This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help! Can't get rid of QQPCRT and Baidu! Have both logs rd

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-06-2015
Ran by [removed] (administrator) on F96F1C4BB on 05-06-2015 18:50:40
Running from C:\Documents and Settings\[removed]\My Documents\Downloads
[removed]
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(百度在线网络技术(北京)有限公司) C:\Program Files\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe
(百度在线网络技术(北京)有限公司) C:\Program Files\baidu\BaiduSd\3.0.0.4605\BaiduSdSvc.exe
(百度在线网络技术(北京)有限公司) C:\Program Files\baidu\BaiduAn\4.0.0.5166\BaiduAnSvc.exe
(Tencent) C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QQPCRTP.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(IDT, Inc.) C:\WINDOWS\sttray.exe
(SigmaTel, Inc.) C:\WINDOWS\stsystra.exe
(百度在线网络技术(北京)有限公司) C:\Program Files\baidu\BaiduSd\3.0.0.4605\BaiduSdTray.exe
(百度在线网络技术(北京)有限公司) C:\Program Files\baidu\BaiduAn\4.0.0.5166\BaiduAnTray.exe
(Tencent) C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QQPCTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Comfort Software Group) C:\Program Files\FreeAlarmClock\FreeAlarmClock.exe
(Spotify Ltd) C:\SpotifyWebHelper.exe
() C:\Program Files\baidu\baidu.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Baidu) C:\Program Files\Common Files\Baidu\BDDownload\109\bddownloader.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Tencent) C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMDeskTopGC.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Documents and Settings\Ralph\My Documents\Downloads\aswMBR.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\…\Run: [IDTSysTrayApp] => C:\WINDOWS\sttray.exe [405504 2007-09-05] (IDT, Inc.)
HKLM\…\Run: [SigmatelSysTrayApp] => C:\WINDOWS\stsystra.exe [282624 2006-07-27] (SigmaTel, Inc.)
HKLM\…\Run: [baidusdTray] => C:\Program Files\Baidu\BaiduSd\3.0.0.4605\BaiduSdTray.exe [3257240 2015-05-05] (百度在线网络技术(北京)有限公司)
HKLM\…\Run: [BaiduAnTray] => C:\Program Files\Baidu\BaiduAn\4.0.0.5166\BaiduAnTray.exe [3042312 2015-05-05] (百度在线网络技术(北京)有限公司)
HKLM\…\Run: [ QQPCTray] => C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QQPCTray.exe [355296 2015-05-05] (Tencent)
HKLM\…\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-04-07] (Apple Inc.)
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [FreeAC] => C:\Program Files\FreeAlarmClock\FreeAlarmClock.exe [1553688 2014-02-20] (Comfort Software Group)
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [Spotify Web Helper] => C:\SpotifyWebHelper.exe [2021944 2015-05-31] (Spotify Ltd)
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [Spotify] => C:\Spotify.exe [7323192 2015-05-31] (Spotify Ltd)
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [apphide] => C:\Program Files\baidu\baidu.exe [65536 2015-04-06] ()
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [Bubble Suite] => "C:\Documents and Settings\Ralph\Application Data\Nosibay\Bubble Suite\Bubble Suite.exe" /winstartup
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\Run: [MaxComputerCleaner] => C:\Program Files\Max Computer Cleaner\MaxComputerCleaner.exe true
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\MountPoints2: {4da88a1a-d6e0-11e3-9ee5-001d09305347} - E:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\MountPoints2: {62544eca-227d-11e4-873e-001d09305347} - F:\VerizonWirelessUpgradeAssistantSetup.exe -a
HKU\S-1-5-21-725345543-764733703-1801674531-1003\…\MountPoints2: {ef456abe-2564-11e4-873f-001d09305347} - F:\VerizonWirelessUpgradeAssistantSetup.exe -a
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMGCShellExt.dll [2015-05-05] (Tencent)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=91932766_hao_pg
HKU\S-1-5-21-725345543-764733703-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Start Page = https://mysearch.avg.com?cid={B47C2F90-5FAB-40A2-AF8F-72143DB8C637}∣=fe1c3dfc85f647cda4e8d1544fd4bab4-4d3b3d1cf427357051f071314fc3678e741461e4⟨=en&ds;=oc011&coid;=avgtbdisoc&cmpid;=≺=sa&d;=2015-01-0402:28:46&v;=18.3.0.885&pid;=safeguard&sg;=&sap;=hp
HKU\S-1-5-21-725345543-764733703-1801674531-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
URLSearchHook: [S-1-5-21-725345543-764733703-1801674531-1006] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\S-1-5-21-725345543-764733703-1801674531-1003 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?FORM=U270DF&PC;=U270&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-725345543-764733703-1801674531-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?FORM=U270DF&PC;=U270&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-725345543-764733703-1801674531-1003 -> {8D6CE8E7-F4C1-4096-9864-21DA27C45BB7} URL = 
BHO: WebMonBHO -> {15DEE173-1BE9-4424-81E0-58A87076E9B1} -> C:\Program Files\Baidu\BaiduSd\3.0.0.4605\websafe\WebMonBHO.dll [2014-11-06] (百度在线网络技术(北京)有限公司)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-04-29] (Oracle Corporation)
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} ->  No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-04-29] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-725345543-764733703-1801674531-1003 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
 
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_246.dll [2014-12-09] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @baidu.com/BaidusdDetectNPPlugin -> C:\Program Files\Baidu\BaiduSd\3.0.0.4605\explugin\npBaiduSDDetectPlug.dll [2014-11-06] (百度在线网络技术(北京)有限公司)
FF Plugin: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-04-29] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-04-29] (Oracle Corporation)
FF Plugin: @qq.com/QQPCMgr -> C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\npQMExtensionsMozilla.dll [2015-05-05] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-12-21] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR Profile: C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-05]
CHR Extension: (Google Docs) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-05]
CHR Extension: (Google Drive) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-05]
CHR Extension: (YouTube) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-05]
CHR Extension: (Google Search) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-05]
CHR Extension: (Google Sheets) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-05]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-20]
CHR Extension: (Google Wallet) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-20]
CHR Extension: (Gmail) - C:\Documents and Settings\Ralph\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-05]
CHR HKLM\…\Chrome\Extension: [ooebklgpfnbcnpokahmdidgbmlcdepkm] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-725345543-764733703-1801674531-1003\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 BaiduHips; C:\Program Files\Common Files\Baidu\BaiduHips\1.2.0.751\BaiduHips.exe [64008 2015-04-02] (百度在线网络技术(北京)有限公司)
R2 BDKVRTP; C:\Program Files\Baidu\BaiduSd\3.0.0.4605\BaiduSdSvc.exe [793096 2014-11-06] (百度在线网络技术(北京)有限公司)
R2 BDMRTP; C:\Program Files\Baidu\BaiduAn\4.0.0.5166\BaiduAnSvc.exe [1047048 2015-04-02] (百度在线网络技术(北京)有限公司)
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-04-29] (Oracle Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 QQPCRTP; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QQPCRTP.exe [297608 2015-05-05] (Tencent)
R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [6079848 2015-01-14] (Reimage®)
S3 TAOFrame; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\TAOFrame.exe [293728 2015-05-05] (Tencent)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [36864 2006-07-01] (Advanced Micro Devices)
R1 bd0001; C:\WINDOWS\System32\DRIVERS\bd0001.sys [86344 2015-04-02] (Baidu)
R1 bd0002; C:\WINDOWS\System32\DRIVERS\bd0002.sys [168392 2015-05-05] (Baidu)
R1 bd0003; C:\WINDOWS\System32\DRIVERS\bd0003.sys [56904 2014-11-06] (Baidu)
R2 BDArKit; C:\WINDOWS\System32\DRIVERS\BDArKit.sys [145224 2015-04-02] (Baidu Technology)
R1 BDDefense; C:\WINDOWS\System32\drivers\BDDefense.sys [121992 2015-05-18] (Baidu)
R1 BDEnhanceBoost; C:\WINDOWS\System32\DRIVERS\BDEnhanceBoost.sys [48328 2015-04-02] (Baidu)
R1 BDFileDefend; C:\WINDOWS\System32\DRIVERS\BDFileDefend.sys [26824 2014-11-06] (Baidu)
R2 BDMNetMon; C:\WINDOWS\System32\DRIVERS\BDMNetMon.sys [118472 2015-04-02] (Baidu)
R1 BDMWrench; C:\WINDOWS\System32\DRIVERS\BDMWrench.sys [239432 2015-04-02] (Baidu)
R1 BdSandBox; C:\WINDOWS\System32\DRIVERS\BdSandBox.sys [139784 2014-11-06] (Baidu)
S0 cercsr6; C:\WINDOWS\system32\Drivers\cercsr6.sys [39904 2004-12-13] (Adaptec, Inc.) [File not signed]
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-05] (Malwarebytes Corporation)
R0 nvata; C:\WINDOWS\System32\DRIVERS\nvata.sys [105472 2006-10-18] (NVIDIA Corporation)
R0 nvatabus; C:\WINDOWS\system32\Drivers\nvatabus.sys [105472 2006-10-18] (NVIDIA Corporation)
R0 nvgts; C:\WINDOWS\System32\DRIVERS\nvgts.sys [102400 2008-01-03] (NVIDIA Corporation)
R1 QMIEProtect; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMIEProtect.sys [49080 2015-05-05] ()
R1 QMUdisk; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QMUdisk.sys [60600 2015-05-05] (Tencent)
R2 QQSysMon; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\QQSysMon.sys [108344 2015-05-05] (电脑管家)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1171464 2006-07-27] (SigmaTel, Inc.)
R2 TAOAccelerator; C:\WINDOWS\system32\Drivers\TAOAccelerator.sys [77016 2015-05-05] (Tencent)
R2 TAOKernelDriver; C:\WINDOWS\system32\Drivers\TAOKernelXP.sys [139064 2015-05-05] (Tencent Technology(Shenzhen) Company Limited)
R3 TFsFlt; C:\WINDOWS\System32\Drivers\TFsFlt.sys [150072 2015-05-05] (电脑管家)
S3 TS888; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\TS888.sys [30392 2015-05-05] (Tencent)
R1 TSCPM; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\tscpm.sys [43448 2015-05-05] (电脑管家)
R1 TSDefenseBt; C:\WINDOWS\System32\DRIVERS\TSDefenseBt.sys [14008 2015-05-05] (Tencent)
R0 TsFltMgr; C:\WINDOWS\System32\DRIVERS\TSFLTMGR.SYS [123864 2015-05-05] (电脑管家)
R1 TSKSP; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\TSKsp.sys [204568 2015-05-05] (电脑管家)
S3 TSSK; C:\WINDOWS\System32\tssk.sys [67896 2015-05-05] (电脑管家)
R1 TSSysKit; C:\Program Files\Tencent\QQPCMgr\10.8.16208.227\TSSysKit.sys [101560 2015-05-05] (电脑管家)
R3 cpuz134; \??\C:\DOCUME~1\Ralph\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [X]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
U1 WS2IFSL; No ImagePath
U3 aswMBR; \??\C:\DOCUME~1\Ralph\LOCALS~1\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\DOCUME~1\Ralph\LOCALS~1\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-05 18:49 - 2015-06-05 18:49 - 00000551 _____ C:\Documents and Settings\Ralph\Desktop\aswMBR.txt
2015-06-05 18:34 - 2012-12-24 09:51 - 00001576 _____ C:\Documents and Settings\Ralph\Desktop\scan.txt
2015-06-05 18:34 - 2012-12-24 09:44 - 00602112 _____ (OldTimer Tools) C:\Documents and Settings\Ralph\Desktop\OTL.exe
2015-06-05 18:22 - 2015-06-05 18:23 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\RogueKiller
2015-06-05 18:22 - 2015-06-05 18:22 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-06-05 18:15 - 2015-06-05 18:50 - 00000000 ____D C:\FRST
2015-06-05 18:02 - 2015-06-05 18:02 - 00000332 _____ C:\WINDOWS\Tasks\ReimageUpdater.job
2015-06-05 18:02 - 2015-06-05 18:02 - 00000274 _____ C:\WINDOWS\Tasks\Reimage Reminder.job
2015-06-05 18:01 - 2015-06-05 18:03 - 00000000 ____D C:\rei
2015-06-05 18:01 - 2015-06-05 18:02 - 00000000 ____D C:\Program Files\Reimage
2015-06-05 18:01 - 2015-06-05 18:02 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Reimage Protector
2015-06-05 18:01 - 2015-06-05 18:01 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Reimage Repair
2015-06-05 18:00 - 2015-06-05 18:03 - 00000156 _____ C:\WINDOWS\Reimage.ini
2015-05-29 20:31 - 2015-05-31 22:10 - 00000000 ____D C:\Bovada
2015-05-29 20:31 - 2015-05-29 20:31 - 00000355 _____ C:\Documents and Settings\All Users\Desktop\BovadaPoker.lnk
2015-05-29 20:31 - 2015-05-29 20:31 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\BovadaPoker
2015-05-29 20:16 - 2015-05-29 20:16 - 00018458 _____ C:\Documents and Settings\Ralph\Desktop\Timberly dildo.xlsx
2015-05-27 20:10 - 2015-05-27 20:10 - 00000000 ____D C:\Documents and Settings\Ralph\Desktop\New Folder (2)
2015-05-27 07:32 - 2015-05-27 07:32 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
2015-05-27 07:31 - 2015-05-27 07:32 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-05-27 07:31 - 2015-05-27 07:31 - 00000000 ____D C:\Program Files\iPod
2015-05-27 07:25 - 2015-05-27 07:25 - 00001255 _____ C:\Documents and Settings\Ralph\Desktop\CopyTrans Control Center.lnk
2015-05-27 07:25 - 2015-05-27 07:25 - 00000000 ____D C:\Documents and Settings\Ralph\Start Menu\Programs\CopyTrans Control Center
2015-05-27 02:09 - 2015-05-27 02:09 - 00705500 _____ C:\Documents and Settings\Ralph\My Documents\cpe.xlsx
2015-05-20 23:14 - 2015-05-22 16:21 - 00000165 ____H C:\Documents and Settings\Ralph\Desktop\~$Revised Cash Forecast for T and R.xlsx
2015-05-20 18:20 - 2015-05-20 18:20 - 00090112 _____ C:\WINDOWS\Minidump\Mini052015-01.dmp
2015-05-19 07:35 - 2015-05-19 07:35 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
2015-05-18 19:15 - 2015-05-18 19:15 - 00090112 _____ C:\WINDOWS\Minidump\Mini051815-01.dmp
2015-05-18 02:30 - 2012-10-03 16:14 - 00026840 _____ (GEAR Software Inc.) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2015-05-18 01:54 - 2015-05-27 07:36 - 00000000 ____D C:\Program Files\iTunes
2015-05-18 01:52 - 2014-08-15 22:35 - 06112072 _____ (Apple, Inc.) C:\WINDOWS\system32\usbaaplrc.dll
2015-05-18 01:52 - 2014-08-15 22:35 - 00045056 _____ (Apple, Inc.) C:\WINDOWS\system32\Drivers\usbaapl.sys
2015-05-17 17:44 - 2015-06-05 18:49 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-16 21:57 - 2015-06-04 23:57 - 00039764 _____ C:\Documents and Settings\Ralph\Desktop\Revised Cash Forecast for T and R.xlsx
2015-05-10 07:28 - 2015-05-18 04:42 - 00000000 ____D C:\Documents and Settings\Ralph\Application Data\WindSolutions
2015-05-10 07:26 - 2015-05-18 04:10 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\WindSolutions
2015-05-10 02:33 - 2015-05-10 02:33 - 00057412 ____H C:\WINDOWS\system32\mlfcache.dat
2015-05-10 00:44 - 2015-05-10 00:44 - 00000000 ____D C:\Program Files\Bonjour
2015-05-09 19:29 - 2015-05-09 19:29 - 00000000 ____D C:\Documents and Settings\Ralph\Local Settings\Application Data\Help
2015-05-09 19:17 - 2015-05-09 20:03 - 00000434 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-06-05 18:51 - 2014-04-29 12:20 - 00000000 ____D C:\Documents and Settings\Ralph\Local Settings\Temp
2015-06-05 18:23 - 2014-04-29 12:10 - 01709723 _____ C:\WINDOWS\WindowsUpdate.log
2015-06-05 18:17 - 2015-05-05 05:17 - 00000342 _____ C:\WINDOWS\Tasks\Bubble Suite Update.job
2015-06-05 18:06 - 2014-11-28 14:58 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-06-05 17:50 - 2015-05-05 06:51 - 00000065 _____ C:\WINDOWS\QMNetworkMgr.ini
2015-06-05 17:49 - 2014-04-29 11:56 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-05 17:40 - 2014-04-29 13:09 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2015-06-05 17:39 - 2015-04-28 17:28 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-06-05 17:38 - 2014-08-22 13:52 - 00000000 ____D C:\Documents and Settings\Ralph\Application Data\Spotify
2015-06-05 17:36 - 2014-08-22 13:52 - 00000000 ____D C:\Documents and Settings\Ralph\Local Settings\Application Data\Spotify
2015-06-05 17:36 - 2004-08-04 04:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-06-05 17:35 - 2015-05-05 17:19 - 00000000 ____D C:\WINDOWS\SxsCaPendDel
2015-06-05 17:35 - 2015-05-05 05:40 - 00001028 _____ C:\WINDOWS\Tasks\QpdrbfFJvc.job
2015-06-05 17:35 - 2014-04-29 15:07 - 00000222 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-06-05 17:35 - 2014-04-29 12:20 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-06-05 17:35 - 2014-04-29 05:50 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-06-05 17:35 - 2014-04-29 05:50 - 00000048 _____ C:\WINDOWS\wiaservc.log
2015-06-05 02:06 - 2014-04-29 12:20 - 00032500 _____ C:\WINDOWS\SchedLgU.Txt
2015-06-04 17:30 - 2014-10-13 19:24 - 00000000 ____D C:\Documents and Settings\Ralph\Application Data\vlc
2015-06-02 10:43 - 2014-05-14 19:23 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2015-05-31 09:12 - 2015-04-28 18:36 - 41287224 _____ C:\libcef.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 10457856 _____ C:\icudtl.dat
2015-05-31 09:12 - 2015-04-28 18:36 - 07323192 _____ (Spotify Ltd) C:\Spotify.exe
2015-05-31 09:12 - 2015-04-28 18:36 - 04253463 _____ C:\devtools_resources.pak
2015-05-31 09:12 - 2015-04-28 18:36 - 03457592 _____ (Microsoft Corporation) C:\d3dcompiler_47.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 02106424 _____ (Microsoft Corporation) C:\d3dcompiler_43.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 02021944 _____ (Spotify Ltd) C:\SpotifyWebHelper.exe
2015-05-31 09:12 - 2015-04-28 18:36 - 02018406 _____ C:\cef.pak
2015-05-31 09:12 - 2015-04-28 18:36 - 01488440 _____ C:\libGLESv2.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 00968248 _____ (The Chromium Authors) C:\ffmpegsumo.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 00777272 _____ (Spotify Ltd) C:\SpotifyCrashService.exe
2015-05-31 09:12 - 2015-04-28 18:36 - 00598403 _____ C:\cef_200_percent.pak
2015-05-31 09:12 - 2015-04-28 18:36 - 00444515 _____ C:\cef_100_percent.pak
2015-05-31 09:12 - 2015-04-28 18:36 - 00124472 _____ (Spotify Ltd) C:\SpotifyLauncher.exe
2015-05-31 09:12 - 2015-04-28 18:36 - 00079928 _____ C:\libEGL.dll
2015-05-31 09:12 - 2015-04-28 18:36 - 00073272 _____ C:\wow_helper.exe
2015-05-31 09:12 - 2015-04-28 18:36 - 00000020 _____ C:\inst_ver.dat
2015-05-31 09:12 - 2015-04-28 18:36 - 00000000 ____D C:\locales
2015-05-30 22:14 - 2014-11-28 14:56 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TEMP
2015-05-27 07:31 - 2014-05-14 19:23 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Apple Computer
2015-05-27 07:29 - 2014-05-14 19:22 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-05-27 07:29 - 2014-05-14 19:22 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Apple
2015-05-27 00:55 - 2014-04-29 05:49 - 01002965 _____ C:\WINDOWS\iis6.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00902471 _____ C:\WINDOWS\FaxSetup.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00443165 _____ C:\WINDOWS\ocgen.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00417251 _____ C:\WINDOWS\tsoc.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00310536 _____ C:\WINDOWS\comsetup.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00186457 _____ C:\WINDOWS\ntdtcsetup.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00158925 _____ C:\WINDOWS\netfxocm.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00063551 _____ C:\WINDOWS\MedCtrOC.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00050079 _____ C:\WINDOWS\ocmsn.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00046234 _____ C:\WINDOWS\tabletoc.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00045381 _____ C:\WINDOWS\msgsocm.log
2015-05-27 00:55 - 2014-04-29 05:49 - 00001917 _____ C:\WINDOWS\imsins.log
2015-05-27 00:54 - 2014-04-29 05:49 - 00281916 _____ C:\WINDOWS\msmqinst.log
2015-05-27 00:48 - 2014-04-29 11:57 - 00000000 ____D C:\Program Files\7-Zip
2015-05-27 00:47 - 2014-04-29 12:20 - 00000178 ___SH C:\Documents and Settings\Ralph\ntuser.ini
2015-05-20 19:21 - 2014-04-29 15:01 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2719985$
2015-05-20 18:24 - 2014-09-27 15:21 - 00000000 ____D C:\WINDOWS\Minidump
2015-05-18 20:04 - 2014-12-24 13:52 - 00000000 ____D C:\Documents and Settings\Ralph\Desktop\New Folder
2015-05-18 19:31 - 2015-05-05 05:16 - 00121992 _____ (Baidu) C:\WINDOWS\system32\Drivers\BDDefense.sys
2015-05-18 18:42 - 2015-03-22 14:22 - 00120320 ___SH C:\Documents and Settings\Ralph\Desktop\Thumbs.db
2015-05-18 02:30 - 2014-04-29 05:48 - 00638609 _____ C:\WINDOWS\setupapi.log
2015-05-13 03:11 - 2014-04-29 13:31 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Microsoft Help
2015-05-13 03:09 - 2014-05-14 03:01 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-05-13 03:01 - 2014-04-29 13:56 - 137310008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-05-10 02:30 - 2014-05-14 19:25 - 00000000 ____D C:\Documents and Settings\Ralph\Application Data\Apple Computer
2015-05-09 19:29 - 2014-04-29 05:42 - 00000000 ____D C:\WINDOWS\Help
2015-05-09 19:17 - 2014-04-29 12:20 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Temp
2015-05-09 19:13 - 2014-04-29 05:49 - 00470938 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-05-08 15:00 - 2014-04-29 15:07 - 00000216 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
 
==================== Files in the root of some directories =======
 
2015-05-05 05:16 - 2015-05-05 05:17 - 0000078 _____ () C:\Documents and Settings\Ralph\Application Data\Bubble Suite.installation.log
2015-04-19 06:20 - 2015-04-19 06:20 - 0005872 ____N () C:\Documents and Settings\Ralph\Application Data\QpdrbfFJvc
2015-04-03 09:20 - 2015-04-03 09:20 - 0000664 _____ () C:\Documents and Settings\Ralph\Local Settings\Application Data\d3d9caps.tmp
2014-11-26 23:53 - 2015-04-10 19:42 - 0018944 _____ () C:\Documents and Settings\Ralph\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
Some files in TEMP:
====================
C:\Documents and Settings\Ralph\Local Settings\Temp\dllnt_dump.dll
C:\Documents and Settings\Ralph\Local Settings\Temp\F0212_s_31184.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\G0417_s_71353.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\javasysmo4105773096368611837.dll
C:\Documents and Settings\Ralph\Local Settings\Temp\jre-7u67-windows-i586-iftw.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\jre-8u40-windows-au.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\jre-8u45-windows-au.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\jueDEE.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\oi_{D3469AEE-67E9-43D4-8BB2-17E798A0755E}.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\optprosetup.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\PCMgr_AndroidServer.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\QQPCMgr_Setup.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\qqpcmgr_v10.8.16208.227_71919_Silence.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\ReimagePackage.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\ReiSysUpdate.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\setup3.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\Uninstall.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\UninstallModule.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\vcredist_x86.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\VerizonWirelessSoftwareUpgradeAssistant_1.3.1.exe
C:\Documents and Settings\Ralph\Local Settings\Temp\vlc-2.1.5-win32.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== End of log ============================
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-06-05 18:46:04
—————————–
18:46:04.656    OS Version: Windows 5.1.2600 Service Pack 3
18:46:04.656    Number of processors: 2 586 0x6B02
18:46:04.656    ComputerName: F96F1C4BB  UserName: Ralph
18:46:10.562    Initialize success
18:46:12.953    VM: initialized successfully
18:46:12.953    VM: Amd CPU virtualization not supported 
18:49:30.796    The log file has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\aswMBR.txt"
18:49:48.984    AVAST engine defs: 15060501
18:56:36.343    The log file has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\aswMBR.txt"
18:56:59.000    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\nvgts1Port0Path0Target0Lun0
18:56:59.015    Disk 0 Vendor: WDC_WD80 10.0 Size: 76293MB BusType: 1
18:56:59.281    Disk 0 MBR read successfully
18:56:59.281    Disk 0 MBR scan
18:56:59.390    Disk 0 Windows XP default MBR code
18:56:59.390    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS        76285 MB offset 63
18:56:59.437    Disk 0 default boot code
18:56:59.437    Disk 0 scanning sectors +156232125
18:56:59.531    Disk 0 scanning C:\WINDOWS\system32\drivers
18:57:10.453    Service scanning
18:57:47.937    Modules scanning
18:57:47.953    Disk 0 trace - called modules:
18:57:48.000    ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll SCSIPORT.SYS nvgts.sys 
18:57:48.000    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89d64998]
18:57:48.000    3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\0000006c[0x89db7720]
18:57:48.000    5 ACPI.sys[b9f62620] -> nt!IofCallDriver -> \Device\Scsi\nvgts1Port0Path0Target0Lun0[0x89d99030]
18:57:56.468    AVAST engine scan C:\WINDOWS
18:58:12.640    AVAST engine scan C:\WINDOWS\system32
19:00:16.578    AVAST engine scan C:\WINDOWS\system32\drivers
19:00:29.421    AVAST engine scan C:\Documents and Settings\Ralph
19:02:30.703    Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\MBR.dat"
19:02:30.718    The log file has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\aswMBR.txt"
19:14:18.156    File: C:\Documents and Settings\Ralph\Local Settings\Temp\jueDEE.exe  **INFECTED** Win32:GenMaliciousA-FRH [Adw]
19:14:29.343    File: C:\Documents and Settings\Ralph\Local Settings\Temp\nsjD6B.tmp  **INFECTED** Win32:Dropper-gen [Drp]
19:14:34.750    File: C:\Documents and Settings\Ralph\Local Settings\Temp\nssC9E.tmp  **INFECTED** Win32:Dropper-gen [Drp]
19:14:35.421    File: C:\Documents and Settings\Ralph\Local Settings\Temp\nsxBFE.tmp  **INFECTED** Win32:Adware-gen [Adw]
19:14:41.421    File: C:\Documents and Settings\Ralph\Local Settings\Temp\setup3.exe  **INFECTED** Win32:Malware-gen
19:14:44.656    File: C:\Documents and Settings\Ralph\Local Settings\Temp\UninstallModule.exe  **INFECTED** Win32:Dropper-gen [Drp]
19:15:41.546    File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\ET4ZA9AD\WinCheckSetup[1].exe  **INFECTED** Win32:Adware-gen [Adw]
19:16:58.546    File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\S7GZK32B\FinalInstaller_dotnet4[1].exe  **INFECTED** Win32:GenMaliciousA-FRH [Adw]
19:17:05.156    File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\S7GZK32B\JOSrv[1].exe  **INFECTED** Win32:Rootkit-gen [Rtk]
19:17:18.406    File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\S7GZK32B\runasu[1].exe  **INFECTED** Win32:Adware-gen [Adw]
19:17:40.484    File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\Y76R2LEL\CASrv[1].exe  **INFECTED** Win32:Rootkit-gen [Rtk]
19:17:44.562    File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\Y76R2LEL\dl[1].htm  **INFECTED** Win32:Dropper-gen [Drp]
19:18:13.062    File: C:\Documents and Settings\Ralph\Local Settings\Temporary Internet Files\Content.IE5\Y76R2LEL\UninstallModule[1].exe  **INFECTED** Win32:Dropper-gen [Drp]
19:19:10.703    AVAST engine scan C:\Documents and Settings\All Users
19:27:00.984    Disk 0 statistics 1499453/0/0 @ 0.52 MB/s
19:27:01.015    Scan finished successfully
19:27:18.203    Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\MBR.dat"
19:27:18.203    The log file has been saved successfully to "C:\Documents and Settings\Ralph\Desktop\aswMBR.txt"
 
 

:welcome:

 

When you ran FRST there should have been an Additions log in your downloads folder, post it please

 

You also have to realize that Windows XP is gone, it will still work but with Microsoft discontinuing updates its leaving your system very vulnerable to infection and most poker sites are prime for getting infected, you may want to think about upgrading your system to Windows 7 or maybe even about purchasing a new one 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI