys 2010-06-21 15:27 . 2008-04-15 03:00 354304 —-a-w- c:\windows\system32\drivers\srv.sys 2010-06-17 14:03 . 2008-04-15 03:00 80384 —-a-w- c:\windows\system32\iccvid.dll 2010-06-16 11:18 . 2010-06-16 11:18 85504 —-a-w- c:\documents and settings\T2\Application Data\SystemRequirementsLab\srlproxy_cyri_4.1.71.0A.dll 2010-06-14 14:31 . 2008-04-15 03:00 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe 2010-06-14 07:41 . 2008-04-15 03:00 1172480 —-a-w- c:\windows\system32\msxml3.dll 2010-06-11 14:51 . 2010-06-11 14:51 3055600 —-a-w- c:\documents and settings\T2\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll 2010-06-11 14:36 . 2010-06-11 14:36 275952 —-a-w- c:\documents and settings\T2\Application Data\Mozilla\plugins\npgoogletalk.dll . ((((((((((((((((((((((((((((((((( Points de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Online Files] @="{B82655E9-B81D-4A97-8154-0D84A4C048E4}" [HKEY_CLASSES_ROOT\CLSID\{B82655E9-B81D-4A97-8154-0D84A4C048E4}] 2010-08-15 19:01 197632 —-a-w- c:\program files\Common Files\OnlineFilesManager.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\documents and settings\T2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-11 133104] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-15 68856] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-03-09 26100520] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LaunchApp"="Alaunch" [X] "NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752] "RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720] "AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-15 208952] "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-15 59392] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168] "LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 821768] "PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208] "eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-05-22 425984] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-15 110592] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632] "BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2008-02-19 1089536] "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832] "Boingo Wi-Fi"="c:\program files\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-09-01 2179] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SDL Trados 2007 Speed Launcher.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SDL Trados 2007 Speed Launcher.lnk backup=c:\windows\pss\SDL Trados 2007 Speed Launcher.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2010-06-20 02:04 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boingo Wi-Fi] 2010-09-01 08:57 2179 —-a-w- c:\program files\Boingo\Boingo Wi-Fi\Boingo.lnk [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtTray] 2008-08-04 16:04 226816 —-a-w- c:\program files\IVT Corporation\BlueSoleil\BtTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3] 2007-12-21 16:57 86016 ——w- c:\program files\Brother\ControlCenter3\BrCtrCen.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent] 2007-09-06 13:08 136136 —-a-w- c:\program files\DAEMON Tools Pro\DTProAgent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2008-12-11 05:36 133104 —-atw- c:\documents and settings\T2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] 2006-11-13 11:39 1289000 —-a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2010-07-21 13:53 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdiamon] 2007-07-16 10:54 25264 —-a-w- c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdimon.exe] 2007-07-16 10:54 434864 —-a-w- c:\program files\Lexmark 3500-4500 Series\lxdimon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] 2009-07-26 15:44 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando] 2008-11-20 11:04 3647304 —-a-w- c:\program files\Pando Networks\Pando\pando.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProductReg] 2008-09-22 21:53 6144 —-a-w- c:\program files\Acer\WR_PopUp\ProductReg.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2010-03-09 09:49 26100520 —-a-r- c:\program files\Skype\Phone\Skype.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] 2008-11-15 14:29 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "SDL FLEXlm License Server"=2 (0x2) "ose"=3 (0x3) "lxdi_device"=2 (0x2) "lxdiCATSCustConnectService"=2 (0x2) "iPod Service"=3 (0x3) "gusvc"=2 (0x2) "gupdate1c991f559cd37ea"=2 (0x2) "BsMobileCS"=2 (0x2) "BsHelpCS"=3 (0x3) "Bonjour Service"=2 (0x2) "BlueSoleilCS"=2 (0x2) "Apple Mobile Device"=2 (0x2) "Adobe LM Service"=3 (0x3) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Documents and Settings\\T2\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= "c:\\Documents and Settings\\T2\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"= "c:\\WINDOWS\\system32\\lxdicoms.exe"= "c:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"= "c:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"= "c:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"= "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager "c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager "c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= "c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"= "c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Pando Networks\\Pando\\pando.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "56753:TCP"= 56753:TCP:*:Disabled:Pando P2P TCP Listening Port "56753:UDP"= 56753:UDP:*:Disabled:Pando P2P UDP Listening Port "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [31.07.2008 20:45 20616] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [15.11.2008 16:48 162512] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [15.11.2008 16:48 19024] R2 SDL FLEXlm License Server;SDL FLEXlm License Server;c:\program files\SDL International\License Server\lmgrd.exe [22.02.2007 08:04 1339392] R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [02.07.2008 14:58 26248] S2 gupdate1c991f559cd37ea;Service Google Update (gupdate1c991f559cd37ea);c:\program files\Google\Update\GoogleUpdate.exe [18.02.2009 20:18 133104] S2 NewServiceInstall1;NewServiceInstall1;c:\program files\SDL International\T2007\TT\Lng\Dialogs1031.lng [23.04.2007 15:20 11264] S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [15.11.2008 16:34 96856] S4 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [01.08.2008 15:55 143467] S4 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service –> c:\windows\system32\lxdicoms.exe -service [?] S4 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdiserv.exe [21.08.2009 18:31 99248] S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17.04.2009 19:18 685816] . Contenu du dossier 'Tâches planifiées' 2010-06-05 c:\windows\Tasks\12-March_to_the_Shore-FYU.job - c:\documents and settings\T2\My Documents\My Music\In_Flames-A_Sense_of_Purpose-2008-FYU\12-March_to_the_Shore-FYU.mp3 [2009-02-13 13:13] 2010-09-01 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-15 12:15] 2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 18:18] 2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 18:18] 2010-08-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2094639727-349796869-1728803408-1006Core.job - c:\documents and settings\T2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-11 05:36] 2010-09-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2094639727-349796869-1728803408-1006UA.job - c:\documents and settings\T2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-11 05:36] . . ——- Examen supplémentaire ——- . uStart Page = hxxp://www.google.ch/ uSearch Page = hxxp://www.google.com uDefault_Search_URL = hxxp://www.google.com/ie uSearch Bar = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uInternet Settings,ProxyServer = 193.120.222.150:5900 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: Send by Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm IE: Send via &Message… - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} - hxxp://qc.nokia.com/qcbin/Spider90.ocx FF - ProfilePath - c:\documents and settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.ch/ FF - prefs.js: network.proxy.type - 0 FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll FF - plugin: c:\documents and settings\T2\Application Data\Move Networks\plugins\npqmp071700000016.dll FF - plugin: c:\documents and settings\T2\Application Data\Mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\T2\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\documents and settings\T2\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll FF - plugin: c:\program files\Picasa2\npPicasa2.dll FF - plugin: c:\program files\Picasa2\npPicasa3.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- PARAMETRES FIREFOX —- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . - - - - ORPHELINS SUPPRIMES - - - - MSConfigStartUp-Nokia - c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe MSConfigStartUp-PC Suite Tray - c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe ************************************************************************** Recherche de processus cachés … Recherche d'éléments en démarrage automatique cachés … Recherche de fichiers cachés … Scan terminé avec succès Fichiers cachés: ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NewServiceInstall1] "ImagePath"="\"c:\program files\SDL International\T2007\TT\Lng\Dialogs1031.lng\"" . ——————— CLES DE REGISTRE BLOQUEES ——————— [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . Heure de fin: 2010-09-01 11:20:21 ComboFix-quarantined-files.txt 2010-09-01 09:20 Avant-CF: 54'932'443'136 bytes free Après-CF: 55'219'912'704 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect - - End Of File - - 2B36D95E82E0A0AA568F245BF6738329
Also Ctrl-Alt-Del opens up windows Task Manager now instead of Sysinternal Process Explorer. An Internet Explorer icon appeared on my desktop and Firefox was no longer default browser.
Hello,

When CF is run it resets a bunch of settings back to default, and those are a few of them.

ComboFix Script
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"=-
"NokiaMServer"=-
DDS::
uInternet Settings,ProxyServer = 193.120.222.150:5900

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. If ComboFix prompts you to update to the newest version, please allow it to do so. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT:



Scanning with MalwareBytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:



Java Outdated
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "JDK 6 Update 21 (JDK or JRE)".
  • Click the "Download JRE" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586.exe to install the newest version.
  • If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
– Starting with Java 6u10, the uninstaller incorporated in each new release uses Enhanced Auto update to automatically remove the previous version when updating to a later update release. It will not remove older versions, so they will need to be removed manually.
– Java is updated frequently. If you want to be automatically notified of future updates, just turn on the Java Automatic Update feature and you will not have to remember to update when Java releases a new version.


Note:
The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
Click Ok and reboot your computer.


NEXT



Clean Java Cache & Temporary Files
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT:



Please download JavaRa and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location and post it in your next reply.


NEXT:



Kaspersky Online Scanner
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


NEXT:



Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
2nd CF log:

ComboFix 10-08-31.02 - T2 01.09.2010 17:01:55.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.41.1033.18.1012.276 [GMT 2:00]
Lancé depuis: c:\documents and settings\T2\Desktop\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\T2\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\9223359341.dll

.
((((((((((((((((((((((((((((( Fichiers créés du 2010-08-01 au 2010-09-01 ))))))))))))))))))))))))))))))))))))
.

2010-08-24 11:44 . 2010-08-24 11:44 ——– d—–w- C:\_OTL
2010-08-23 18:40 . 2010-08-23 18:40 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-08-23 14:56 . 2010-08-23 14:56 ——– d—–w- c:\documents and settings\T2\Local Settings\Application Data\IsolatedStorage
2010-08-23 14:52 . 2010-08-26 09:00 ——– d—–w- c:\program files\Common Files\Nokia
2010-08-23 14:52 . 2008-08-26 08:26 18816 —-a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-08-23 14:50 . 2010-08-26 09:00 ——– d—–w- c:\program files\Nokia
2010-08-18 14:57 . 2010-08-18 14:57 57896 —ha-w- c:\windows\system32\mlfcache.dat
2010-08-18 14:56 . 2010-08-18 14:57 ——– d—–w- c:\program files\Safari
2010-08-18 14:18 . 2010-08-27 21:14 690656 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-08-18 13:21 . 2010-08-25 15:32 ——– d—–w- c:\documents and settings\T2\Local Settings\Application Data\Nokia
2010-08-18 13:21 . 2010-08-26 08:59 ——– d—–w- c:\windows\Globalization
2010-08-18 13:20 . 2010-08-18 13:20 ——– d—–w- c:\documents and settings\All Users\Application Data\NokiaMusic
2010-08-18 13:17 . 2010-08-18 13:27 ——– d—–w- c:\windows\system32\drivers\UMDF
2010-08-15 19:03 . 2010-09-01 15:07 ——– d—–w- c:\program files\Common Files\Data
2010-08-15 19:01 . 2010-08-15 19:01 197632 —-a-w- c:\program files\Common Files\OnlineFilesManager.dll
2010-08-13 13:20 . 2010-08-13 13:20 503808 —-a-w- c:\documents and settings\T2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-70b90442-n\msvcp71.dll
2010-08-13 13:20 . 2010-08-13 13:20 499712 —-a-w- c:\documents and settings\T2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-70b90442-n\jmc.dll
2010-08-13 13:20 . 2010-08-13 13:20 348160 —-a-w- c:\documents and settings\T2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-70b90442-n\msvcr71.dll
2010-08-13 13:20 . 2010-08-13 13:20 61440 —-a-w- c:\documents and settings\T2\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-16850e93-n\decora-sse.dll
2010-08-13 13:20 . 2010-08-13 13:20 12800 —-a-w- c:\documents and settings\T2\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-16850e93-n\decora-d3d.dll
2010-08-09 21:51 . 2010-08-09 21:51 ——– d—–w- c:\program files\iPod
2010-08-09 21:50 . 2010-08-09 21:52 ——– d—–w- c:\program files\iTunes
2010-08-09 21:50 . 2010-08-09 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-09 21:43 . 2010-08-09 21:44 ——– d—–w- c:\program files\QuickTime
2010-08-09 21:34 . 2010-08-09 21:34 ——– d—–w- c:\program files\Bonjour
2010-08-09 21:29 . 2010-08-09 21:29 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-01 12:46 . 2008-11-15 15:09 ——– d—–w- c:\documents and settings\T2\Application Data\uTorrent
2010-09-01 09:23 . 2009-02-18 18:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-09-01 08:59 . 2009-06-16 16:02 ——– d—–w- c:\documents and settings\T2\Application Data\Skype
2010-09-01 08:58 . 2009-06-16 16:14 ——– d—–w- c:\documents and settings\T2\Application Data\skypePM
2010-08-31 19:47 . 2010-07-20 06:21 ——– d—–w- c:\documents and settings\T2\Application Data\vlc
2010-08-27 13:35 . 2008-11-16 13:52 83768 —-a-w- c:\documents and settings\T2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-27 05:54 . 2008-11-21 02:42 ——– d—–w- c:\program files\Mozilla Thunderbird
2010-08-23 17:09 . 2008-11-15 15:09 ——– d—–w- c:\program files\uTorrent
2010-08-18 14:57 . 2009-09-26 10:55 ——– d—–w- c:\documents and settings\T2\Application Data\Apple Computer
2010-08-18 13:22 . 2008-11-17 12:29 ——– d—–w- c:\documents and settings\T2\Application Data\Nokia
2010-08-10 14:50 . 2009-09-02 22:37 1 —-a-w- c:\documents and settings\T2\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-08-09 21:51 . 2009-09-26 10:50 ——– d—–w- c:\program files\Common Files\Apple
2010-08-04 07:24 . 2010-05-08 23:56 ——– d—–w- c:\documents and settings\T2\Application Data\Winamp
2010-08-03 14:55 . 2009-05-24 09:52 ——– d—–w- c:\program files\Winamp
2010-07-27 18:01 . 2008-11-17 12:29 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Suite
2010-07-23 04:13 . 2010-07-23 04:13 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe
2010-07-19 19:37 . 2008-11-17 05:01 ——– d—–w- c:\documents and settings\T2\Application Data\dvdcss
2010-07-08 17:03 . 2009-04-29 17:48 ——– d—–w- c:\documents and settings\T2\Application Data\U3
2010-06-30 12:31 . 2008-04-15 03:00 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:15 . 2008-04-15 03:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2008-04-15 03:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-06-24 12:10 . 2007-08-14 01:54 667136 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2008-04-15 03:00 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2008-04-15 03:00 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2008-04-15 03:00 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-16 11:18 . 2010-06-16 11:18 85504 —-a-w- c:\documents and settings\T2\Application Data\SystemRequirementsLab\srlproxy_cyri_4.1.71.0A.dll
2010-06-14 14:31 . 2008-04-15 03:00 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2008-04-15 03:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
2010-06-11 14:51 . 2010-06-11 14:51 3055600 —-a-w- c:\documents and settings\T2\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
2010-06-11 14:36 . 2010-06-11 14:36 275952 —-a-w- c:\documents and settings\T2\Application Data\Mozilla\plugins\npgoogletalk.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Online Files]
@="{B82655E9-B81D-4A97-8154-0D84A4C048E4}"
[HKEY_CLASSES_ROOT\CLSID\{B82655E9-B81D-4A97-8154-0D84A4C048E4}]
2010-08-15 19:01 197632 —-a-w- c:\program files\Common Files\OnlineFilesManager.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\T2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-11 133104]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-15 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-03-09 26100520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-15 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-15 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 821768]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-05-22 425984]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-15 110592]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2008-02-19 1089536]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"Boingo Wi-Fi"="c:\program files\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-09-01 2179]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SDL Trados 2007 Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SDL Trados 2007 Speed Launcher.lnk
backup=c:\windows\pss\SDL Trados 2007 Speed Launcher.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boingo Wi-Fi]
2010-09-01 08:57 2179 —-a-w- c:\program files\Boingo\Boingo Wi-Fi\Boingo.lnk

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtTray]
2008-08-04 16:04 226816 —-a-w- c:\program files\IVT Corporation\BlueSoleil\BtTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
2007-12-21 16:57 86016 ——w- c:\program files\Brother\ControlCenter3\BrCtrCen.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2007-09-06 13:08 136136 —-a-w- c:\program files\DAEMON Tools Pro\DTProAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-12-11 05:36 133104 —-atw- c:\documents and settings\T2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 11:39 1289000 —-a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-07-21 13:53 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdiamon]
2007-07-16 10:54 25264 —-a-w- c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdimon.exe]
2007-07-16 10:54 434864 —-a-w- c:\program files\Lexmark 3500-4500 Series\lxdimon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 15:44 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando]
2008-11-20 11:04 3647304 —-a-w- c:\program files\Pando Networks\Pando\pando.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProductReg]
2008-09-22 21:53 6144 —-a-w- c:\program files\Acer\WR_PopUp\ProductReg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-03-09 09:49 26100520 —-a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-11-15 14:29 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SDL FLEXlm License Server"=2 (0x2)
"ose"=3 (0x3)
"lxdi_device"=2 (0x2)
"lxdiCATSCustConnectService"=2 (0x2)
"iPod Service"=3 (0x3)
"gusvc"=2 (0x2)
"gupdate1c991f559cd37ea"=2 (0x2)
"BsMobileCS"=2 (0x2)
"BsHelpCS"=3 (0x3)
"Bonjour Service"=2 (0x2)
"BlueSoleilCS"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Adobe LM Service"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\T2\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\T2\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
"c:\\WINDOWS\\system32\\lxdicoms.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56753:TCP"= 56753:TCP:*:Disabled:Pando P2P TCP Listening Port
"56753:UDP"= 56753:UDP:*:Disabled:Pando P2P UDP Listening Port
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [31.07.2008 20:45 20616]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [15.11.2008 16:48 162512]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [15.11.2008 16:48 19024]
R2 SDL FLEXlm License Server;SDL FLEXlm License Server;c:\program files\SDL International\License Server\lmgrd.exe [22.02.2007 08:04 1339392]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [02.07.2008 14:58 26248]
S2 gupdate1c991f559cd37ea;Service Google Update (gupdate1c991f559cd37ea);c:\program files\Google\Update\GoogleUpdate.exe [18.02.2009 20:18 133104]
S2 NewServiceInstall1;NewServiceInstall1;c:\program files\SDL International\T2007\TT\Lng\Dialogs1031.lng [23.04.2007 15:20 11264]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [15.11.2008 16:34 96856]
S4 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [01.08.2008 15:55 143467]
S4 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service –> c:\windows\system32\lxdicoms.exe -service [?]
S4 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdiserv.exe [21.08.2009 18:31 99248]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17.04.2009 19:18 685816]
.
Contenu du dossier 'Tâches planifiées'

2010-06-05 c:\windows\Tasks\12-March_to_the_Shore-FYU.job
- c:\documents and settings\T2\My Documents\My Music\In_Flames-A_Sense_of_Purpose-2008-FYU\12-March_to_the_Shore-FYU.mp3 [2009-02-13 13:13]

2010-09-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-15 12:15]

2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 18:18]

2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 18:18]

2010-08-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2094639727-349796869-1728803408-1006Core.job
- c:\documents and settings\T2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-11 05:36]

2010-09-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2094639727-349796869-1728803408-1006UA.job
- c:\documents and settings\T2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-11 05:36]
.
.
——- Examen supplémentaire ——-
.
uStart Page = hxxp://www.google.ch/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send by Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
IE: Send via &Message… - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} - hxxp://qc.nokia.com/qcbin/Spider90.ocx
FF - ProfilePath - c:\documents and settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ch/
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\documents and settings\T2\Application Data\Move Networks\plugins\npqmp071700000016.dll
FF - plugin: c:\documents and settings\T2\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\T2\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\T2\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\program files\Picasa2\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- PARAMETRES FIREFOX —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-01 17:09
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés …

Recherche d'éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NewServiceInstall1]
"ImagePath"="\"c:\program files\SDL International\T2007\TT\Lng\Dialogs1031.lng\""
.
——————— CLES DE REGISTRE BLOQUEES ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs chargées dans les processus actifs ———————

- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\igfxdev.dll
.
Heure de fin: 2010-09-01 17:12:55
ComboFix-quarantined-files.txt 2010-09-01 15:12
ComboFix2.txt 2010-09-01 09:20

Avant-CF: 51'713'597'440 bytes free
Après-CF: 51'698'458'624 bytes free

- - End Of File - - 3610E4287ED5D0CBDD05E121932DA2A5
MBAM log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4523 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 01.09.2010 17:40:41 mbam-log-2010-09-01 (17-40-41).txt Scan type: Quick scan Objects scanned: 144930 Time elapsed: 10 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
JavaRA log: JavaRa 1.16 Removal Log. Report follows after line. ———————————— The JavaRa removal process was started on Wed Sep 01 18:44:00 2010 Found and removed: C:\Documents and Settings\T2\Application Data\Sun\Java\jre1.6.0_10 Found and removed: C:\Documents and Settings\T2\Application Data\Sun\Java\jre1.6.0_11 Found and removed: C:\Documents and Settings\T2\Application Data\Sun\Java\jre1.6.0_12 Found and removed: C:\Documents and Settings\T2\Application Data\Sun\Java\jre1.6.0_13 Found and removed: C:\Documents and Settings\T2\Application Data\Sun\Java\jre1.6.0_15 Found and removed: C:\Documents and Settings\T2\Application Data\Sun\Java\jre1.6.0_19 Found and removed: C:\Documents and Settings\T2\Application Data\Sun\Java\jre1.6.0_20 Found and removed: Software\JavaSoft\Java2D\1.5.0_10 Found and removed: Software\JavaSoft\Java2D\1.5.0_11 Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB} Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500} JavaRa 1.16 Removal Log. Report follows after line. ———————————— The JavaRa removal process was started on Wed Sep 01 18:44:37 2010 ———————————— Finished reporting.
Try this one instead:

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
ESET scan log: C:\Documents and Settings\T2\Local Settings\Temporary Internet Files\Content.IE5\I7ENY123\asshole[1].pdf JS/Exploit.Pdfka.CQZ trojan C:\Documents and Settings\T2\Local Settings\Temporary Internet Files\Content.IE5\I7ENY123\asshole[2].pdf JS/Exploit.Pdfka.CQZ trojan
Hello,


OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    
    :Reg
    
    :Files
    C:\Documents and Settings\T2\Local Settings\Temporary Internet Files\Content.IE5\I7ENY123\asshole[1].pdf
    C:\Documents and Settings\T2\Local Settings\Temporary Internet Files\Content.IE5\I7ENY123\asshole[2].pdf
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
OTL fix log:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
========== REGISTRY ==========
========== FILES ==========
C:\Documents and Settings\T2\Local Settings\Temporary Internet Files\Content.IE5\I7ENY123\asshole[1].pdf moved successfully.
C:\Documents and Settings\T2\Local Settings\Temporary Internet Files\Content.IE5\I7ENY123\asshole[2].pdf moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\T2\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\T2\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point (0)

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 65716 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: T2
->Temp folder emptied: 112856484 bytes
->Temporary Internet Files folder emptied: 9278444 bytes
->Java cache emptied: 128094 bytes
->FireFox cache emptied: 79804913 bytes
->Google Chrome cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 5735 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8394 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 240255133 bytes

Total Files Cleaned = 422.00 mb


[EMPTYFLASH]

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: Guest
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

User: T2
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.11.0 log created on 09022010_154302

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI