This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet Explorer pops up and connects to random sites

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I forgot: the router wasn't shipped with the default password. default username, yes, but the password is, well, it's no default pass and it's rather secure. Ain't in the list of combinations the malware tries to crack the router with either. What do you think?
OK, here's the RKU report: RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #2 ============================================== >Drivers ============================================== 0xF5EE3000 C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 5857280 bytes (Intel Corporation, Intel Graphics Miniport Driver) 0xAA2B3000 C:\WINDOWS\system32\drivers\RtkHDAud.sys 4968448 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver) 0xBF1E7000 C:\WINDOWS\System32\igxpdx32.DLL 2699264 bytes (Intel Corporation, DirectDraw® Driver for Intel® Graphics Technology) 0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2260992 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2260992 bytes 0x804D7000 RAW 2260992 bytes 0x804D7000 WMIxWDM 2260992 bytes 0xBF800000 Win32k 1855488 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xA9EA8000 C:\WINDOWS\system32\DRIVERS\snp2uvc.sys 1773568 bytes (-, UVC Camera Streaming Driver) 0xBF04F000 C:\WINDOWS\System32\igxpdv32.DLL 1671168 bytes (Intel Corporation, Component GHAL Driver) 0xF5D4A000 C:\WINDOWS\system32\DRIVERS\athw.sys 1314816 bytes (Atheros Communications, Inc., Driver for Atheros AR5008 Wireless Network Adapter) 0xF758A000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xAA0A8000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xF5C46000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xAA1B3000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xA9728000 C:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver) 0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xA90BC000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xF5CEF000 C:\WINDOWS\system32\DRIVERS\SynTP.sys 225280 bytes (Synaptics, Inc., Synaptics Touchpad Driver) 0xF7718000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xA9974000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xF755D000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xF7673000 dac2w2k.sys 180224 bytes (Mylex Corporation, Mylex Disk Array Controller Driver) 0xBF024000 C:\WINDOWS\System32\igxpgd32.dll 176128 bytes (Intel Corporation, Intel Graphics 2D Driver) 0xAA118000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xF5EA7000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a) 0xAA165000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xAA081000 C:\WINDOWS\System32\Drivers\aswSP.SYS 159744 bytes (ALWIL Software, avast! self protection module) 0xAA18D000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xA8DC8000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xAA28F000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xF5D26000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xF5CA4000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xAA143000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x806FF000 ACPI_HAL 134400 bytes 0x806FF000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xF7653000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xF76E8000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xF5E8B000 C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 114688 bytes (Realtek Semiconductor Corporation , Realtek 10/100/1000 NDIS 5.1 Driver ) 0xF7532000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xF769F000 adpu160m.sys 102400 bytes (Microsoft Corporation, Adaptec Ultra160 SCSI miniport) 0xF76B8000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xA9E90000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xF76D0000 C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver) 0xA9B31000 C:\WINDOWS\System32\Drivers\aswMon2.SYS 94208 bytes (ALWIL Software, avast! File System Filter Driver for Windows XP) 0xF762A000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xF5CD8000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xA9937000 C:\WINDOWS\System32\Drivers\SENTINEL.SYS 86016 bytes (SafeNet, Inc., Sentinel System Driver (NT Parallel driver)) 0xA95AB000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xF5ECF000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xAA20C000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xF7617000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xBF012000 C:\WINDOWS\System32\igxprd32.dll 73728 bytes (Intel Corporation, Intel Graphics 2D Rotation Driver) 0xF7641000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xA8C27000 C:\Acer\Empowering Technology\eRecovery\int15.sys 69632 bytes 0xF7707000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xF5CC7000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xF754C000 sfdrv01.sys 69632 bytes (Protection Technology, StarForce Protection Environment Driver) 0xF7867000 prohlp02.sys 65536 bytes (Protection Technology, StarForce Protection Helper Driver) 0xF64D9000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xA9A39000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xF64E9000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xF77C7000 aic78u2.sys 57344 bytes (Microsoft Corporation, Adaptec Ultra2 SCSI miniport) 0xF7797000 aic78xx.sys 57344 bytes (Microsoft Corporation, Adaptec Ultra SCSI miniport) 0xF7827000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xF7937000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xF79C7000 C:\WINDOWS\System32\drivers\prodrv06.sys 53248 bytes (Protection Technology, StarForce Protection Environment Driver) 0xF7947000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xF7502000 C:\WINDOWS\system32\DRIVERS\STREAM.SYS 53248 bytes (Microsoft Corporation, WDM CODEC Class Device Driver 2.0) 0xF7787000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xF7807000 ql12160.sys 49152 bytes (QLogic Corporation, Miniport Driver for QLogic ISP PCI Adapters) 0xF77F7000 ql1280.sys 49152 bytes (QLogic Corporation, Miniport Driver for QLogic ISP PCI Adapters) 0xF7967000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xF7897000 agp440.sys 45056 bytes (Microsoft Corporation, 440 NT AGP Filter) 0xF78A7000 agpCPQ.sys 45056 bytes (Microsoft Corporation, CompatNT AGP Filter) 0xF7877000 alim1541.sys 45056 bytes (Microsoft Corporation, ALi M1541 NT AGP Filter) 0xF7887000 amdagp.sys 45056 bytes (Advanced Micro Devices, Inc., AMD Win2000 AGP Filter) 0xF7522000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xF7777000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xF7957000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xF7857000 viaagp.sys 45056 bytes (Microsoft Corporation, VIA NT AGP Filter) 0xF6499000 C:\WINDOWS\System32\Drivers\aswTdi.SYS 40960 bytes (ALWIL Software, avast! TDI Filter Driver) 0xF7767000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xF7997000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xF7837000 PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0xF77E7000 ql1080.sys 40960 bytes (QLogic Corporation, Miniport Driver for QLogic ISP PCI Adapters) 0xF77B7000 ql1240.sys 40960 bytes (Microsoft Corporation, QLogic ISP PCI Adapters) 0xF7847000 sisagp.sys 40960 bytes (Silicon Integrated Systems Corporation, SiS NT AGP Filter) 0xF7987000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xF7817000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xF7927000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xF7977000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xF6479000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xA8ECC000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xF77A7000 ql10wnt.sys 36864 bytes (Microsoft Corporation, Miniport Driver for QLogic ISP PCI Adapters) 0xF77D7000 ultra.sys 36864 bytes (Promise Technology, Inc., Promise Ultra66 Miniport Driver) 0xF6489000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xF7B47000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xF7A5F000 sfhlp02.sys 32768 bytes (Protection Technology, StarForce Protection Helper Driver) 0xF7A1F000 symc8xx.sys 32768 bytes (LSI Logic, Symbios 8XX SCSI Miniport Driver) 0xF7A2F000 sym_u3.sys 32768 bytes (LSI Logic, Symbios Ultra3 SCSI Miniport Driver) 0xF7AB7000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xF7A07000 asc.sys 28672 bytes (Advanced System Products, Inc., AdvanSys SCSI Controller Driver) 0xF7B2F000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xF7A57000 hpn.sys 28672 bytes (Microsoft Corporation, NetRAID-4M Miniport Driver) 0xF79E7000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xF7A4F000 perc2.sys 28672 bytes (Microsoft Corporation, PERC 2 Miniport Driver) 0xF7B5F000 C:\WINDOWS\system32\DRIVERS\sncduvc.SYS 28672 bytes (-, USBCAMD for Sonix UVC) 0xF7A27000 sym_hi.sys 28672 bytes (LSI Logic, Symbios Hi-Perf SCSI Miniport Driver) 0xF7B57000 C:\WINDOWS\System32\Drivers\Aavmker4.SYS 24576 bytes (ALWIL Software, avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP) 0xF7A37000 ABP480N5.SYS 24576 bytes (Microsoft Corporation, AdvanSys SCSI Controller Driver) 0xF7A3F000 asc3350p.sys 24576 bytes (Microsoft Corporation, AdvanSys SCSI Card Driver) 0xF7AC7000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xF7ACF000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xF79F7000 sfsync02.sys 24576 bytes (Protection Technology, StarForce Protection Synchronization Driver) 0xF7AAF000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xF7AD7000 C:\WINDOWS\System32\Drivers\VcommMgr.sys 24576 bytes (IVT Corporation., Bluetooth VcommMgr Driver) 0xF7B37000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xAA798000 C:\WINDOWS\System32\Drivers\aswRdr.SYS 20480 bytes (ALWIL Software, avast! TDI RDR Driver) 0xF7ABF000 C:\WINDOWS\system32\DRIVERS\DKbFltr.sys 20480 bytes (Dritek System Inc., Dritek PS2 Keyboard Filter Driver) 0xF7A47000 dpti2o.sys 20480 bytes (Microsoft Corporation, DPT SmartRAID miniport) 0xF7A17000 i2omp.sys 20480 bytes (Microsoft Corporation, I2O Miniport Driver) 0xF7ADF000 C:\WINDOWS\System32\Drivers\IvtBtBus.sys 20480 bytes (IVT Corporation., IVT Bluetooth Bus Device Driver) 0xF7A0F000 mraid35x.sys 20480 bytes (American Megatrends Inc., MegaRAID RAID Controller Driver for Windows Whistler 32) 0xF7B3F000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xF79EF000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xA91FD000 C:\WINDOWS\System32\Drivers\PCASp50.sys 20480 bytes (Printing Communications Assoc., Inc. (PCAUSA), PCAUSA NDIS 5.0 SPR Protocol Driver) 0xF7AEF000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xF7AF7000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xF79FF000 sparrow.sys 20480 bytes (Adaptec, Inc., Adaptec AIC-6x60 series SCSI miniport) 0xF7AE7000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xF7A8F000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xF7B8B000 aha154x.sys 16384 bytes (Microsoft Corporation, Adaptec AHA-154x series SCSI miniport) 0xF7B9B000 asc3550.sys 16384 bytes (Advanced System Products, Inc., AdvanSys Ultra-Wide PCI SCSI Driver) 0xF7B7F000 C:\WINDOWS\system32\DRIVERS\BATTC.SYS 16384 bytes (Microsoft Corporation, Battery Class Driver) 0xF7BA7000 BtHidBus.sys 16384 bytes (IVT Corporation., Bluetooth HID BUS Driver) 0xF7BA3000 cbidf2k.sys 16384 bytes (Microsoft Corporation, CardBus/PCMCIA IDE Miniport Driver) 0xF7435000 C:\WINDOWS\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver) 0xF7B87000 cpqarray.sys 16384 bytes (Microsoft Corporation, Compaq Drive Array Controllers SCSI Miniport Driver) 0xF7B93000 dac960nt.sys 16384 bytes (Microsoft Corporation, Mylex Disk Array Controller Driver) 0xF7B9F000 ini910u.sys 16384 bytes (Microsoft Corporation, INITIO ini910u SCSI miniport) 0xF7425000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xA9D64000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xF7B8F000 symc810.sys 16384 bytes (Symbios Logic Inc., Symbios Logic Inc. SCSI Miniport Driver) 0xA9D60000 C:\WINDOWS\system32\DRIVERS\wpsnuio.sys 16384 bytes (Skyhook Wireless, WPS NDIS User Mode I/O Driver) 0xF7B83000 ACPIEC.sys 12288 bytes (Microsoft Corporation, ACPI Embedded Controller Driver) 0xF7B97000 amsint.sys 12288 bytes (Microsoft Corporation, AMD SCSI/NET Controller) 0xA9DD4000 C:\WINDOWS\System32\Drivers\aswFsBlk.SYS 12288 bytes (ALWIL Software, avast! File System Access Blocking Driver) 0xF7B77000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xF7B7B000 compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver) 0xAA26B000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xF7C53000 C:\WINDOWS\System32\Drivers\i2omgmt.SYS 12288 bytes (Microsoft Corporation, I2O Utility Filter) 0xF742D000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xF7C5B000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xF7431000 C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 12288 bytes (Microsoft Corporation, Windows Management Interface for ACPI) 0xF7C6B000 aliide.sys 8192 bytes (Acer Laboratories Inc., ALi mini IDE Driver) 0xF7CD1000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xF7CB3000 C:\WINDOWS\system32\DRIVERS\btnetdrv.sys 8192 bytes (IVT Corporation., Bluetooth PAN Network Adapter Driver) 0xF7C75000 cd20xrnt.sys 8192 bytes (Microsoft Corporation, IBM Portable CD-ROM Drive Miniport) 0xF7C6D000 cmdide.sys 8192 bytes (CMD Technology, Inc., CMD PCI IDE Bus Driver) 0xF7CDD000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xF7CCF000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xF7C73000 intelide.sys 8192 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0xF7C67000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xF7CD3000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xF7C77000 perc2hib.sys 8192 bytes (Microsoft Corporation, PERC 2 Hibernate Driver) 0xF7C7B000 prosync1.sys 8192 bytes (Protection Technology, StarForce Protection Synchronization Driver) 0xF7CD5000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xF7C79000 sfhlp01.sys 8192 bytes (Protection Technology, StarForce Protection Helper Driver) 0xF7CB5000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xF7C6F000 toside.sys 8192 bytes (Microsoft Corporation, Toshiba PCI IDE Controller) 0xF7CB1000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xF7C71000 viaide.sys 8192 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) 0xF7C69000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xF7E3D000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xF7EBC000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xF7E7D000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xF7D30000 C:\WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 4096 bytes (Microsoft Corporation, ACPI Operation Registration Driver) 0xF7D2F000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) 0xE17C1AC0 unknown_irp_handler 1344 bytes 0xE1927C30 unknown_irp_handler 976 bytes ============================================== >Stealth ============================================== 0x009F0000 Hidden Image–>CFScan.dll [ EPROCESS 0x829DC468 ] PID: 608, 45056 bytes ============================================== >Files ============================================== !–>[Hidden] C:\Documents and Settings\T2\Local Settings\Temporary Internet Files\Content.IE5\UJSPQWES\de[1].htm !–>[Hidden] C:\Documents and Settings\T2\Local Settings\Temporary Internet Files\Content.IE5\UJSPQWES\loginbox[1].swf ============================================== >Hooks ============================================== ntoskrnl.exe+0x00005B22, Type: Inline - RelativeJump 0x804DCB22–>804DCB29 [ntoskrnl.exe] ntoskrnl.exe–>NtCreateProcessEx, Type: Inline - RelativeJump 0x8059056D–>AA096502 [aswSP.SYS] ntoskrnl.exe–>NtCreateSection, Type: Inline - RelativeJump 0x8056DB66–>AA096326 [aswSP.SYS] ntoskrnl.exe–>NtLoadDriver, Type: Inline - RelativeJump 0x805AEDE2–>AA096460 [aswSP.SYS] ntoskrnl.exe–>ObInsertObject, Type: Inline - RelativeJump 0x8056DA64–>AA093972 [aswSP.SYS] ntoskrnl.exe–>ObMakeTemporaryObject, Type: Inline - RelativeJump 0x805E74E6–>AA0924BA [aswSP.SYS] [1220]explorer.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77DD1218–>00000000 [shimeng.dll] [1220]explorer.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77F110B4–>00000000 [shimeng.dll] [1220]explorer.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x01001268–>00000000 [shimeng.dll] [1220]explorer.exe–>mswsock.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71A51178–>00000000 [shimeng.dll] [1220]explorer.exe–>shell32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7C9C15A4–>00000000 [shimeng.dll] [1220]explorer.exe–>user32.dll–>GetCursorPos, Type: Inline - RelativeJump 0x7E42974E–>00000000 [hd243_module.dat] [1220]explorer.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7E41133C–>00000000 [shimeng.dll] [1220]explorer.exe–>user32.dll–>MessageBoxIndirectA, Type: Inline - RelativeJump 0x7E43A082–>00000000 [hd243_module.dat] [1220]explorer.exe–>user32.dll–>MessageBoxIndirectW, Type: Inline - RelativeJump 0x7E4664D5–>00000000 [hd243_module.dat] [1220]explorer.exe–>wininet.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x3D9314B0–>00000000 [shimeng.dll] [1220]explorer.exe–>ws2_32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71AB109C–>00000000 [shimeng.dll] [2284]firefox.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3–>00000000 [firefox.exe] [912]services.exe–>advapi32.dll–>CreateProcessAsUserW, Type: IAT modification 0x01001094–>00000000 [unknown_code_page] [912]services.exe–>kernel32.dll–>CreateProcessW, Type: IAT modification 0x01001114–>00000000 [unknown_code_page]
Hello,

Lets try this:

Reset IE8:

  • Please download Microsoft FixIt and save it to the desktop.
  • Double click on MicrosoftFixit50195.exe select I Agree and click on Next.
  • Follow the on-screen prompts.
  • You may delete MicrosoftFixit50195.exe when finished and or keep it if any problems in the future with IE8.
  • Next time IE8 is launched you will be prompted to reapply settings again, this is normal.

  • Note: Any add-ons will require to be reapplied after the above reset.


Please tell me if your still experiencing issues with Internet Explorer.

If you are then please take a screenshot of the issue you are having:

Please take a screenshot of that window.
  • You can do this by pressing the PrintScreen key.
  • Then go to Start > All Programs > Accessories > Paint
  • In Paint, go up to Edit > Paste
  • Then Go up to File > Save As. Click the drop-down box to change the "Save As Type" to "JPEG", name it what you want, and save it where you want.
  • Then click Reply in this topic.
  • Scroll down to Attachments.
  • Click the Browse button.
  • Locate the file you just saved, click on it, then click Open.
  • Click Upload and submit the reply.
OK, I ran the fixit. Will see. IE doesn't pop up all the time, regularly. I'll be sure to take a screenshot if it does. Should I already proceed with some of the cleanup procedures you posted?
I'd only like for you to make sure you update Thunderbird, and Internet Explorer to the latest version. You can hold up on doing anything else in my all clean post for now.
I don't think it's resolved. I still get an impromptu IE download window for some "one-click antivirus". Plus now Windows Media Player also just popped up. Any chance it's all legitimate behaviour?
Let me grab a new OTL scan from you.


OTL Custom Scan

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
OTL.txt

OTL logfile created on: 08.09.2010 19:43:08 - Run 2
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\T2\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000100C | Country: Switzerland | Language: FRS | Date Format: dd.MM.yyyy

1'012.00 Mb Total Physical Memory | 348.00 Mb Available Physical Memory | 34.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.17 Gb Total Space | 46.86 Gb Free Space | 32.50% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PEQUENINO
Current User Name: T2
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\T2\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\T2\Local Settings\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (Boingo Wireless, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\SDL International\License Server\trados.exe ()
PRC - C:\Program Files\SDL International\License Server\lmgrd.exe (Macrovision Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (SafeNet, Inc)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\T2\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Common Files\OnlineFilesManager.dll (Microsoft)
MOD - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.dll (Adobe Systems, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll (Sun Microsystems, Inc.)
MOD - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\stlport_vc7145.dll (STLport Consulting, Inc.)
MOD - C:\WINDOWS\system32\xpsp2res.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\AudioShell\AudioShellExt.dll (Softpointer Inc)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (ServiceLayer) – C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (BlueSoleilCS) – C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe ()
SRV - (BsHelpCS) – C:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe ()
SRV - (BsMobileCS) – C:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe ()
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (lxdi_device) – C:\WINDOWS\System32\lxdicoms.exe ( )
SRV - (lxdiCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe ()
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (NewServiceInstall1) – C:\Program Files\SDL International\T2007\TT\Lng\Dialogs1031.lng ()
SRV - (SDL FLEXlm License Server) – C:\Program Files\SDL International\License Server\lmgrd.exe (Macrovision Corporation)
SRV - (SentinelProtectionServer) – C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe (SafeNet, Inc)


========== Driver Services (SafeList) ==========

DRV - (upperdev) – C:\WINDOWS\System32\DRIVERS\usbser_lowerflt.sys File not found
DRV - (mcdbus) – C:\WINDOWS\System32\DRIVERS\mcdbus.sys File not found
DRV - (catchme) – C:\DOCUME~1\T2\LOCALS~1\Temp\catchme.sys File not found
DRV - (Wpsnuio) – C:\WINDOWS\system32\drivers\wpsnuio.sys (Skyhook Wireless)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (BtHidBus) – C:\WINDOWS\System32\Drivers\BtHidBus.sys (IVT Corporation.)
DRV - (JMCR) – C:\WINDOWS\system32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - (IvtBtBUs) – C:\WINDOWS\system32\drivers\IvtBtBus.sys (IVT Corporation.)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation.)
DRV - (Btcsrusb) – C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation.)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (BT) – C:\WINDOWS\system32\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation.)
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (Sentinel) – C:\WINDOWS\System32\Drivers\SENTINEL.SYS (SafeNet, Inc.)
DRV - (sfcure01) StarForce Cure Driver (version 1.x) – C:\WINDOWS\system32\drivers\sfcure01.sys ()
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (int15.sys) – C:\Acer\Empowering Technology\eRecovery\int15.sys ()
DRV - (DKbFltr) – C:\WINDOWS\system32\drivers\DKbFltr.SYS (Dritek System Inc.)
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (prohlp02) – C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (sfhlp01) – C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (prodrv06) – C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (prosync1) – C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ch/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ch/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.08.10 07:57:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.09.03 23:53:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.09.02 16:18:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.2\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010.09.03 23:53:05 | 000,000,000 | —D | M]

[2010.09.02 16:18:49 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Mozilla\Extensions
[2010.09.02 16:18:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\T2\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.09.08 16:40:10 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\extensions
[2010.04.28 07:16:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009.03.04 15:30:50 | 000,001,504 | —- | M] () – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\searchplugins\imdb.xml
[2008.11.17 05:01:06 | 000,001,032 | —- | M] () – C:\Documents and Settings\T2\Application Data\Mozilla\Firefox\Profiles\bdrclox5.default\searchplugins\wikipedia-eng.xml
[2010.09.08 16:40:10 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010.03.29 09:55:27 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010.09.01 18:29:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.09.01 18:29:39 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009.11.30 18:59:59 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2008.11.20 13:04:50 | 000,239,432 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2010.03.13 16:49:04 | 000,001,516 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-france.xml
[2010.03.13 16:49:04 | 000,001,822 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\cnrtl-tlfi-fr.xml
[2010.03.13 16:49:04 | 000,000,757 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-france.xml
[2008.11.17 14:06:34 | 000,000,748 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\MediaDICO-fr.xml
[2010.03.13 16:49:06 | 000,001,426 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-fr.xml
[2010.03.24 13:18:59 | 000,000,956 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-france.xml

O1 HOSTS File: ([2010.09.02 18:17:15 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Boingo Wi-Fi] C:\Program Files\Boingo\Boingo Wi-Fi\Boingo.lnk ()
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {98C53984-8BF8-4D11-9B1C-C324FCA9CADE} http://qc.nokia.com/qcbin/Spider90.ocx (Loader Class v3)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO: )
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\T2\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\T2\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.08.15 19:37:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DIVXA32.ACM (Hacked With Joy !)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\DIVX.DLL (DivXNetworks, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.xvid - C:\WINDOWS\System32\XVIDVFW.DLL ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 90 Days ==========

[2010.09.08 12:13:01 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Desktop\2466009_20100907151956
[2010.09.08 09:57:59 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010.09.07 11:36:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010.09.07 11:34:32 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010.09.07 11:24:50 | 000,000,000 | -HSD | C] – C:\Documents and Settings\T2\PrivacIE
[2010.09.05 17:36:27 | 001,286,232 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\T2\Desktop\TDSSKiller.exe
[2010.09.03 08:48:56 | 000,000,000 | -HSD | C] – C:\Documents and Settings\T2\IETldCache
[2010.09.02 17:48:25 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2010.09.02 17:45:02 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010.09.02 15:42:14 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\T2\Desktop\OTL.exe
[2010.09.02 08:46:59 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010.09.01 18:43:23 | 000,378,880 | —- | C] (The RaProducts Team: Paul McLain and Fred de Vries) – C:\Documents and Settings\T2\Desktop\JavaRa.exe
[2010.09.01 18:30:28 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010.09.01 17:18:16 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Application Data\Malwarebytes
[2010.09.01 17:18:08 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.09.01 17:18:06 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010.09.01 17:18:06 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010.09.01 17:18:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010.09.01 11:07:49 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010.09.01 11:03:32 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010.09.01 11:03:32 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010.09.01 11:03:32 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010.09.01 11:03:32 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010.09.01 11:03:13 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010.09.01 11:02:39 | 000,000,000 | —D | C] – C:\Qoobox
[2010.08.24 13:44:17 | 000,000,000 | —D | C] – C:\_OTL
[2010.08.24 13:14:32 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\My Documents\EXPO
[2010.08.23 16:56:17 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Local Settings\Application Data\IsolatedStorage
[2010.08.23 16:52:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nokia
[2010.08.23 16:52:10 | 000,018,816 | —- | C] (Nokia) – C:\WINDOWS\System32\drivers\pccsmcfd.sys
[2010.08.23 16:50:49 | 000,000,000 | —D | C] – C:\Program Files\Nokia
[2010.08.20 16:48:46 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Desktop\muzic putain
[2010.08.18 16:56:50 | 000,000,000 | —D | C] – C:\Program Files\Safari
[2010.08.18 15:21:15 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Local Settings\Application Data\Nokia
[2010.08.18 15:21:06 | 000,000,000 | —D | C] – C:\WINDOWS\Globalization
[2010.08.18 15:20:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NokiaMusic
[2010.08.18 15:17:38 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2010.08.15 21:03:18 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Data
[2010.08.15 21:01:11 | 000,197,632 | —- | C] (Microsoft) – C:\Program Files\Common Files\OnlineFilesManager.dll
[2010.08.09 23:51:15 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010.08.09 23:50:59 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010.08.09 23:50:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010.08.09 23:43:09 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010.08.09 23:34:54 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010.07.20 08:21:08 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\Application Data\vlc
[2010.06.28 09:25:27 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mercury Interactive
[2010.06.13 11:26:02 | 000,000,000 | —D | C] – C:\Documents and Settings\T2\My Documents\Promo
[2009.08.21 18:28:50 | 000,356,352 | —- | C] ( ) – C:\WINDOWS\System32\lxdiinpa.dll
[2009.08.21 18:28:50 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdiiesc.dll
[2009.08.21 18:28:50 | 000,311,296 | —- | C] ( ) – C:\WINDOWS\System32\lxdihcp.dll
[2009.08.21 18:28:49 | 001,187,840 | —- | C] ( ) – C:\WINDOWS\System32\lxdiserv.dll
[2009.08.21 18:28:49 | 000,942,080 | —- | C] ( ) – C:\WINDOWS\System32\lxdiusb1.dll
[2009.08.21 18:28:48 | 000,614,400 | —- | C] ( ) – C:\WINDOWS\System32\lxdipmui.dll
[2009.08.21 18:28:48 | 000,532,480 | —- | C] ( ) – C:\WINDOWS\System32\lxdilmpm.dll
[2009.08.21 18:28:48 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdiprox.dll
[2009.08.21 18:28:48 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdipplc.dll
[2009.08.21 18:28:47 | 000,671,744 | —- | C] ( ) – C:\WINDOWS\System32\lxdihbn3.dll
[2009.08.21 18:28:45 | 000,765,952 | —- | C] ( ) – C:\WINDOWS\System32\lxdicomc.dll
[2009.08.21 18:28:45 | 000,360,448 | —- | C] ( ) – C:\WINDOWS\System32\lxdicomm.dll
[2007.04.02 06:40:54 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2005.11.23 01:55:32 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[1 C:\Documents and Settings\T2\My Documents\*.tmp files -> C:\Documents and Settings\T2\My Documents\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010.09.08 19:40:59 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\T2\Desktop\OTL.exe
[2010.09.08 19:15:33 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010.09.08 19:09:00 | 000,001,054 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.09.08 19:06:01 | 000,001,134 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2094639727-349796869-1728803408-1006UA.job
[2010.09.08 09:01:26 | 000,111,571 | —- | M] () – C:\Documents and Settings\T2\Desktop\antivirus-download.JPG
[2010.09.08 08:57:30 | 000,061,352 | —- | M] () – C:\Documents and Settings\T2\Desktop\adobreader-popup.JPG
[2010.09.08 08:57:15 | 000,061,352 | —- | M] () – C:\Documents and Settings\T2\Desktop\wmp-popup.JPG
[2010.09.08 08:55:43 | 000,039,630 | —- | M] () – C:\Documents and Settings\T2\Desktop\hands-popup.JPG
[2010.09.07 15:17:50 | 000,659,968 | —- | M] () – C:\Documents and Settings\T2\Desktop\MicrosoftFixit50195.msi
[2010.09.07 13:32:32 | 000,143,872 | —- | M] () – C:\Documents and Settings\T2\Desktop\Timesheet_Nokia_Switzerland.xls
[2010.09.07 12:37:48 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010.09.07 11:36:00 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010.09.07 11:20:38 | 000,024,832 | —- | M] () – C:\WINDOWS\System32\9203853141.dll
[2010.09.07 11:18:32 | 000,001,050 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.09.07 11:18:10 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010.09.07 11:17:57 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010.09.07 11:17:53 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2010.09.07 11:16:58 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\T2\ntuser.ini
[2010.09.07 11:16:57 | 008,388,608 | -H– | M] () – C:\Documents and Settings\T2\NTUSER.DAT
[2010.09.07 11:16:17 | 000,001,646 | —- | M] () – C:\WINDOWS\System32\spupdsvc.inf
[2010.09.07 09:40:35 | 000,133,632 | —- | M] () – C:\Documents and Settings\T2\Desktop\RKUnhookerLE.EXE
[2010.09.06 01:06:00 | 000,001,082 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2094639727-349796869-1728803408-1006Core.job
[2010.09.04 19:57:29 | 000,218,624 | —- | M] () – C:\Documents and Settings\T2\Desktop\Copy of Feedbackbogen_RC_frz.xls
[2010.09.03 10:27:06 | 001,286,232 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\T2\Desktop\TDSSKiller.exe
[2010.09.02 18:17:30 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010.09.02 18:17:15 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010.09.02 17:49:54 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010.09.02 17:49:14 | 003,830,422 | R— | M] () – C:\Documents and Settings\T2\Desktop\ComboFix.exe
[2010.09.02 15:51:27 | 000,869,051 | —- | M] () – C:\Documents and Settings\T2\Desktop\SecurityCheck.exe
[2010.09.01 11:07:55 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010.09.01 10:48:47 | 000,000,174 | —- | M] () – C:\Documents and Settings\T2\defogger_reenable
[2010.08.27 23:35:25 | 000,331,480 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010.08.27 21:20:41 | 000,050,477 | —- | M] () – C:\Documents and Settings\T2\Desktop\Defogger.exe
[2010.08.27 15:35:18 | 000,083,768 | —- | M] () – C:\Documents and Settings\T2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010.08.26 11:18:44 | 000,997,390 | —- | M] () – C:\Documents and Settings\T2\Desktop\neirongzhinan.PDF
[2010.08.26 10:59:15 | 000,443,442 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010.08.26 10:59:15 | 000,072,516 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010.08.25 23:52:46 | 000,000,347 | —- | M] () – C:\WINDOWS\mercury.ini
[2010.08.25 17:32:45 | 000,526,486 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010.08.24 14:48:25 | 000,001,730 | -H– | M] () – C:\Documents and Settings\T2\My Documents\Default.rdp
[2010.08.23 21:59:44 | 000,000,440 | —- | M] () – C:\Documents and Settings\T2\Desktop\dump0.zip
[2010.08.23 21:59:11 | 000,000,512 | —- | M] () – C:\Documents and Settings\T2\Desktop\dump0.dat
[2010.08.23 13:46:15 | 000,043,266 | —- | M] () – C:\Documents and Settings\T2\Desktop\4917217001L_1.jpg
[2010.08.19 11:34:06 | 000,000,819 | —- | M] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010.08.18 16:57:43 | 000,057,896 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010.08.18 15:27:02 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010.08.18 15:20:08 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010.08.18 15:17:41 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010.08.09 14:51:12 | 000,378,880 | —- | M] (The RaProducts Team: Paul McLain and Fred de Vries) – C:\Documents and Settings\T2\Desktop\JavaRa.exe
[2010.08.08 14:08:40 | 000,003,027 | —- | M] () – C:\Documents and Settings\T2\Desktop\Français.lng
[2010.08.06 11:34:22 | 000,017,408 | —- | M] () – C:\Documents and Settings\T2\My Documents\Budgetisation.xls
[2010.07.30 19:20:28 | 004,768,204 | -H– | M] () – C:\Documents and Settings\T2\Local Settings\Application Data\IconCache.db
[2010.06.29 22:12:58 | 000,288,474 | —- | M] () – C:\Documents and Settings\T2\My Documents\Titus plonge5.wmv
[2010.06.29 11:30:00 | 001,426,900 | —- | M] () – C:\Documents and Settings\T2\My Documents\VIDEO_019.mp4
[1 C:\Documents and Settings\T2\My Documents\*.tmp files -> C:\Documents and Settings\T2\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.09.08 09:01:26 | 000,111,571 | —- | C] () – C:\Documents and Settings\T2\Desktop\antivirus-download.JPG
[2010.09.08 08:57:30 | 000,061,352 | —- | C] () – C:\Documents and Settings\T2\Desktop\adobreader-popup.JPG
[2010.09.08 08:56:03 | 000,061,352 | —- | C] () – C:\Documents and Settings\T2\Desktop\wmp-popup.JPG
[2010.09.08 08:55:43 | 000,039,630 | —- | C] () – C:\Documents and Settings\T2\Desktop\hands-popup.JPG
[2010.09.07 15:17:50 | 000,659,968 | —- | C] () – C:\Documents and Settings\T2\Desktop\MicrosoftFixit50195.msi
[2010.09.07 11:20:38 | 000,024,832 | —- | C] () – C:\WINDOWS\System32\9203853141.dll
[2010.09.07 09:40:34 | 000,133,632 | —- | C] () – C:\Documents and Settings\T2\Desktop\RKUnhookerLE.EXE
[2010.09.04 19:57:28 | 000,218,624 | —- | C] () – C:\Documents and Settings\T2\Desktop\Copy of Feedbackbogen_RC_frz.xls
[2010.09.02 17:46:59 | 000,001,646 | —- | C] () – C:\WINDOWS\System32\spupdsvc.inf
[2010.09.02 15:51:26 | 000,869,051 | —- | C] () – C:\Documents and Settings\T2\Desktop\SecurityCheck.exe
[2010.09.01 18:43:23 | 000,003,027 | —- | C] () – C:\Documents and Settings\T2\Desktop\Français.lng
[2010.09.01 11:07:55 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010.09.01 11:07:51 | 000,263,488 | —- | C] () – C:\cmldr
[2010.09.01 11:03:32 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010.09.01 11:03:32 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010.09.01 11:03:32 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010.09.01 11:03:32 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010.09.01 11:03:32 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010.09.01 10:48:31 | 000,000,174 | —- | C] () – C:\Documents and Settings\T2\defogger_reenable
[2010.08.27 21:21:05 | 003,830,422 | R— | C] () – C:\Documents and Settings\T2\Desktop\ComboFix.exe
[2010.08.27 21:20:40 | 000,050,477 | —- | C] () – C:\Documents and Settings\T2\Desktop\Defogger.exe
[2010.08.27 15:46:09 | 000,143,872 | —- | C] () – C:\Documents and Settings\T2\Desktop\Timesheet_Nokia_Switzerland.xls
[2010.08.26 11:19:15 | 000,997,390 | —- | C] () – C:\Documents and Settings\T2\Desktop\neirongzhinan.PDF
[2010.08.23 21:59:44 | 000,000,440 | —- | C] () – C:\Documents and Settings\T2\Desktop\dump0.zip
[2010.08.23 21:59:11 | 000,000,512 | —- | C] () – C:\Documents and Settings\T2\Desktop\dump0.dat
[2010.08.23 20:40:45 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010.08.23 13:46:14 | 000,043,266 | —- | C] () – C:\Documents and Settings\T2\Desktop\4917217001L_1.jpg
[2010.08.18 17:59:50 | 000,001,730 | -H– | C] () – C:\Documents and Settings\T2\My Documents\Default.rdp
[2010.08.18 16:57:43 | 000,057,896 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010.08.18 16:20:35 | 000,002,528 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2010.08.18 16:18:18 | 000,690,656 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010.08.18 15:27:02 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010.08.18 15:17:41 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010.07.19 21:37:55 | 001,426,900 | —- | C] () – C:\Documents and Settings\T2\My Documents\VIDEO_019.mp4
[2010.07.19 21:37:55 | 000,288,474 | —- | C] () – C:\Documents and Settings\T2\My Documents\Titus plonge5.wmv
[2010.06.28 09:25:22 | 000,000,347 | —- | C] () – C:\WINDOWS\mercury.ini
[2010.06.16 13:20:18 | 000,011,164 | —- | C] () – C:\Documents and Settings\T2\hs_err_pid3604.log
[2010.04.14 14:24:45 | 000,036,352 | —- | C] () – C:\WINDOWS\System32\SX32W.DLL
[2010.01.19 18:45:14 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010.01.19 18:45:14 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2010.01.18 21:36:36 | 000,002,143 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010.01.18 21:18:39 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009.10.10 16:22:40 | 000,002,528 | —- | C] () – C:\Documents and Settings\T2\Application Data\$_hpcst$.hpc
[2009.08.21 18:31:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdivs.dll
[2009.08.21 18:31:18 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\lxdicoin.dll
[2009.08.21 18:30:11 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\lxdicaps.dll
[2009.08.21 18:30:10 | 000,692,224 | —- | C] () – C:\WINDOWS\System32\lxdidrs.dll
[2009.08.21 18:30:10 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdicnv4.dll
[2009.08.21 18:28:50 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\lxdiinst.dll
[2009.08.21 18:28:47 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdigrd.dll
[2009.05.05 21:40:31 | 000,002,686 | —- | C] () – C:\WINDOWS\System32\SHORTCUT.INI
[2009.05.05 21:39:48 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\REMOTEDEVICE.INI
[2009.05.05 21:38:30 | 000,004,535 | —- | C] () – C:\WINDOWS\System32\LOCALSERVICE.INI
[2009.05.05 21:38:28 | 000,000,101 | —- | C] () – C:\WINDOWS\System32\LOCALDEVICE.INI
[2009.05.05 21:30:46 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\BSPRINT.INI
[2009.04.16 21:12:45 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\drivers\sfcure01.sys
[2009.02.06 11:01:24 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS45.DLL
[2008.11.17 15:38:34 | 000,052,736 | —- | C] () – C:\Documents and Settings\T2\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.11.16 18:40:00 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008.11.16 03:39:04 | 000,000,125 | —- | C] () – C:\Documents and Settings\T2\Local Settings\Application Data\fusioncache.dat
[2008.08.30 09:36:18 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008.08.04 18:04:44 | 000,000,951 | —- | C] () – C:\WINDOWS\System32\bscs.ini
[2008.08.04 17:36:50 | 000,405,589 | —- | C] () – C:\WINDOWS\System32\BsUI.dll
[2008.08.01 15:58:50 | 000,278,647 | —- | C] () – C:\WINDOWS\System32\outlookAddin.dll
[2008.08.01 15:58:30 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\HtmPrintHelper.dll
[2008.08.01 15:58:14 | 000,622,693 | —- | C] () – C:\WINDOWS\System32\BSShell.dll
[2008.08.01 15:56:14 | 000,098,403 | —- | C] () – C:\WINDOWS\System32\Bs2Res.dll
[2008.08.01 15:55:40 | 000,118,880 | —- | C] () – C:\WINDOWS\System32\BsMobileSDK.dll
[2008.08.01 15:55:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\BsMobileCSps.dll
[2008.08.01 15:46:30 | 017,907,824 | —- | C] () – C:\WINDOWS\System32\BsLangInDepRes.dll
[2008.08.01 15:46:30 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\BsVistaCommon.dll
[2008.07.31 04:37:26 | 000,006,782 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008.05.16 10:12:30 | 000,000,036 | —- | C] () – C:\WINDOWS\PidList.ini
[2008.04.15 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008.02.15 07:21:56 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2007.10.01 08:59:46 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2007.05.09 09:16:40 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2006.09.18 15:37:50 | 000,000,530 | —- | C] () – C:\WINDOWS\System32\tx12_ic.ini
[2006.09.18 15:37:48 | 000,667,280 | —- | C] () – C:\WINDOWS\System32\tx12.dll
[2005.03.29 00:45:26 | 000,000,153 | —- | C] () – C:\WINDOWS\ALaunch.ini
[2004.06.07 00:00:00 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\XVIDCORE.DLL
[2004.06.07 00:00:00 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\XVIDVFW.DLL

========== LOP Check ==========

[2008.12.04 13:57:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2DBoy
[2010.02.08 20:36:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010.02.04 18:57:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2009.04.19 08:34:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010.05.18 07:42:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoBoingo
[2010.02.01 11:23:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2010.08.18 15:20:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NokiaMusic
[2010.07.27 20:01:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010.04.14 14:15:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SDL International
[2008.11.17 05:29:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TRADOS
[2010.05.21 11:34:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEngineLite
[2010.08.09 23:52:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009.09.26 12:54:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.07.06 18:18:33 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Ableton
[2010.05.26 19:57:53 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\avidemux
[2009.10.10 12:31:45 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.04.19 08:33:45 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\DAEMON Tools Pro
[2009.10.20 17:56:23 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\FileZilla
[2010.05.08 12:05:51 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\foobar2000
[2009.11.30 19:00:08 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Foxit
[2010.01.04 15:32:26 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Foxit Software
[2010.03.22 11:39:20 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\GCMSWorkbench.2C30485F6B8C679517FCFDBDF0D73C7F278DFACC.1
[2009.05.05 21:04:27 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\GetRightToGo
[2009.08.21 18:35:17 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Lexmark Productivity Studio
[2010.08.18 15:22:01 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Nokia
[2010.04.12 17:58:39 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Notepad++
[2009.09.03 00:35:17 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\OpenOffice.org
[2008.12.11 07:47:54 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Opera
[2010.02.15 16:56:12 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\PC Suite
[2009.11.18 01:04:32 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\ScummVM
[2009.02.26 13:40:03 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\SDL International
[2010.06.16 13:18:29 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\SystemRequirementsLab
[2010.09.02 16:18:42 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Thunderbird
[2008.12.03 15:09:13 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\Trados
[2010.09.02 17:31:28 | 000,000,000 | —D | M] – C:\Documents and Settings\T2\Application Data\uTorrent
[2010.06.05 11:51:22 | 000,000,564 | —- | M] () – C:\WINDOWS\Tasks\12-March_to_the_Shore-FYU.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008.08.15 19:37:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010.01.26 11:43:41 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010.09.01 11:07:55 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004.08.03 23:00:08 | 000,263,488 | —- | M] () – C:\cmldr
[2010.09.02 18:22:57 | 000,038,306 | —- | M] () – C:\ComboFix.txt
[2008.08.15 19:37:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010.09.07 11:17:53 | 1061,105,664 | -HS- | M] () – C:\hiberfil.sys
[2008.08.15 19:37:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010.09.01 18:44:39 | 000,006,986 | —- | M] () – C:\JavaRa.log
[2010.02.11 11:14:28 | 000,003,163 | —- | M] () – C:\license.lic
[2008.08.15 19:37:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008.04.15 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008.04.15 05:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010.09.07 11:17:51 | 1585,446,912 | -HS- | M] () – C:\pagefile.sys
[2008.08.30 09:40:32 | 000,000,080 | —- | M] () – C:\Preload.aaa
[2008.08.15 19:57:08 | 000,000,542 | —- | M] () – C:\RHDSetup.log
[2010.04.14 14:13:15 | 145,245,184 | —- | M] () – C:\SDLT2007.msi
[2009.04.20 18:20:23 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009.04.20 18:45:49 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009.04.20 18:50:41 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009.04.20 19:05:00 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009.04.20 19:08:33 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009.04.20 19:41:06 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009.04.21 20:58:05 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009.10.10 14:48:25 | 000,000,292 | -H– | M] () – C:\sqmdata07.sqm
[2009.11.05 20:28:09 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009.03.12 04:08:03 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009.04.14 17:03:07 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009.04.16 16:45:39 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009.04.16 20:41:01 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009.04.17 17:54:07 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009.04.19 08:27:34 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2009.04.19 08:58:38 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009.04.20 18:04:40 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2009.04.20 18:07:28 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009.04.20 18:11:36 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009.04.20 18:17:50 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009.04.20 18:20:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009.04.20 18:45:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009.04.20 18:50:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009.04.20 19:04:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009.04.20 19:08:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009.04.20 19:41:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009.04.21 20:58:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009.10.10 14:48:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009.11.05 20:28:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009.03.12 04:08:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009.04.14 17:03:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009.04.16 16:45:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009.04.16 20:41:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009.04.17 17:54:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009.04.19 08:27:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009.04.19 08:58:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009.04.20 18:04:40 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009.04.20 18:07:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009.04.20 18:11:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009.04.20 18:17:49 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010.08.25 17:26:16 | 000,054,674 | —- | M] () – C:\TDSSKiller.2.4.1.2_25.08.2010_17.24.15_log.txt
[2010.09.05 17:43:58 | 000,054,054 | —- | M] () – C:\TDSSKiller.2.4.2.0_05.09.2010_17.37.17_log.txt
[1999.11.11 09:17:54 | 000,000,049 | —- | M] () – C:\XPH.TAG

< %systemroot%\Fonts\*.com >
[2006.04.18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006.06.29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006.04.18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006.06.29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008.08.15 19:37:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002.02.11 23:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD45.DLL
[2002.02.11 23:00:00 | 000,043,008 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP45.DLL
[2008.07.06 14:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007.03.15 23:08:12 | 000,113,664 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdidrpp.dll
[2007.04.09 07:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006.10.27 04:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008.07.06 12:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008.08.15 12:29:32 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008.08.15 12:29:32 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008.08.15 12:29:32 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008.08.15 19:37:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008.11.16 07:22:48 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008.08.15 19:43:46 | 000,000,079 | —- | M] () – C:\Documents and Settings\T2\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010.09.02 17:49:14 | 003,830,422 | R— | M] () – C:\Documents and Settings\T2\Desktop\ComboFix.exe
[2010.08.27 21:20:41 | 000,050,477 | —- | M] () – C:\Documents and Settings\T2\Desktop\Defogger.exe
[2010.08.09 14:51:12 | 000,378,880 | —- | M] (The RaProducts Team: Paul McLain and Fred de Vries) – C:\Documents and Settings\T2\Desktop\JavaRa.exe
[2010.09.08 19:40:59 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\T2\Desktop\OTL.exe
[2008.08.06 11:27:08 | 003,520,552 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Documents and Settings\T2\Desktop\procexp.exe
[2010.09.07 09:40:35 | 000,133,632 | —- | M] () – C:\Documents and Settings\T2\Desktop\RKUnhookerLE.EXE
[2010.09.02 15:51:27 | 000,869,051 | —- | M] () – C:\Documents and Settings\T2\Desktop\SecurityCheck.exe
[2010.09.03 10:27:06 | 001,286,232 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\T2\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >
[2010.08.15 21:01:11 | 000,197,632 | —- | M] (Microsoft) – C:\Program Files\Common Files\OnlineFilesManager.dll

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2005.02.19 21:52:52 | 000,240,640 | —- | M] () – C:\Documents and Settings\T2\My Documents\SFNightmare.exe
[1 C:\Documents and Settings\T2\My Documents\*.tmp files -> C:\Documents and Settings\T2\My Documents\*.tmp -> ]

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2008.04.15 05:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2008.11.16 07:22:49 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\T2\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010.09.08 18:55:40 | 000,049,152 | —- | M] () – C:\Documents and Settings\T2\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >
[2008.04.15 05:00:00 | 000,208,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\inf\unregmp2.exe

< %SYSTEMROOT%\Installer\*.exe >

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< %systemroot%\pchealth\helpctr\System\*.exe /s >

< %systemroot%\Web\*.exe >

< %systemroot%\system32\msn\*.* >

< %systemroot%\system32\*.tro >

< %AppData%\Microsoft\Installer\msupdates\*.* >

< %ProgramFiles%\Messenger\*.exe >
[2008.04.14 14:42:30 | 001,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe

< %systemroot%\system32\systhem32\*.* >

< %systemroot%\system\*.exe >

< %USERPROFILE%\Templates\*.tmp >

< %SYSTEMDRIVE%\explorexxx.exe\*.* >

< %Windir%\Installer\*.tmp >
[4 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]

< %systemroot%\System32\*.xco >

< %ProgramFiles%\system32\*.* >

< %systemroot%\System32\windos\*.* >

< %SystemRoot%\system32\sandbox\*.* >

< %SystemRoot%\system32\*.amo >

< %SystemRoot%\system32\Windows Live\*.* >

< %ProgramFiles%\logs\*.* >

< %ProgramFiles%\Bifrost\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-24 11:55:58
< End of report >
I have a few other things that I need to attend to before I can look at your latest log. I'd like for you to see if you can check for Windows updates, and if any are found to install them.
Hello,

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    [1 C:\Documents and Settings\T2\My Documents\*.tmp files -> C:\Documents and Settings\T2\My Documents\*.tmp -> ]
    [2010.09.07 11:20:38 | 000,024,832 | —- | M] () – C:\WINDOWS\System32\9203853141.dll
    [1 C:\Documents and Settings\T2\My Documents\*.tmp files -> C:\Documents and Settings\T2\My Documents\*.tmp -> ]
    [4 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI