Hi
Well thats why I was asking, since the pc seems to be running fine, and when I did used Firefox I dnt have any problems with pictures (red X), so I thought Maybe Uninstall IE, but if its still malware that wont help. As for the ISP (I have had a look at my contract with them an it expires in a month and half time so I will select a different ISP supplier.
Ran Fixit, still same issues on IE.
Below OTL log
again thanks for ur patience in assisting me.
OTL logfile created on: 08/07/2012 09:39:55 - Run 4
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Documents and Settings\sfvb\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
494.42 Mb Total Physical Memory | 117.52 Mb Available Physical Memory | 23.77% Memory free
1.13 Gb Paging File | 0.72 Gb Available in Paging File | 64.09% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 9.17 Gb Free Space | 46.93% Space Free | Partition Type: NTFS
Drive D: | 29.29 Gb Total Space | 6.80 Gb Free Space | 23.23% Space Free | Partition Type: NTFS
Drive E: | 29.29 Gb Total Space | 6.33 Gb Free Space | 21.61% Space Free | Partition Type: NTFS
Drive F: | 33.66 Gb Total Space | 8.36 Gb Free Space | 24.85% Space Free | Partition Type: NTFS
Computer Name: SF2 | User Name: sfvb | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\sfvb\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe ()
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\1XConfig.exe (Intel)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ========== MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe ()
MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL ()
========== Win32 Services (SafeList) ========== SRV - (HidServ) -- %SystemRoot%\System32\hidserv.dll File not found
SRV - (vToolbarUpdater10.2.0) -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe ()
SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (WLANKEEPER) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
========== Driver Services (SafeList) ========== DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (catchme) -- C:\DOCUME~1\sfvb\LOCALS~1\Temp\catchme.sys File not found
DRV - (Avgldx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) -- C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) -- C:\WINDOWS\system32\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (hwdatacard) -- C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (STAC97) Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (w29n51) Intel® -- C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (IWCA) -- C:\WINDOWS\system32\drivers\iwca.sys (Intel Corporation)
DRV - (bcm4sbxp) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (tifm) -- C:\WINDOWS\system32\drivers\tifm.sys (Texas Instruments)
DRV - (HSFHWICH) -- C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (OMCI) -- C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.msn.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...ferrer:source?} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.msn.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...Box&Form=IE8SRCIE - HKCU\..\SearchScopes\{B965E9D1-8213-415E-A181-F8175661ED1E}: "URL" =
http://www.bing.com/...rc=IE-SearchBoxIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@pptv.com/plugin: C:\Program Files\Internet Explorer\PPLite\plugin\npplugin2.dll (PPLive Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.709: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.709: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.709: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/14 12:45:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\AutocompletePro\
[email protected]FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/02/07 11:49:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\10.2.0.3\ [2012/03/15 09:26:22 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2012/07/06 22:22:04 | 000,000,022 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CA54D3F-CEAE-48AF-9A2B-31909CB9515D}
https://site.cmbchin...oad/CMBEdit.cab (Edit Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 114.64.255.146
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E21A50FD-326F-46B7-90B0-CED202A1549F}: DhcpNameServer = 208.67.222.222 208.67.220.220 114.64.255.146
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\IntelWireless: DllName - (C:\Program Files\Intel\Wireless\Bin\LgNotify.dll) - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\sfvb\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\sfvb\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/12 23:15:36 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2012/07/02 14:32:29 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009/03/13 13:44:31 | 000,000,000 | R--D | M] - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009/03/13 13:44:31 | 000,000,000 | R--D | M] - E:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009/03/13 13:44:31 | 000,000,000 | R--D | M] - F:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/07/07 11:14:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sfvb\Desktop\Fix IE
[2012/07/06 16:01:24 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/07/06 15:56:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012/07/06 15:10:47 | 016,430,008 | ---- | C] (Mozilla) -- C:\Documents and Settings\sfvb\Desktop\Firefox Setup 13.0.1.exe
[2012/07/04 23:14:39 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/07/04 23:14:39 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/07/04 23:14:39 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/07/04 23:14:39 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/07/04 23:13:10 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/07/04 23:05:59 | 004,572,925 | R--- | C] (Swearware) -- C:\Documents and Settings\sfvb\Desktop\ComboFix.exe
[2012/07/04 10:24:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sfvb\Application Data\TigerPlayer
[2012/07/03 22:00:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sfvb\Application Data\Malwarebytes
[2012/07/03 21:59:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/03 21:59:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/07/03 21:59:33 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/07/03 21:59:33 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/07/03 21:58:03 | 010,063,000 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\sfvb\Desktop\mbam-setup-1.61.0.1400.exe
[2012/07/03 21:40:40 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/07/03 21:37:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sfvb\Desktop\FixPolicies
[2012/07/03 21:36:52 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\sfvb\Desktop\OTL.exe
[2012/07/03 13:55:19 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Documents and Settings\sfvb\Desktop\aswMBR.exe
[2012/07/03 13:45:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/07/03 13:44:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2012/07/03 13:44:47 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2012/07/03 13:38:52 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\sfvb\Desktop\erunt-setup.exe
[2012/07/03 10:34:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\BaiduPlayer
[2012/07/02 21:57:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sfvb\Application Data\CometPlayer
[2012/07/02 14:32:29 | 000,000,000 | R--D | C] -- C:\autorun.inf
[2012/06/28 08:38:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla
[2012/06/22 12:14:57 | 000,684,288 | ---- | C] (RealNetworks, Inc.) -- C:\Documents and Settings\sfvb\Desktop\RealPlayer2012.exe
[2012/06/17 10:02:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Kingsoft
[2010/12/02 15:54:40 | 043,658,352 | ---- | C] (DivX, Inc.) -- C:\Program Files\DivXInstaller.exe
[2010/12/02 15:12:11 | 011,873,890 | ---- | C] (Audacity Team ) -- C:\Program Files\audacity-win-unicode-1.3.12.exe
[2010/06/21 10:04:29 | 000,092,064 | ---- | C] (MCCI) -- C:\Documents and Settings\sfvb\mqdmmdm.sys
[2010/06/21 10:04:29 | 000,079,328 | ---- | C] (MCCI) -- C:\Documents and Settings\sfvb\mqdmserd.sys
[2010/06/21 10:04:29 | 000,066,656 | ---- | C] (MCCI) -- C:\Documents and Settings\sfvb\mqdmbus.sys
[2010/06/21 10:04:29 | 000,009,232 | ---- | C] (MCCI) -- C:\Documents and Settings\sfvb\mqdmmdfl.sys
[2010/06/21 10:04:29 | 000,006,208 | ---- | C] (MCCI) -- C:\Documents and Settings\sfvb\mqdmcmnt.sys
[2010/06/21 10:04:29 | 000,005,936 | ---- | C] (MCCI) -- C:\Documents and Settings\sfvb\mqdmwhnt.sys
[2010/06/21 10:04:29 | 000,004,048 | ---- | C] (MCCI) -- C:\Documents and Settings\sfvb\mqdmcr.sys
[2010/06/21 10:04:28 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\sfvb\usbsermptxp.sys
[2010/06/21 10:04:28 | 000,022,768 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\sfvb\usbsermpt.sys
========== Files - Modified Within 30 Days ========== [2012/07/08 09:34:23 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-790525478-1677128483-1343024091-1003.job
[2012/07/08 09:34:20 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-790525478-1677128483-1343024091-1003.job
[2012/07/08 09:33:48 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/08 09:33:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/07/08 09:28:02 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/08 09:19:45 | 101,277,290 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/07/07 23:02:01 | 000,000,368 | ---- | M] () -- C:\WINDOWS\tasks\WpsUpdateTask_sfvb.job
[2012/07/07 22:49:56 | 000,025,088 | ---- | M] () -- C:\Documents and Settings\sfvb\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/07 22:31:21 | 000,000,911 | ---- | M] () -- C:\Documents and Settings\sfvb\Application Data\coreavc.ini
[2012/07/07 11:17:24 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012/07/07 11:17:24 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012/07/07 11:06:37 | 000,403,231 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\MiniToolBox.exe
[2012/07/07 11:06:18 | 000,415,707 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\Fix IE.zip
[2012/07/06 22:22:16 | 000,006,852 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\all
[2012/07/06 22:22:04 | 000,000,022 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/07/06 16:30:53 | 000,002,501 | ---- | M] () -- C:\Documents and Settings\sfvb\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office PowerPoint 2003.lnk
[2012/07/06 15:41:57 | 004,572,925 | R--- | M] (Swearware) -- C:\Documents and Settings\sfvb\Desktop\ComboFix.exe
[2012/07/06 15:10:47 | 016,430,008 | ---- | M] (Mozilla) -- C:\Documents and Settings\sfvb\Desktop\Firefox Setup 13.0.1.exe
[2012/07/06 13:19:43 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\sfvb\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2012/07/06 11:10:30 | 000,000,138 | ---- | M] () -- C:\WINDOWS\vsfilter.INI
[2012/07/05 11:09:09 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/07/04 22:59:06 | 000,649,555 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\Print screen.png
[2012/07/04 20:44:40 | 000,659,968 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\MicrosoftFixit50195.msi
[2012/07/04 17:00:30 | 000,181,354 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/07/03 21:59:41 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/03 21:58:03 | 010,063,000 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\sfvb\Desktop\mbam-setup-1.61.0.1400.exe
[2012/07/03 21:37:34 | 000,185,065 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\FixPolicies.exe
[2012/07/03 21:37:01 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sfvb\Desktop\OTL.exe
[2012/07/03 14:00:09 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\MBR.dat
[2012/07/03 13:58:25 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Documents and Settings\sfvb\Desktop\aswMBR.exe
[2012/07/03 13:44:52 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\NTREGOPT.lnk
[2012/07/03 13:44:52 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\ERUNT.lnk
[2012/07/03 13:39:09 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\sfvb\Desktop\erunt-setup.exe
[2012/07/03 10:33:14 | 015,519,888 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\BaiduPlayer1.14.0.132.exe
[2012/07/03 09:10:10 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/07/02 14:21:51 | 000,132,597 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\Flash_Disinfector.exe
[2012/06/22 13:28:30 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/06/22 12:15:02 | 000,684,288 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\sfvb\Desktop\RealPlayer2012.exe
[2012/06/17 17:26:49 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/06/11 16:56:39 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\sfvb\Desktop\Microsoft Office Word 2003.lnk
========== Files Created - No Company Name ========== [2012/07/07 11:06:30 | 000,403,231 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\MiniToolBox.exe
[2012/07/07 11:06:17 | 000,415,707 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\Fix IE.zip
[2012/07/06 22:22:15 | 000,006,852 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\all
[2012/07/04 23:14:39 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/07/04 23:14:39 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/07/04 23:14:39 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/07/04 23:14:39 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/07/04 23:14:39 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/07/04 22:59:05 | 000,649,555 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\Print screen.png
[2012/07/04 20:44:29 | 000,659,968 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\MicrosoftFixit50195.msi
[2012/07/03 21:59:41 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/03 21:37:26 | 000,185,065 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\FixPolicies.exe
[2012/07/03 14:00:09 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\MBR.dat
[2012/07/03 13:44:52 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\NTREGOPT.lnk
[2012/07/03 13:44:52 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\ERUNT.lnk
[2012/07/03 10:33:06 | 015,519,888 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\BaiduPlayer1.14.0.132.exe
[2012/07/02 14:21:51 | 000,132,597 | ---- | C] () -- C:\Documents and Settings\sfvb\Desktop\Flash_Disinfector.exe
[2012/05/17 16:26:37 | 000,000,305 | ---- | C] () -- C:\WINDOWS\System32\bdsecushr.dat
[2012/05/16 20:54:54 | 000,000,138 | ---- | C] () -- C:\WINDOWS\vsfilter.INI
[2012/04/28 15:04:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\psnetwork.ini
[2012/01/07 03:03:10 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\sfvb\Local Settings\Application Data\WebpageIcons.db
[2011/12/30 11:34:24 | 000,000,911 | ---- | C] () -- C:\Documents and Settings\sfvb\Application Data\coreavc.ini
[2011/06/15 20:18:44 | 000,112,128 | ---- | C] () -- C:\WINDOWS\System32\drvinst.exe
[2011/06/15 20:18:19 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\nmocod.dll
[2011/02/27 16:32:18 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\sfvb\Local Settings\Application Data\prvlcl.dat
[2010/07/16 03:32:29 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\sfvb\Local Settings\Application Data\fusioncache.dat
[2010/07/16 03:21:29 | 000,000,157 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2010/07/16 03:20:42 | 000,000,840 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2010/07/16 03:16:07 | 000,128,786 | ---- | C] () -- C:\WINDOWS\hppins02.dat
[2010/07/16 03:16:06 | 000,001,883 | ---- | C] () -- C:\WINDOWS\hppmdl02.dat
[2010/06/21 10:18:53 | 000,016,002 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem20.PNF
[2010/06/21 10:18:53 | 000,015,682 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem17.PNF
[2010/06/21 10:18:53 | 000,012,420 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem16.PNF
[2010/06/21 10:18:53 | 000,009,913 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem20.inf
[2010/06/21 10:18:53 | 000,009,232 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem17.inf
[2010/06/21 10:18:53 | 000,007,754 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem18.PNF
[2010/06/21 10:18:53 | 000,007,314 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem19.PNF
[2010/06/21 10:18:53 | 000,006,989 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem18.inf
[2010/06/21 10:18:53 | 000,005,960 | ---- | C] () -- C:\Documents and Settings\sfvb\1277086733-(null)
[2010/06/21 10:18:53 | 000,004,477 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem19.inf
[2010/06/21 10:18:52 | 000,014,334 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem13.PNF
[2010/06/21 10:18:52 | 000,012,828 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem14.PNF
[2010/06/21 10:18:52 | 000,012,794 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem15.PNF
[2010/06/21 10:18:52 | 000,007,201 | ---- | C] () -- C:\Documents and Settings\sfvb\1277086732-(null)
[2010/06/21 10:18:52 | 000,006,141 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem15.inf
[2010/06/21 10:18:52 | 000,005,880 | ---- | C] () -- C:\Documents and Settings\sfvb\Copy of oem14.inf
[2010/06/21 10:04:29 | 000,009,913 | ---- | C] () -- C:\Documents and Settings\sfvb\MCCI_MDM.INF
[2010/06/21 10:04:29 | 000,009,232 | ---- | C] () -- C:\Documents and Settings\sfvb\USB_MOT_BRIT.INF
[2010/06/21 10:04:29 | 000,006,989 | ---- | C] () -- C:\Documents and Settings\sfvb\MCCI_BUS.INF
[2010/06/21 10:04:29 | 000,006,141 | ---- | C] () -- C:\Documents and Settings\sfvb\USBMOT2000XP.INF
[2010/06/21 10:04:29 | 000,005,960 | ---- | C] () -- C:\Documents and Settings\sfvb\USB_MOT_A1000.INF
[2010/06/21 10:04:29 | 000,004,477 | ---- | C] () -- C:\Documents and Settings\sfvb\MCCI_SDM.INF
[2010/06/21 10:04:28 | 000,007,201 | ---- | C] () -- C:\Documents and Settings\sfvb\USBMOT2000.INF
[2010/06/21 10:04:28 | 000,005,880 | ---- | C] () -- C:\Documents and Settings\sfvb\USB_CMCS_2000.INF
[2010/03/25 20:17:11 | 000,025,088 | ---- | C] () -- C:\Documents and Settings\sfvb\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/14 16:26:19 | 000,000,406 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
========== Files - Unicode (All) ==========[2012/04/24 14:13:23 | 000,000,981 | ---- | M] ()(C:\Documents and Settings\All Users\Desktop\WPS??.lnk) -- C:\Documents and Settings\All Users\Desktop\WPS演示.lnk
[2012/04/24 14:13:23 | 000,000,981 | ---- | M] ()(C:\Documents and Settings\All Users\Desktop\WPS??.lnk) -- C:\Documents and Settings\All Users\Desktop\WPS文字.lnk
[2012/04/24 14:13:23 | 000,000,981 | ---- | C] ()(C:\Documents and Settings\All Users\Desktop\WPS??.lnk) -- C:\Documents and Settings\All Users\Desktop\WPS演示.lnk
[2012/04/24 14:13:23 | 000,000,966 | ---- | M] ()(C:\Documents and Settings\All Users\Desktop\WPS??.lnk) -- C:\Documents and Settings\All Users\Desktop\WPS表格.lnk
[2012/04/24 14:13:23 | 000,000,966 | ---- | C] ()(C:\Documents and Settings\All Users\Desktop\WPS??.lnk) -- C:\Documents and Settings\All Users\Desktop\WPS表格.lnk
[2012/04/24 14:13:22 | 000,000,981 | ---- | C] ()(C:\Documents and Settings\All Users\Desktop\WPS??.lnk) -- C:\Documents and Settings\All Users\Desktop\WPS文字.lnk
(C:\Documents and Settings\All Users\Start Menu\Programs\WPS Office ???) -- C:\Documents and Settings\All Users\Start Menu\Programs\WPS Office 个人版
< End of report >