NTVDM CPU 16 bit MS-DOS Subsystem [Solved] - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

NTVDM CPU 16 bit MS-DOS Subsystem [Solved] The NTVDM CPU has encountered an illegal instruction pop-up

#1 abs81

  • Group: Member
  • Posts: 13
  • Joined: 05-June 09

Posted 05 June 2009 - 04:00 AM

Hi There,

I am facing a nagging issue since a few days now.
Once I boot up my laptop everything is fine until i log on to the wireless network.
Every 5 minutes there after, i receive the following pop-up
The header of the pop-up is 16 bit MS-DOS Subsystem

The body is :
C:\DOCUME~1\Abdulk\G94A4H5~1.EXE
The NTVDM CPU has encountered an illegal instruction.
CS:0576 IP:0100 OP:63 6f 6e 63 75 Choose 'Close' to terminate the application.

Two buttons are present, Close and Ignore
Clicking on Ignore does not do anything, the pop-up remains.
Clicking on Close does close the window, only to see it pop-up again after 5 minutes or so.
Please advise!

My HJT Log is :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:49:56 PM, on 05-06-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\WatchGuard\Mobile VPN\ncpclcfg.exe
C:\Program Files\WatchGuard\Mobile VPN\ncprwsnt.exe
C:\Program Files\WatchGuard\Mobile VPN\ncpsec.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\WatchGuard\Mobile VPN\rwsrsu.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\OEM02Mon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ACT\ACT for Windows\Act.Scheduler.UI.exe
C:\Program Files\ACT\ACT for Windows\Act8.exe
C:\Program Files\WatchGuard\Mobile VPN\ncpbudgt.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\udaterui.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\McTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Documents and Settings\AbdulK\Application Data\taskmon.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\AbdulK\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ae/
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Spb Wallet - {2913D3DD-9363-4C21-B205-C19A584A0674} - C:\Program Files\Spb Wallet\SpbWalletToolbar.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ACTSchedulerUI] "C:\Program Files\ACT\ACT for Windows\Act.Scheduler.UI.exe" -Dfalse
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\Act8.exe" -stayrunning
O4 - HKLM\..\Run: [NcpBudget] "C:\Program Files\WatchGuard\Mobile VPN\ncpbudgt.exe"
O4 - HKLM\..\Run: [NcpPopup] "C:\Program Files\WatchGuard\Mobile VPN\ncppopup.exe" noerrmsg
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework360\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [JobHisInit] C:\Program Files\RDS\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Program Files\RDS\RMClient\MplSetUp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [TaskMon] C:\Documents and Settings\AbdulK\Application Data\taskmon.exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.co...sreqlab_srl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zon...1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1229032500399
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1229032489383
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/...tail/DASAct.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.12) - http://gameadvisor.f...bal/msc3121.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mayflex.local
O17 - HKLM\Software\..\Telephony: DomainName = mayflex.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mayflex.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mayflex.local
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ACT! Scheduler - Sage Software SB, Inc - c:\program files\act\act for windows\act.scheduler.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework360\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: ncpclcfg - NCP engineering GmbH - C:\Program Files\WatchGuard\Mobile VPN\ncpclcfg.exe
O23 - Service: ncprwsnt - NCP Engineering GmbH - C:\Program Files\WatchGuard\Mobile VPN\ncprwsnt.exe
O23 - Service: NcpSec - Unknown owner - C:\Program Files\WatchGuard\Mobile VPN\ncpsec.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RwsRsu (rwsrsu) - Unknown owner - C:\Program Files\WatchGuard\Mobile VPN\rwsrsu.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 11528 bytes

#2 pauline addis

  • Group: Visiting Consultant
  • Posts: 777
  • Joined: 06-September 08

Posted 09 June 2009 - 09:17 AM

Hello abs81 :),

Welcome to Geeks to Go!
My name is Pauline and I will be helping you to fix your computer.

But I need more information, so please, do as follow:
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


#3 abs81

  • Group: Member
  • Posts: 13
  • Joined: 05-June 09

Posted 09 June 2009 - 11:01 AM

Hi Pauline!

Many thanks for your reply, I have been checking my subscriptions every hour since June 5th! I am relieved I must add!

The infected computer is my work laptop, and I am worried that it will affect not only the computer and the external drives that I connected to it since the infection, but also my office colleagues, through the LAN. Also, as an added measure, once you have helped me to get rid of this infection, if you could kindly let me know some preventive measures that i should take to ensure that i am relatively protected against these type of infections.

Coming back to the OTL logs :

OTL.txt Log :

OTL logfile created on: 09-06-2009 08:49:23 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\AbdulK\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-MM-yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.41 Gb Total Space | 3.38 Gb Free Space | 13.84% Space Free | Partition Type: NTFS
Drive D: | 84.87 Gb Total Space | 80.04 Gb Free Space | 94.31% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USER-19EE27C6D1
Current User Name: AbdulK
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\McAfee\Common Framework360\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework360\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\WatchGuard\Mobile VPN\ncpclcfg.exe (NCP engineering GmbH)
PRC - C:\Program Files\WatchGuard\Mobile VPN\ncprwsnt.exe (NCP Engineering GmbH)
PRC - C:\Program Files\WatchGuard\Mobile VPN\ncpsec.exe ()
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\WatchGuard\Mobile VPN\rwsrsu.exe ()
PRC - C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\WINDOWS\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\ACT\ACT for Windows\Act.Scheduler.UI.exe (Sage Software SB, Inc)
PRC - C:\Program Files\ACT\ACT for Windows\Act8.exe (Sage Software SB, Inc)
PRC - C:\Program Files\WatchGuard\Mobile VPN\ncpbudgt.exe (NCP engineering GmbH)
PRC - C:\Program Files\McAfee\Common Framework360\Common Framework\udaterui.exe (McAfee, Inc.)
PRC - D:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework360\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Documents and Settings\AbdulK\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aawservice [Auto | Running]) -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
SRV - (AcrSch2Svc [Auto | Running]) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (ACT! Scheduler [Auto | Stopped]) -- c:\program files\act\act for windows\act.scheduler.exe (Sage Software SB, Inc)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (btwdins [Auto | Running]) -- C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-092308-165331 [On_Demand | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (HP Port Resolver [On_Demand | Stopped]) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE (Hewlett-Packard Company)
SRV - (HP Status Server [On_Demand | Stopped]) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE (Hewlett-Packard Company)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (McAfeeFramework [Unknown | Running]) -- C:\Program Files\McAfee\Common Framework360\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
SRV - (McTaskManager [Unknown | Running]) -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (MSSQL$ACT7 [Auto | Running]) -- C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper [On_Demand | Stopped]) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (Microsoft Corporation)
SRV - (ncpclcfg [Auto | Running]) -- C:\Program Files\WatchGuard\Mobile VPN\ncpclcfg.exe (NCP engineering GmbH)
SRV - (ncprwsnt [Auto | Running]) -- C:\Program Files\WatchGuard\Mobile VPN\ncprwsnt.exe (NCP Engineering GmbH)
SRV - (NcpSec [Auto | Running]) -- C:\Program Files\WatchGuard\Mobile VPN\ncpsec.exe ()
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (rwsrsu [Auto | Running]) -- C:\Program Files\WatchGuard\Mobile VPN\rwsrsu.exe ()
SRV - (ServiceLayer [On_Demand | Stopped]) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (SQLAgent$ACT7 [On_Demand | Stopped]) -- C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlagent.EXE (Microsoft Corporation)
SRV - (WinVNC4 [Auto | Running]) -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)
SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (APPDRV [System | Running]) -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (bcm4sbxp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (btaudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTDriver [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWDNDIS [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\btwhid.sys (Broadcom Corporation.)
DRV - (btwmodem [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (ENTECH [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ENTECH.sys (EnTech Taiwan)
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWAZL [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (L8042mou [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\L8042mou.Sys (Logitech, Inc.)
DRV - (LHidKe [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LHidKE.Sys (Logitech, Inc.)
DRV - (LHidUsbK [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LHidUsbK.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mfeapfk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfeavfk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [System | Running]) -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys (McAfee, Inc.)
DRV - (mfetdik [System | Running]) -- C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (NcpFilt [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ncpvaxp.sys (NCP Engineering GmbH)
DRV - (NcpFiltMP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ncpvaxp.sys (NCP Engineering GmbH)
DRV - (ncpvaxp [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ncpvaxp.sys (NCP Engineering GmbH)
DRV - (nmwcd [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdc [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (OEM02Afx [On_Demand | Running]) -- C:\WINDOWS\system32\Drivers\OEM02Afx.sys (Creative Technology Ltd.)
DRV - (OEM02Dev [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (OEM02Vfx [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (pccsmcfd [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys (Nokia)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (rimmptsk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\rimsptsk.sys (REDC)
DRV - (rismxdp [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\rixdptsk.sys (REDC)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (snapman [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (STHDA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (StillCam [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (tap0901 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\tap0901.sys (The OpenVPN Project)
DRV - (tifsfilter [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\tifsfilt.sys (Acronis)
DRV - (timounter [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (upperdev [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (usbser [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbser.sys (Microsoft Corporation)
DRV - (UsbserFilt [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
DRV - (usb_rndisx [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\usb8023x.sys (Microsoft Corporation)
DRV - (vncmirror [System | Running]) -- C:\WINDOWS\system32\DRIVERS\vncmirror.sys (RealVNC Ltd.)
DRV - (w39n51 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\w39n51.sys (Intel® Corporation)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ae/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 7\BKMRKSYNC\ [2009-01-12 13:33:34 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009-04-09 13:23:20 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009-06-08 09:23:59 | 00,000,000 | ---D | M]


O1 HOSTS File: (752 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 10.0.10.9 exchange
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Spb Wallet) - {2913D3DD-9363-4C21-B205-C19A584A0674} - C:\Program Files\Spb Wallet\SpbWalletToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\Act8.exe" -stayrunning (Sage Software SB, Inc)
O4 - HKLM..\Run: [ACTSchedulerUI] "C:\Program Files\ACT\ACT for Windows\Act.Scheduler.UI.exe" -Dfalse File not found
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [JobHisInit] C:\Program Files\RDS\RMClient\JobHisInit.exe (RICOH COMPANY,LTD.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE (Logitech Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework360\Common Framework\udaterui.exe" /StartedFromRunKey (McAfee, Inc.)
O4 - HKLM..\Run: [MplSetUp] C:\Program Files\RDS\RMClient\MplSetUp.exe (RICOH COMPANY,LTD.)
O4 - HKLM..\Run: [NcpBudget] "C:\Program Files\WatchGuard\Mobile VPN\ncpbudgt.exe" (NCP engineering GmbH)
O4 - HKLM..\Run: [NcpPopup] "C:\Program Files\WatchGuard\Mobile VPN\ncppopup.exe" noerrmsg ()
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [NWEReboot] File not found
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RegistryMechanic] File not found
O4 - HKLM..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE (McAfee, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon (Microsoft Corporation)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" (Nero AG)
O4 - HKCU..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.srtest.co...sreqlab_srl.cab (System Requirements Lab Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zon...1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat...b?1229032500399 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1229032489383 (MUWebControl Class)
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} http://das.microsoft.com/activate/cab/x86/...tail/DASAct.cab (DASWebDownload Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk...ows-i586-jc.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} http://gameadvisor.f...bal/msc3121.cab (Measurement Services Client v.3.12)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mayflex.local
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-08-27 22:50:00 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{c6cd2d43-4506-11de-b610-001c2385bab9}\Shell - "" = AutoRun
O33 - MountPoints2\{c6cd2d43-4506-11de-b610-001c2385bab9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c6cd2d43-4506-11de-b610-001c2385bab9}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O33 - MountPoints2\{c6cd2d44-4506-11de-b610-001c2385bab9}\Shell\AutoRun\command - "" = DATA\DELETED\POWER.exe
O33 - MountPoints2\{c6cd2d44-4506-11de-b610-001c2385bab9}\Shell\open\command - "" = DATA\DELETED\POWER.exe
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009-06-09 20:46:46 | 00,000,000 | ---D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[2009-06-09 20:46:37 | 00,501,760 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\AbdulK\Desktop\OTL.exe
[2009-06-09 19:43:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\AbdulK\Application Data\Malwarebytes
[2009-06-09 19:43:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009-06-09 19:41:02 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009-06-09 19:20:25 | 00,264,704 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\AbdulK\Desktop\TFC.exe
[2009-06-09 15:36:23 | 00,445,979 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Malware and Spyware Cleaning Guide.mht
[2009-06-09 11:49:09 | 00,061,952 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\PI Excel IBM 09-06-09.xls
[2009-06-09 11:46:10 | 00,071,168 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\OPME 1 - IBM SO.doc
[2009-06-09 06:05:28 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\PromoItemReport.xls
[2009-06-09 06:02:08 | 00,147,456 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\DubaiRepStockReport.xls
[2009-06-08 13:30:43 | 00,027,646 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Etisalat Bill.pdf
[2009-06-08 12:18:12 | 00,043,520 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\BoQ - Cabling RTA 08-06-09.xls
[2009-06-08 11:09:42 | 00,018,432 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Quote Magic Touch 08-06-09.xls
[2009-06-08 09:24:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2009-06-08 09:22:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\AbdulK\Application Data\Sun
[2009-06-07 16:29:11 | 09,184,256 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\1. T111-1C-NTT1-Excel format.xls
[2009-06-07 11:31:49 | 07,823,936 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Excel Overview Revised Pres_2008 v2.pptx
[2009-06-07 11:27:42 | 04,614,280 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Extreme_Summitt_04_09_final.pptx
[2009-06-07 11:01:00 | 00,016,896 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Quote Final Revision E Passport 07-06-09.xls
[2009-06-07 10:24:47 | 00,022,016 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Revised Quote Excel silicon 07-06-09.xls
[2009-06-05 21:40:44 | 00,020,927 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\PrintReceipt.pdf
[2009-06-05 13:13:49 | 00,000,000 | ---D | C] -- C:\bintheredunthat
[2009-06-05 13:10:50 | 00,071,009 | ---- | C] () -- C:\alcanshorty.bfu
[2009-06-05 06:05:20 | 00,039,424 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\CreditProfiles.xls
[2009-06-05 00:55:48 | 00,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\AbdulK\Desktop\HijackThis.exe
[2009-06-05 00:51:47 | 00,081,920 | ---- | C] (Soeperman Enterprises Ltd.) -- C:\BFU.exe
[2009-06-04 18:54:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\AbdulK\Application Data\Help
[2009-06-04 13:26:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Acronis
[2009-06-04 13:20:20 | 00,000,824 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Acronis True Image Home 9.0.lnk
[2009-06-04 13:20:09 | 00,000,000 | ---D | C] -- C:\Program Files\Acronis
[2009-06-04 12:13:34 | 00,093,018 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\NTVDM CPU Problem.JPG
[2009-06-04 00:46:19 | 00,002,855 | ---- | C] () -- C:\WINDOWS\System32\command.PIF
[2009-06-04 00:46:19 | 00,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2009-06-03 23:48:28 | 00,005,282 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2009-06-03 22:26:36 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Acronis
[2009-06-02 09:20:36 | 00,024,064 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Sample Board Layouts.xls
[2009-06-01 12:05:19 | 02,221,709 | ---- | C] () -- C:\Documents and Settings\AbdulK\My Documents\Excel Warranty Terms_V2 3.pdf
[2009-06-01 09:09:37 | 00,040,960 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Sensitive Information- Desktop.xls
[2009-05-31 15:50:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\AbdulK\My Documents\Spb Wallets
[2009-05-31 13:53:21 | 00,000,680 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Spb Wallet.lnk
[2009-05-31 13:53:16 | 00,000,000 | ---D | C] -- C:\Program Files\Spb Wallet
[2009-05-28 21:54:48 | 00,000,000 | RHSD | C] -- C:\RECYCLED
[2009-05-28 10:21:27 | 01,389,401 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\practice-routine-generator.pdf
[2009-05-27 09:26:10 | 00,043,008 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\ICC 20-20 WC 2009.xls
[2009-05-25 09:17:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\AbdulK\My Documents\ECP Pack
[2009-05-24 12:50:14 | 00,015,872 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Excel BoQ ABDU Ethiopia 24-05-09.xls
[2009-05-20 11:52:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\AbdulK\Application Data\U3
[2009-05-20 10:23:48 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\May Sale - AK.xls
[2009-05-16 18:16:45 | 00,000,000 | RHSD | C] -- C:\DATA
[2009-05-13 14:38:36 | 01,161,429 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\20080922_Welcome-Pack-08-25-08.pdf
[2009-05-12 12:31:00 | 00,000,928 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Shortcut to PlantsVsZombies.exe.lnk
[2009-05-12 12:29:42 | 00,000,000 | ---- | C] () -- C:\WINDOWS\popcreg.dat
[2009-05-12 12:10:59 | 00,032,768 | ---- | C] () -- C:\Documents and Settings\AbdulK\Desktop\Mayflex Sales Meeting.xls
[2009-05-09 18:32:38 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009-05-09 18:32:35 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009-05-09 18:32:35 | 00,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009-05-09 18:32:35 | 00,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009-05-09 18:32:34 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009-05-09 18:32:33 | 00,084,480 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009-04-28 18:15:33 | 00,000,226 | ---- | C] () -- C:\WINDOWS\PMJobCli.ini
[2009-04-28 18:15:29 | 00,012,309 | ---- | C] () -- C:\WINDOWS\PMRicMb.ini
[2009-04-28 18:15:29 | 00,007,873 | ---- | C] () -- C:\WINDOWS\PMRicPMb.ini
[2009-04-28 18:15:29 | 00,005,390 | ---- | C] () -- C:\WINDOWS\PMPrtMb.ini
[2009-04-28 18:15:29 | 00,004,644 | ---- | C] () -- C:\WINDOWS\PMRicFMb.ini
[2009-04-28 18:15:29 | 00,003,149 | ---- | C] () -- C:\WINDOWS\PMDvPrn.ini
[2009-04-28 18:15:29 | 00,002,102 | ---- | C] () -- C:\WINDOWS\PMDvDev.ini
[2009-04-28 18:15:29 | 00,002,047 | ---- | C] () -- C:\WINDOWS\PMDIOMb.ini
[2009-04-28 18:15:29 | 00,002,036 | ---- | C] () -- C:\WINDOWS\PMHostMb.ini
[2009-04-28 18:15:29 | 00,001,885 | ---- | C] () -- C:\WINDOWS\PMPSIOMb.ini
[2009-04-28 18:15:29 | 00,001,727 | ---- | C] () -- C:\WINDOWS\PMRicSMb.ini
[2009-04-28 18:15:29 | 00,001,706 | ---- | C] () -- C:\WINDOWS\PMRicCMb.ini
[2009-04-28 18:15:29 | 00,001,494 | ---- | C] () -- C:\WINDOWS\PMMib2Mb.ini
[2009-04-28 18:15:29 | 00,001,168 | ---- | C] () -- C:\WINDOWS\PMDvFax.ini
[2009-04-28 18:15:29 | 00,001,143 | ---- | C] () -- C:\WINDOWS\PMDPIMb.ini
[2009-04-28 18:15:29 | 00,001,094 | ---- | C] () -- C:\WINDOWS\PMAxsMb.ini
[2009-04-28 18:15:29 | 00,000,842 | ---- | C] () -- C:\WINDOWS\PMDvScan.ini
[2009-04-28 18:15:29 | 00,000,423 | ---- | C] () -- C:\WINDOWS\PMDvCopy.ini
[2009-04-28 18:15:29 | 00,000,332 | ---- | C] () -- C:\WINDOWS\PMSnmpMb.ini
[2009-04-28 18:15:26 | 00,000,035 | ---- | C] () -- C:\WINDOWS\RidocPrn.ini
[2009-04-28 18:15:09 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\PMObservps.dll
[2008-12-31 17:04:42 | 00,691,560 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2008-08-31 09:33:29 | 00,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2008-08-31 09:33:06 | 00,000,139 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2008-08-31 09:32:46 | 00,000,677 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2008-08-30 03:01:39 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-08-29 23:03:59 | 00,014,848 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2008-08-29 15:47:45 | 00,002,150 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2008-08-29 15:47:45 | 00,000,056 | RHS- | C] () -- C:\WINDOWS\System32\057CB5E5FF.sys
[2008-08-28 14:05:20 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-08-27 23:10:16 | 00,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2008-08-27 17:17:55 | 00,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008-04-14 16:00:00 | 00,000,702 | ---- | C] () -- C:\WINDOWS\win.ini
[2008-04-14 16:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2007-05-18 01:52:30 | 02,842,624 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2007-05-18 01:23:20 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2007-05-11 02:03:00 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007-05-11 02:03:00 | 01,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007-05-11 02:03:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007-05-11 02:03:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007-05-11 02:03:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007-03-29 22:00:40 | 00,203,264 | ---- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
[2006-09-26 03:07:52 | 00,033,792 | ---- | C] () -- C:\WINDOWS\System32\A620USD.dll
[2005-02-17 23:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005-02-17 23:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2004-12-05 13:30:20 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\Hijri32.dll
[2003-01-07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001-11-19 19:05:18 | 00,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2001-11-15 00:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[2001-07-07 03:00:00 | 00,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini

========== Files - Modified Within 30 Days ==========

[2009-06-09 20:46:48 | 00,501,760 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\AbdulK\Desktop\OTL.exe
[2009-06-09 20:22:00 | 00,002,150 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2009-06-09 20:21:06 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-06-09 20:20:38 | 00,000,264 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2009-06-09 20:20:27 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\AbdulK\Local Settings\desktop.ini
[2009-06-09 20:20:06 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-06-09 20:20:04 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-06-09 19:20:33 | 00,264,704 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\AbdulK\Desktop\TFC.exe
[2009-06-09 17:08:33 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\May Sale - AK.xls
[2009-06-09 15:36:30 | 00,445,979 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Malware and Spyware Cleaning Guide.mht
[2009-06-09 14:23:04 | 00,000,264 | ---- | M] () -- C:\WINDOWS\tasks\OGADaily.job
[2009-06-09 12:08:46 | 00,061,952 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\PI Excel IBM 09-06-09.xls
[2009-06-09 11:46:10 | 00,071,168 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\OPME 1 - IBM SO.doc
[2009-06-09 06:05:28 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\PromoItemReport.xls
[2009-06-09 06:02:08 | 00,147,456 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\DubaiRepStockReport.xls
[2009-06-08 13:31:38 | 00,015,872 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\to do weekend.xls
[2009-06-08 13:30:43 | 00,027,646 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Etisalat Bill.pdf
[2009-06-08 12:30:53 | 00,043,520 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\BoQ - Cabling RTA 08-06-09.xls
[2009-06-08 11:13:16 | 00,018,432 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Quote Magic Touch 08-06-09.xls
[2009-06-07 16:29:31 | 09,184,256 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\1. T111-1C-NTT1-Excel format.xls
[2009-06-07 14:54:07 | 00,004,096 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\ScheduledItems
[2009-06-07 11:31:51 | 07,823,936 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Excel Overview Revised Pres_2008 v2.pptx
[2009-06-07 11:27:45 | 04,614,280 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Extreme_Summitt_04_09_final.pptx
[2009-06-07 11:18:29 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-06-07 11:01:00 | 00,016,896 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Quote Final Revision E Passport 07-06-09.xls
[2009-06-07 10:24:47 | 00,022,016 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Revised Quote Excel silicon 07-06-09.xls
[2009-06-05 21:40:44 | 00,020,927 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\PrintReceipt.pdf
[2009-06-05 13:10:52 | 00,071,009 | ---- | M] () -- C:\alcanshorty.bfu
[2009-06-05 06:05:20 | 00,039,424 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\CreditProfiles.xls
[2009-06-04 19:15:14 | 00,000,702 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-06-04 19:15:14 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-06-04 19:15:14 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009-06-04 13:20:20 | 00,000,824 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Acronis True Image Home 9.0.lnk
[2009-06-04 12:13:35 | 00,093,018 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\NTVDM CPU Problem.JPG
[2009-06-04 00:46:19 | 00,002,855 | ---- | M] () -- C:\WINDOWS\System32\command.PIF
[2009-06-03 23:50:51 | 00,005,282 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2009-06-03 17:37:16 | 00,024,064 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Sample Board Layouts.xls
[2009-06-01 12:05:20 | 02,221,709 | ---- | M] () -- C:\Documents and Settings\AbdulK\My Documents\Excel Warranty Terms_V2 3.pdf
[2009-06-01 09:17:20 | 00,040,960 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Sensitive Information- Desktop.xls
[2009-05-31 16:49:32 | 00,462,426 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-05-31 16:49:32 | 00,079,684 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-05-31 16:49:31 | 00,551,896 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-05-31 13:53:21 | 00,000,680 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Spb Wallet.lnk
[2009-05-28 10:21:27 | 01,389,401 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\practice-routine-generator.pdf
[2009-05-27 09:28:09 | 00,043,008 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\ICC 20-20 WC 2009.xls
[2009-05-25 09:26:27 | 00,032,768 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Mayflex Sales Meeting.xls
[2009-05-24 12:50:14 | 00,015,872 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Excel BoQ ABDU Ethiopia 24-05-09.xls
[2009-05-13 14:38:36 | 01,161,429 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\20080922_Welcome-Pack-08-25-08.pdf
[2009-05-12 12:31:00 | 00,000,928 | ---- | M] () -- C:\Documents and Settings\AbdulK\Desktop\Shortcut to PlantsVsZombies.exe.lnk
[2009-05-12 12:29:42 | 00,000,000 | ---- | M] () -- C:\WINDOWS\popcreg.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8CE646EE
< End of report >


EXTRAS.txt Log :

OTL Extras logfile created on: 09-06-2009 08:49:32 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\AbdulK\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-MM-yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.41 Gb Total Space | 3.38 Gb Free Space | 13.84% Space Free | Partition Type: NTFS
Drive D: | 84.87 Gb Total Space | 80.04 Gb Free Space | 94.31% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USER-19EE27C6D1
Current User Name: AbdulK
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0x00000000
"FirewallDisableNotify" = 0x00000000
"UpdatesDisableNotify" = 0x00000000
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\McAfee\Common Framework360\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service (McAfee, Inc.)
C:\Program Files\InternetCalls.com\InternetCalls\InternetCalls.exe:*:Enabled:InternetCalls (InternetCalls)
C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk (Google)
C:\Documents and Settings\AbdulK\Local Settings\Temp\hp_webrelease\setup\HPZnet01.exe:*:Enabled:hpznet01.exe File not found
C:\Documents and Settings\AbdulK\Local Settings\Temp\hp_webrelease\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe File not found
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
D:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe (Hewlett-Packard Development Company, L.P.)
D:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe (Hewlett-Packard Development Company, L.P.)
D:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe (Hewlett-Packard Development Company, L.P.)
D:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe (Hewlett-Packard Development Company, L.P.)
D:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe ()
D:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe (Hewlett-Packard)
D:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe (Hewlett-Packard Development Company, L.P.)
D:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe (Hewlett-Packard)
D:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe (Hewlett-Packard Development Company, L.P.)
D:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe (Hewlett-Packard)
D:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe ( )
D:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe (Hewlett-Packard Development Company, L.P.)
D:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\12Voip.com\12Voip\12Voip.exe:*:Enabled:12Voip (12Voip)
C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe:*:Enabled:FreeCall (FreeCall)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype (Skype Technologies S.A.)
C:\Program Files\ACT\ACT for Windows\Act8.exe:*:Enabled:ACT! Premium 2006 (Sage Software SB, Inc)
C:\Program Files\ACT\ACT for Windows\Act.Scheduler.UI.exe:*:Enabled:ACT! Scheduler (Sage Software SB, Inc)
D:\Program Files\Lavasoft\Ad-Aware2007.exe:*:Enabled:Ad-Aware 2007 File not found
C:\Program Files\IBS Enterprise Client\AswClientWin.exe:*:Enabled:IBS Enterprise Client 6.00 (IBS AB, Corporate Headquarters, P. O. Box 1350, SE-171 26 Solna)
C:\Program Files\WatchGuard\WatchGuard Mobile VPN with SSL\wgsslvpnc.exe:*:Enabled:Mobile VPN with SSL client ()
C:\Program Files\Network Associates\VirusScan\mcconsol.exe:*:Enabled:VirusScan Console File not found
C:\Program Files\Network Associates\VirusScan\shcfg32.exe:*:Enabled:VirusScan On-Access Scan File not found
C:\Program Files\Network Associates\VirusScan\ScnCfg32.Exe:*:Enabled:VirusScan On-Demand Scan File not found
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe:*:Enabled:Google Desktop (Google)
C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager (Microsoft Corporation)
C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager (Microsoft Corporation)
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application (Microsoft Corporation)
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus File not found
C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater (Nokia Corporation)
C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process (Nokia Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\WatchGuard\Mobile VPN\NCPMON.exe:*:Enabled:ncpmon.exe (NCP engineering GmbH)
C:\Documents and Settings\AbdulK\Application Data\taskmon.exe:*:Enabled:taskmon File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\McAfee\Common Framework360\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service (McAfee, Inc.)
C:\Program Files\InternetCalls.com\InternetCalls\InternetCalls.exe:*:Enabled:InternetCalls (InternetCalls)
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server File not found
C:\Program Files\12Voip.com\12Voip\12Voip.exe:*:Enabled:12Voip (12Voip)
C:\Program Files\Acoustica CD Label Maker\cdlabel.exe:*:Disabled:Acoustica CD Label Maker ( Acoustica Inc.)
C:\Program Files\WatchGuard\WatchGuard Mobile VPN with SSL\wgsslvpnc.exe:*:Enabled:Mobile VPN with SSL client ()
C:\Program Files\FreeCall.com\FreeCall\FreeCall.exe:*:Enabled:FreeCall (FreeCall)
C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager (Microsoft Corporation)
C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager (Microsoft Corporation)
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application (Microsoft Corporation)
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype (Skype Technologies S.A.)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Documents and Settings\AbdulK\Application Data\taskmon.exe:*:Disabled:taskmon File not found

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0E6AB9FC-76C2-431B-9C06-6C1CFFFEA8EB}" = Ad-Aware 2007
"{0F1C652A-003A-4E3D-A442-E612F209F853}" = Hijri Calendar
"{15AC0C5D-A6FB-4CE2-8CD0-28179EEB5625}" = Nokia Connectivity Cable Driver
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{1E7F9E62-D2B9-4B22-86D8-99E24D6C58A9}" = IRISCard 4 Pro
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{268D8766-8280-4BE5-9680-2BC769E5855A}" = ACT! Premium 2006
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35C03C04-3F1F-42C2-A989-A757EE691F65}" = McAfee VirusScan Enterprise
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{36FE3EDA-0C18-48DE-934B-D9862F82A7A8}" = McAfee Agent
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}" = Skype Plugin Manager
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{4781569D-5404-1F26-4B2B-6DF444441031}" = Nero 7 Ultra Edition
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}" = Nokia PC Suite
"{59367F7E-D7C1-4629-8AEC-71AA24A68F31}" = Nokia Software Updater
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5D8BD582-EB43-43E1-8532-9E38FD9338AA}" = 3200
"{612B9183-67A9-4B44-9877-2F059E35B86A}" = Broadcom 440x 10/100 Integrated Controller
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D4111AC-12C2-4169-87B2-6D9FFF4FD9A4}" = ACT!
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{784CFD4D-1BA5-4DB5-9377-84DAF0D19EF1}" = WinXP Manager
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{84F1DAC1-E1BF-4A21-9D2B-DD3E12686A2C}" = Read in Microsoft Reader Add-in for Microsoft Word
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-1033-F400-7760-000000000003}" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"{B148AB4B-C8FA-474B-B981-F2943C5B5BCD}" = OGA Notifier 1.7.0105.35.0
"{B1914265-0D07-48E0-A937-F20A76D0032D}" = Acronis True Image Home
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C138D676-4F0F-4FDE-8BE5-26CFD3566DCD}" = DeskTopBinder - SmartDeviceMonitor for Client
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D002159B-91CD-48E5-96D1-C476BA3DECB3}" = 3100_3200_3300_Help
"{D3227BD6-7D66-4B96-BA01-C21FB1F2224D}" = 3100_3200_3300trb
"{D3C80E77-E549-4F76-BC07-61DDBD950345}" = Silent Hill 2
"{D848D140-41C3-4A53-86D8-E866A100B4CD}" = PC Connectivity Solution
"{D99C322D-C21B-40C7-AE71-EE51AA096B6E}" = Nokia Flashing Cable Driver
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"{IBSClientWin-V6}_is1" = IBS Enterprise Client for Windows 6.00
"12Voip_is1" = 12Voip
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"5986551A16FD8E9B1B4C89E7AAD17C1BB3196D28" = Windows Driver Package - Nokia Modem (10/27/2008 7.01.0.1)
"6D296974BAB6CA8429D5E687B292A6DA3E9FBD4A" = Windows Driver Package - Nokia Modem (10/27/2008 3.9)
"9CD348AE9C64C4B939B624E8E24F3903EFDFC82B" = Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1)
"Acoustica CD/DVD Label Maker" = Acoustica CD/DVD Label Maker
"Adobe Acrobat 8 Professional - English, Français, Deutsch" = Adobe Acrobat 8.1.0 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AoA Audio Extractor_is1" = AoA Audio Extractor 1.0
"Audio Converter Pro" = River Past Audio Converter Pro
"C5A76DC11BABDA0A881E7BE8DDEB641365A77FFD" = Windows Driver Package - Nokia Modem (05/22/2008 3.8)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Creative OEM002" = Laptop Integrated Webcam Driver (1.03.02.0719)
"DELL Webcam Center" = DELL Webcam Center
"DELL Webcam Manager" = DELL Webcam Manager
"Digsby" = Digsby
"FreeCall_is1" = FreeCall
"Google Desktop" = Google Desktop
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{268D8766-8280-4BE5-9680-2BC769E5855A}" = ACT! Premium 2006
"InternetCalls_is1" = InternetCalls
"J Walk Windows Client" = J Walk Windows Client (32 bit)
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.8.0
"LimeWire" = LimeWire 4.14.8
"McAfee Anti-Spyware Enterprise Module" = McAfee AntiSpyware Enterprise Module
"Measurement Services Client" = Futuremark Measurement Services Client
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mobile VPN with SSL client_is1" = WatchGuard Mobile VPN with SSL client 10
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NCP RWS/GA" = WatchGuard Mobile VPN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia PC Suite" = Nokia PC Suite
"NVIDIA Drivers" = NVIDIA Drivers
"Plants vs. Zombies" = Plants vs. Zombies
"RealVNC_is1" = VNC Enterprise Edition E4.3.1
"Registry Mechanic_is1" = Registry Mechanic 5.1
"Skype_is1" = Skype 3.0
"Spb Wallet_is1" = Spb Wallet 1.5.1
"SystemRequirementsLab" = System Requirements Lab
"Unlocker" = Unlocker 1.8.7
"VLC media player" = VideoLAN VLC media player 0.8.6a
"VNCMirror_is1" = VNC Mirror Driver 1.7
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01005" = Microsoft User-Mode Driver Framework Feature Pack 1.5
"Yahoo! Messenger" = Yahoo! Messenger

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 09-06-2009 11:28:18 AM | Computer Name = USER-19EE27C6D1 | Source = ACT! Scheduler | ID = 0
Description = Service cannot be started. System.Exception: Unable to get scheduler
configuration. Object reference not set to an instance of an object. at Act.Scheduler.SchedulerService.GetSchedulerConfiguration()

at Act.Scheduler.SchedulerService.OnStart(String[] args) at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
state)

Error - 09-06-2009 11:28:18 AM | Computer Name = USER-19EE27C6D1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 09-06-2009 11:28:19 AM | Computer Name = USER-19EE27C6D1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 09-06-2009 11:29:32 AM | Computer Name = USER-19EE27C6D1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for MAYFLEX\AbdulK failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 09-06-2009 12:18:47 PM | Computer Name = USER-19EE27C6D1 | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 09-06-2009 12:20:22 PM | Computer Name = USER-19EE27C6D1 | Source = ACT! Scheduler | ID = 0
Description = Service cannot be started. System.Exception: Unable to get scheduler
configuration. Object reference not set to an instance of an object. at Act.Scheduler.SchedulerService.GetSchedulerConfiguration()

at Act.Scheduler.SchedulerService.OnStart(String[] args) at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
state)

Error - 09-06-2009 12:20:24 PM | Computer Name = USER-19EE27C6D1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 09-06-2009 12:20:24 PM | Computer Name = USER-19EE27C6D1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 09-06-2009 12:20:28 PM | Computer Name = USER-19EE27C6D1 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 09-06-2009 12:21:41 PM | Computer Name = USER-19EE27C6D1 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for MAYFLEX\AbdulK failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

[ System Events ]
Error - 06-06-2009 11:24:57 AM | Computer Name = USER-19EE27C6D1 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain MAYFLEX due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.

Error - 06-06-2009 01:51:39 PM | Computer Name = USER-19EE27C6D1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 07-06-2009 01:12:08 PM | Computer Name = USER-19EE27C6D1 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain MAYFLEX due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.

Error - 07-06-2009 01:17:02 PM | Computer Name = USER-19EE27C6D1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 07-06-2009 01:17:59 PM | Computer Name = USER-19EE27C6D1 | Source = Dhcp | ID = 1002
Description = The IP address lease 10.0.76.4 for the Network Card with network address
00FFAE34AB3B has been denied by the DHCP server 10.0.76.254 (The DHCP Server sent
a DHCPNACK message).

Error - 09-06-2009 11:08:57 AM | Computer Name = USER-19EE27C6D1 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain MAYFLEX due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.

Error - 09-06-2009 11:19:25 AM | Computer Name = USER-19EE27C6D1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 09-06-2009 11:23:25 AM | Computer Name = USER-19EE27C6D1 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain MAYFLEX due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.

Error - 09-06-2009 11:25:36 AM | Computer Name = USER-19EE27C6D1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 09-06-2009 11:28:17 AM | Computer Name = USER-19EE27C6D1 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain MAYFLEX due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.


< End of report >

#4 pauline addis

  • Group: Visiting Consultant
  • Posts: 777
  • Joined: 06-September 08

Posted 10 June 2009 - 02:23 AM

Hello abs81,

Sorry for the delay...

It seems that you already have made some cleaning on this computer.
Can you tell me what have been found previously by McAfee, MBAM or others please ?

The spreading method depends on the infections.
For your usb keys and external hard drives, let's use flash disinfector. It will clean and protect your media from any autorun infection.
You can keep and use this tool to scan any suspicious key or external drive. Also, you should open them by right-click > explore rather than double-click, which launch the infection if present.

And don't worry, we won't let you go without some advices on programs to use to protect your system :)


Ok, let's begin:


Step 1

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [ACTSchedulerUI] "C:\Program Files\ACT\ACT for Windows\Act.Scheduler.UI.exe" -Dfalse File not found
    O4 - HKLM..\Run: [NWEReboot] File not found
    O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
    O4 - HKLM..\Run: [RegistryMechanic] File not found
    O33 - MountPoints2\{c6cd2d44-4506-11de-b610-001c2385bab9}\Shell\AutoRun\command - "" = DATA\DELETED\POWER.exe
    O33 - MountPoints2\{c6cd2d44-4506-11de-b610-001c2385bab9}\Shell\open\command - "" = DATA\DELETED\POWER.exe
    
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    C:\Documents and Settings\AbdulK\Application Data\taskmon.exe=-
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    C:\Documents and Settings\AbdulK\Application Data\taskmon.exe=-
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log

Step 2

Download Flash_Disinfector.exe by sUBs to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.

Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you run it. Don't delete this folder...it will help protect your drives from future infection.


Step 3

Download ComboFix by sUBs to your Desktop.

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
    Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


  • Double click combofix.exe and follow the prompts.


  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.


  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
  • Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
  • CF disconnects your machine from the Internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


#5 abs81

  • Group: Member
  • Posts: 13
  • Joined: 05-June 09

Posted 10 June 2009 - 02:47 AM

Hi Pauline,

Many thanks for your reply, I appreciate the same.

However, when I am trying to download the Flash_Disinfector.exe, McAfee pops-up, displays the file being downloaded as a Trojan, deletes it and asks me to close the window. Basically it is preventing me from downloading the Flash_Disinfector.exe file. I went through the 'How to disable your security programs' as well, but since it is a corporate AV program, we do not have access to the exit button when we right click the 'M' Logo in the system tray.

Kindly help!

Thanks a ton for everything again,
regards,
Abs81.

#6 abs81

  • Group: Member
  • Posts: 13
  • Joined: 05-June 09

Posted 10 June 2009 - 03:41 AM

Hi Pauline,

A Quick one.

If i download the Flash_Disinfector.exe at home using my personal laptop, and then transfer it to this one using a flash drive, will it work or will McAfee still deny access to it? I guess it will still block it!please help!

Also, i have noticed that whenever i boot the laptop with the 'Wifi' on(or at work with the LAN connected), once the laptop boots, i get a pop-up stating that Windows Explorer encountered an error and needs to close.It closes windows explorer, screen goes blank, system tray and taskbar closes, and then reopens, and the same pop-up appears.If i boot up with the LAN disconnected and the Wifi off, and once boot up is complete then either connect to LAN or switch on the Wifi, the pop-up does not appear.
Also, regarding your earlier query on MBAM, I actually have deleted the logs that were generated using MBAM, since after running it, the po-ups still appeared, and i guessed that a more specific solution was required to clear this problem. I hope that the MBAM log was not critical to your solution!

Waiting to hear from you,
Thanks again,
Abs81.

#7 pauline addis

  • Group: Visiting Consultant
  • Posts: 777
  • Joined: 06-September 08

Posted 10 June 2009 - 04:28 AM

Hello Abs81,

If you can't disable McAfee, as soon as you will try to use Flash Disinfector, downloaded from another computer, it will be deleted. Can you add some exceptions? If yes, download it with your personal laptop and transfer it.

Open the VirusScan Console
Right-click On-Access Scanner and select Properties
Click All Processes, Detection, Exclusions
See if you can add Flash Disinfector as an exception

If not, you can scan you external drives with your personal computer (you don't need to open them, and don't allow the automatical run) or I will indicate you later another tool.


Can you boot in Safe Mode? If yes, do so before running ComboFix to not let McAfee interfer with the tool.
To start in safe mode:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.

Concerning your question about network, to avoid getting infected or infect other users over the network, basic tips are to use a firewall (If you do not already have one, install Sunbelt Personal Firewall or Online Armor (good and free). See Understanding and Using Firewalls for more information), avoid sharing drives (You can check to see if you have enabled sharing by right clicking on the drive icon in My Computer, then select Sharing.), and be careful about the attachments you can receive by mails or Instant Messaging programs.


So let's go on the OTL and combofix steps please.

#8 abs81

  • Group: Member
  • Posts: 13
  • Joined: 05-June 09

Posted 10 June 2009 - 05:35 AM

Hi Pauline,

I will do as you say, will run the flash Disinfector file on my personal laptop and connect my external drives to it and hopefully that should do the trick.

Please find the OTL log as shown below :

========== OTL ==========
Process explorer.exe killed successfully!
No active process named Mcshield.exe was found!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ACTSchedulerUI deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NWEReboot deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RegistryMechanic deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c6cd2d44-4506-11de-b610-001c2385bab9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c6cd2d44-4506-11de-b610-001c2385bab9}\ not found.
File DATA\DELETED\POWER.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c6cd2d44-4506-11de-b610-001c2385bab9}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c6cd2d44-4506-11de-b610-001c2385bab9}\ not found.
File DATA\DELETED\POWER.exe not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Documents and Settings\AbdulK\Application Data\taskmon.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Documents and Settings\AbdulK\Application Data\taskmon.exe deleted successfully.
========== FILES ==========
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\WCESLog.log scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF39EB.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF3A1F.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF3B7F.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF3BB7.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF3CAA.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF3CBC.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF52DD.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF5BA.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF91EB.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DFBDE.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~DFF6D7.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\AbdulK\Local Settings\Temp\~WRD2815.doc scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_534.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6b4.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\WFV1.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTL by OldTimer - Version 2.1.1.0 log created on 06102009_144331

Files moved on Reboot...
C:\Documents and Settings\AbdulK\Local Settings\Temp\WCESLog.log moved successfully.
File C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF39EB.tmp not found!
File C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF3A1F.tmp not found!
File C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF3B7F.tmp not found!
File C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF3BB7.tmp not found!
File C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF3CAA.tmp not found!
File C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF3CBC.tmp not found!
C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF52DD.tmp moved successfully.
File C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF5BA.tmp not found!
File C:\Documents and Settings\AbdulK\Local Settings\Temp\~DF91EB.tmp not found!
File C:\Documents and Settings\AbdulK\Local Settings\Temp\~DFBDE.tmp not found!
C:\Documents and Settings\AbdulK\Local Settings\Temp\~DFF6D7.tmp moved successfully.
File C:\Documents and Settings\AbdulK\Local Settings\Temp\~WRD2815.doc not found!
File C:\WINDOWS\temp\Perflib_Perfdata_534.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_6b4.dat not found!
File move failed. C:\WINDOWS\temp\WFV1.tmp scheduled to be moved on reboot.

Registry entries deleted on Reboot...


Also, please find the CF log as shown below :

ComboFix 09-06-09.06 - Administrator 10-06-2009 15:04.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.3285 [GMT 4:00]
Running from: D:\ComboFix.exe
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\data\DELETED
c:\data\DELETED\Desktop.ini
c:\documents and settings\AbdulK\q1se1u3.exe
c:\documents and settings\AbdulK\qd1u3.exe
c:\documents and settings\AbdulK\v7k9f1o4r1c8.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\recycle\D-0-060-0000000000-1111111-2222222
c:\recycle\D-0-060-0000000000-1111111-2222222\Desktop.ini
c:\recycle\D-0-060-0000000000-1111111-2222222\FiX.exe
c:\windows\system32\command.pif
c:\windows\system32\tmp.reg

----- BITS: Possible infected sites -----

hxxp://storage
.
((((((((((((((((((((((((( Files Created from 2009-05-10 to 2009-06-10 )))))))))))))))))))))))))))))))
.

2009-06-10 10:43 . 2009-06-10 10:43 -------- d-----w- C:\_OTL
2009-06-10 09:05 . 2009-06-10 09:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\ACT
2009-06-10 09:05 . 2009-06-10 09:05 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2009-06-10 09:05 . 2009-06-10 09:05 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
2009-06-09 15:43 . 2009-06-09 15:43 -------- d-----w- c:\documents and settings\AbdulK\Application Data\Malwarebytes
2009-06-09 15:43 . 2009-06-09 15:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-08 05:24 . 2009-06-08 05:24 -------- d-----w- c:\windows\Sun
2009-06-08 05:24 . 2009-06-08 05:23 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-08 05:23 . 2009-06-08 05:23 152576 ----a-w- c:\documents and settings\AbdulK\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-05 09:35 . 2009-06-05 09:35 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-06-05 09:13 . 2009-06-05 09:18 -------- d-----w- C:\bintheredunthat
2009-06-05 09:00 . 2009-06-05 09:00 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-06-04 20:51 . 2008-02-19 13:10 81920 ----a-w- C:\BFU.exe
2009-06-04 09:20 . 2009-06-04 09:20 388000 ----a-w- c:\windows\system32\drivers\timntr.sys
2009-06-04 09:20 . 2009-06-04 09:20 32288 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2009-06-04 09:20 . 2009-06-04 09:20 99776 ----a-w- c:\windows\system32\drivers\snapman.sys
2009-06-04 09:20 . 2009-06-04 09:20 -------- d-----w- c:\program files\Acronis
2009-06-03 20:46 . 2009-06-03 20:46 -------- d--h--w- c:\windows\PIF
2009-06-03 18:56 . 2009-06-03 18:56 -------- d-----w- c:\windows\system32\wbem\Repository
2009-06-03 18:26 . 2009-06-04 09:20 -------- d-----w- c:\program files\Common Files\Acronis
2009-06-02 08:44 . 2009-06-03 18:56 -------- d-----w- c:\documents and settings\AsmothU
2009-06-02 08:31 . 2009-06-03 18:56 -------- d-----w- c:\documents and settings\SergioC
2009-06-02 07:50 . 2009-06-02 07:50 -------- d-----w- c:\documents and settings\DianeP\Local Settings\Application Data\Microsoft
2009-05-31 09:53 . 2009-05-31 09:53 -------- d-----w- c:\program files\Spb Wallet
2009-05-20 07:54 . 2007-10-23 05:27 110592 ----a-w- c:\documents and settings\AbdulK\Application Data\U3\temp\cleanup.exe
2009-05-20 07:53 . 2008-05-02 06:41 3493888 ---ha-w- c:\documents and settings\AbdulK\Application Data\U3\temp\Launchpad Removal.exe
2009-05-20 07:52 . 2009-05-20 07:53 -------- d-----w- c:\documents and settings\AbdulK\Application Data\U3
2009-05-16 14:16 . 2009-06-10 11:07 -------- d-sh--r- C:\DATA
2009-05-12 08:29 . 2009-05-12 08:29 0 ----a-w- c:\windows\popcreg.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-10 10:47 . 2008-08-29 11:47 2150 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-10 09:15 . 2008-08-29 18:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-10 09:12 . 2008-12-12 09:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-10 09:05 . 2008-08-27 10:32 30296 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-08 05:23 . 2008-09-26 00:14 -------- d-----w- c:\program files\Java
2009-06-05 09:18 . 2008-10-26 11:13 -------- d-----w- c:\program files\Unlocker
2009-06-05 09:18 . 2008-09-26 00:11 -------- d-----w- c:\program files\LimeWire
2009-06-05 09:05 . 2008-08-27 19:02 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-19 18:05 . 2008-08-29 10:58 -------- d-----w- c:\program files\IBS Enterprise Client
2009-05-13 06:05 . 2008-12-01 12:26 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-12 08:29 . 2009-05-07 07:35 -------- d-----w- c:\program files\PopCap Games
2009-05-09 14:43 . 2009-05-09 14:43 -------- d-----w- c:\documents and settings\AbdulK\Application Data\Media Player Classic
2009-05-09 14:32 . 2009-05-09 14:32 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-05-09 13:56 . 2009-05-09 13:56 -------- d-----w- c:\documents and settings\AbdulK\Application Data\River Past G4
2009-05-09 13:56 . 2009-05-09 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\River Past G4
2009-05-09 13:54 . 2009-05-09 13:54 161532 ----a-w- c:\windows\Audio Converter Pro Uninstaller.exe
2009-05-09 13:54 . 2009-05-09 13:54 -------- d-----w- c:\program files\Common Files\River Past
2009-05-09 13:54 . 2009-05-09 13:54 -------- d-----w- c:\program files\River Past
2009-05-07 08:07 . 2009-05-07 07:36 25 ----a-w- c:\windows\popcinfot.dat
2009-05-07 07:35 . 2009-05-07 07:35 -------- d-----w- c:\documents and settings\All Users\Application Data\PopCap Games
2009-05-03 11:44 . 2009-05-03 11:44 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-05-03 11:43 . 2008-09-26 12:59 -------- d-----w- c:\program files\MSECache
2009-04-28 14:15 . 2009-04-28 14:15 -------- d-----w- c:\program files\Common Files\RDPrint
2009-04-28 14:14 . 2009-04-28 14:15 2255 ----a-w- c:\windows\PmData.Dat
2009-04-28 14:14 . 2009-04-28 14:14 -------- d-----w- c:\program files\RDS
2009-04-28 10:20 . 2009-04-28 10:17 -------- d-----w- c:\documents and settings\AbdulK\Application Data\Digsby
2009-04-28 10:16 . 2009-04-28 10:16 -------- d-----w- c:\program files\Digsby
2009-04-26 04:57 . 2008-08-27 15:29 30296 ----a-w- c:\documents and settings\AbdulK\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-25 10:34 . 2009-04-25 10:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-04-09 09:29 . 2009-04-09 09:29 36864 ----a-w- c:\documents and settings\AbdulK\Application Data\Autodesk\DWG TrueView 2010\R7\enu\ContextualTabSelectorRules.dll
2009-04-07 09:18 . 2009-04-07 09:18 18724 ----a-w- c:\windows\unins000.dat
2009-04-07 09:18 . 2009-04-07 09:18 667978 ----a-w- c:\windows\unins000.exe
2009-04-02 13:21 . 2009-05-09 14:32 84480 ----a-w- c:\windows\system32\ff_vfw.dll
2008-08-29 11:47 . 2008-08-29 11:47 56 --sh--r- c:\windows\system32\057CB5E5FF.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-10 36864]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-10 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-10 81920]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2008-02-22 1245184]
"Act! Preloader"="c:\program files\ACT\ACT for Windows\Act8.exe" [2006-04-05 1015808]
"NcpBudget"="c:\program files\WatchGuard\Mobile VPN\ncpbudgt.exe" [2008-01-17 401920]
"NcpPopup"="c:\program files\WatchGuard\Mobile VPN\ncppopup.exe" [2007-11-07 535040]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework360\Common Framework\udaterui.exe" [2008-11-10 136512]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-12-12 30192]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-10-06 111952]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"JobHisInit"="c:\program files\RDS\RMClient\JobHisInit.exe" [2007-08-30 229481]
"MplSetUp"="c:\program files\RDS\RMClient\MplSetUp.exe" [2007-08-30 49254]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-08 148888]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2004-06-08 29696]

c:\documents and settings\lisao\Start Menu\Programs\Startup\
uninstall.exe [2009-6-2 581632]

c:\documents and settings\administrator.MAYFLEX\Start Menu\Programs\Startup\
uninstall.exe [2009-6-2 581632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=c:\windows\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Common Framework360\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\InternetCalls.com\\InternetCalls\\InternetCalls.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\12Voip.com\\12Voip\\12Voip.exe"=
"c:\\Program Files\\Acoustica CD Label Maker\\cdlabel.exe"=
"c:\\Program Files\\WatchGuard\\WatchGuard Mobile VPN with SSL\\wgsslvpnc.exe"=
"c:\\Program Files\\FreeCall.com\\FreeCall\\FreeCall.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R2 MSSQL$ACT7;MSSQL$ACT7;c:\program files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe -sACT7 --> c:\program files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe -sACT7 [?]
R2 ncpclcfg;ncpclcfg;c:\program files\WatchGuard\Mobile VPN\ncpclcfg.exe [29-08-2008 04:27 PM 81920]
R2 ncprwsnt;ncprwsnt;c:\program files\WatchGuard\Mobile VPN\NCPRWSNT.EXE [29-08-2008 04:27 PM 1036296]
R2 NcpSec;NcpSec;c:\program files\WatchGuard\Mobile VPN\NCPSEC.EXE [29-08-2008 04:27 PM 45056]
R2 rwsrsu;RwsRsu;c:\program files\WatchGuard\Mobile VPN\rwsrsu.exe [29-08-2008 04:27 PM 266240]
R3 NcpFiltMP;NcpFiltMP;c:\windows\system32\drivers\ncpvaxp.sys [29-08-2008 04:27 PM 80040]
R3 OEM02Afx;Provides a software interface to control audio effects of OEM002 camera.;c:\windows\system32\drivers\OEM02Afx.sys [27-08-2008 11:05 PM 141376]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [27-08-2008 11:05 PM 235520]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [27-08-2008 11:05 PM 7424]
R3 tap0901;TAP-Win32 Adapter V9;c:\windows\system32\drivers\tap0901.sys [29-08-2008 03:04 PM 25344]
S2 ACT! Scheduler;ACT! Scheduler;c:\program files\ACT\ACT for Windows\Act.Scheduler.exe [29-08-2008 03:12 PM 53248]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12-12-2008 04:13 AM 30192]
S3 NcpFilt;Ncp Filter Service;c:\windows\system32\drivers\ncpvaxp.sys [29-08-2008 04:27 PM 80040]
S3 ncpvaxp;NCP Secure Client Virtual Adapter Driver;c:\windows\system32\drivers\ncpvaxp.sys [29-08-2008 04:27 PM 80040]
S3 SQLAgent$ACT7;SQLAgent$ACT7;c:\program files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlagent.EXE -i ACT7 --> c:\program files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlagent.EXE -i ACT7 [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6cd2d43-4506-11de-b610-001c2385bab9}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-10 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 13:04]

2009-06-10 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 13:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ae/
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-10 15:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(372)
c:\windows\system32\relog_ap.dll

- - - - - - - > 'explorer.exe'(1744)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee\Common Framework360\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\McAfee\Common Framework360\Common Framework\naPrdMgr.exe
c:\program files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\RealVNC\VNC4\winvnc4.exe
c:\windows\system32\scardsvr.exe
c:\windows\system32\rundll32.exe
c:\program files\McAfee\Common Framework360\Common Framework\McTray.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Completion time: 2009-06-10 15:21 - machine was rebooted [AbdulK]
ComboFix-quarantined-files.txt 2009-06-10 11:21

Pre-Run: 3,581,788,160 bytes free
Post-Run: 3,412,848,640 bytes free

241 --- E O F --- 2009-04-29 06:17


Waiting to hear from you, and thanks a ton again!
Abs81

#9 pauline addis

  • Group: Visiting Consultant
  • Posts: 777
  • Joined: 06-September 08

Posted 10 June 2009 - 08:54 AM

Hello Abs81,

How is running your computer, do you still get the message at startup?


Please download Malwarebytes' Anti-Malware.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Complete Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


Then, please do an online scan with Kaspersky WebScanner

Click on Accept

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT

  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      Extended (if available otherwise Standard)
    • Scan Options:
      Scan Archives
      Scan Mail Bases

  • Click OK
  • Now under select a target to scan:
      Select My Computer

  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:

  • Save the file to your desktop.
  • Copy and paste that information in your next post.


#10 abs81

  • Group: Member
  • Posts: 13
  • Joined: 05-June 09

Posted 10 June 2009 - 12:09 PM

Hi Pauline,

Apologies for the late reply but the scans took up a lot of time!

The pop-ups have disappeared, as well as the 'windows explorer needs to close pop-up' on startup, we are well on the way to recovery!

One thing i did notice is that it took a long time to boot up, is that normal with the new apps that i downloaded for cleanup?

Please find the logs as shown :

The MBAM log :

Malwarebytes' Anti-Malware 1.37
Database version: 2258
Windows 5.1.2600 Service Pack 3

10-06-2009 07:50:25 PM
mbam-log-2009-06-10 (19-50-25).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 205327
Time elapsed: 34 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\2052 (Malware.Trace) -> Quarantined and deleted successfully.

Files Infected:
(No malicious items detected)

The Kaspersky log :

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, June 10, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, June 10, 2009 17:42:59
Records in database: 2334930
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
F:\
I:\
S:\
Y:\

Scan statistics:
Files scanned: 61895
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 01:03:46


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\RECYCLE\D-0-060-0000000000-1111111-2222222\FiX.exe.vir Infected: Trojan.Win32.VB.jid 1

The selected area was scanned.


Also I tried to download the Flash disinfector on my personal pc, and the Norton Antivirus on my personal PC flagged the setup file as a Trojan and deleted it, should i diable the AV and then download and run the file?

Many thanks again,

Waiting to hear from you,

Abs81

#11 pauline addis

  • Group: Visiting Consultant
  • Posts: 777
  • Joined: 06-September 08

Posted 10 June 2009 - 01:13 PM

Double post

#12 pauline addis

  • Group: Visiting Consultant
  • Posts: 777
  • Joined: 06-September 08

Posted 10 June 2009 - 01:22 PM

Hello Abs81,

Quote

pop-ups have disappeared, as well as the 'windows explorer needs to close pop-up' on startup, we are well on the way to recovery!

Good news :)

Quote

One thing i did notice is that it took a long time to boot up, is that normal with the new apps that i downloaded for cleanup?

Is it longer at each boot up or was it just after the running of one tool?

Do you have any other symptom?


Instead of Flash Disinfector, let's use UsbFix (sorry, it's in french :))

Please download UsbFix by Chiquitine29, C_XX & Chimay8 to your desktop
  • Double-click UsbFix.exe to install it
    • A window "Installation de UsbFix" will appear, click Suivant
    • Next Window (Licence), check "Je suis d'accord avec les termes et conditions ci-dessus" and click Suivant
    • Next window (Répertoire), click Suivant
      A window will popup, click Oui
    • Next window (Confirmation), click Démarrer
    • And last window (Fin), click Quitter

  • Plug all your external drives and USB keys
  • Double-click the UsbFix V3.xxx on your desktop to launch the application
  • Type 1, and press ENTER
    If a message popup, click Ok
  • Once the scan is done, the report will popup. Please post back its content C:\UsbFix.txt in your next reply


#13 abs81

  • Group: Member
  • Posts: 13
  • Joined: 05-June 09

Posted 10 June 2009 - 01:45 PM

Hi Pauline,

When i booted up my laptop when i got home, i noticed that it took a little while longer to boot up than usual. After reading your post, i rebooted again to check, and sure enough it did take a little while longer to boot. No other symptoms though.Everything is working just fine.

Please find attached the logs. I ran the application individually with each USB drive, I hope thats ok.

USB Drive 1 log :


############################## [ UsbFix V3.029 | Scan ]

# User : AbdulK () # USER-19EE27C6D1
# Update on 05/06/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-or...ols/usbfix.html
# Start at: 11:28:32 PM | 10-06-2009

# Intel® Core™2 Duo CPU T7300 @ 2.00GHz
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# AV : VirusScan Enterprise + AntiSpyware Enterprise 8.5.0.781 [ Enabled | Updated ]

# C:\ # Local Fixed Disk # 24.41 Go (3.05 Go free) # NTFS
# D:\ # Local Fixed Disk # 84.87 Go (80.04 Go free) # NTFS
# E:\ # Local Fixed Disk # 93.16 Go (92.98 Go free) [Abs 100GB] # NTFS
# F:\ # CD-ROM Disc
# I:\ # Network Connection
# S:\ # Network Connection
# Y:\ # Network Connection

############################## [ Processus actifs ]

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\naPrdMgr.exe
C:\Program Files\WatchGuard\Mobile VPN\ncpclcfg.exe
C:\Program Files\WatchGuard\Mobile VPN\ncprwsnt.exe
C:\Program Files\WatchGuard\Mobile VPN\ncpsec.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\WatchGuard\Mobile VPN\rwsrsu.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\OEM02Mon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ACT\ACT for Windows\Act8.exe
C:\Program Files\WatchGuard\Mobile VPN\ncpbudgt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\udaterui.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\McTray.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\McScript_InUse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## [ Registre Startup ]

HKCU_Main: "Local Page"="C:\\windows\\system32\\blank.htm"
HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
HKCU_Main: "Start Page"="http://www.google.ae/"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="abdulk"
HKLM_logon: "AltDefaultUserName"="abdulk"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: SigmatelSysTrayApp=%ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
HKLM_Run: OEM02Mon.exe=C:\WINDOWS\OEM02Mon.exe
HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM_Run: Dell QuickSet=C:\Program Files\Dell\QuickSet\quickset.exe
HKLM_Run: Act! Preloader="C:\Program Files\ACT\ACT for Windows\Act8.exe" -stayrunning
HKLM_Run: NcpBudget="C:\Program Files\WatchGuard\Mobile VPN\ncpbudgt.exe"
HKLM_Run: NcpPopup="C:\Program Files\WatchGuard\Mobile VPN\ncppopup.exe" noerrmsg
HKLM_Run: McAfeeUpdaterUI="C:\Program Files\McAfee\Common Framework360\Common Framework\udaterui.exe" /StartedFromRunKey
HKLM_Run: HP Software Update=D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
HKLM_Run: Logitech Hardware Abstraction Layer=KHALMNPR.EXE
HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
HKLM_Run: Google Desktop Search="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
HKLM_Run: ShStatEXE="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
HKLM_Run: Synchronization Manager=%SystemRoot%\system32\mobsync.exe /logon
HKLM_Run: JobHisInit=C:\Program Files\RDS\RMClient\JobHisInit.exe
HKLM_Run: MplSetUp=C:\Program Files\RDS\RMClient\MplSetUp.exe
HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
HKCU_Run: H/PC Connection Agent="C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

################## [ Fichiers # Dossiers infectieux ]


################## [ Registre # Clés Run infectieuses ]


################## [ Registre # Mountpoints2 ]

HKCU\...\Explorer\MountPoints2\{74ded809-8b44-11dd-b4b1-001c26f3d4b9}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{c6cd2d43-4506-11de-b610-001c2385bab9}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{d2207c90-cec0-11dd-b536-001c26f3d4b9}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{e573b301-2aac-11de-b5d5-001c2385bab9}\Shell\AutoRun\Command

################## [ ! Fin du rapport # UsbFix V3.029 ! ]


USB drive 2 Log :


############################## [ UsbFix V3.029 | Scan ]

# User : AbdulK () # USER-19EE27C6D1
# Update on 05/06/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-or...ols/usbfix.html
# Start at: 11:31:26 PM | 10-06-2009

# Intel® Core™2 Duo CPU T7300 @ 2.00GHz
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# AV : VirusScan Enterprise + AntiSpyware Enterprise 8.5.0.781 [ Enabled | Updated ]

# C:\ # Local Fixed Disk # 24.41 Go (3.05 Go free) # NTFS
# D:\ # Local Fixed Disk # 84.87 Go (80.04 Go free) # NTFS
# E:\ # Local Fixed Disk # 465.64 Go (281.9 Go free) [ABS 500GB] # FAT32
# F:\ # CD-ROM Disc
# I:\ # Network Connection
# S:\ # Network Connection
# Y:\ # Network Connection

############################## [ Processus actifs ]

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\naPrdMgr.exe
C:\Program Files\WatchGuard\Mobile VPN\ncpclcfg.exe
C:\Program Files\WatchGuard\Mobile VPN\ncprwsnt.exe
C:\Program Files\WatchGuard\Mobile VPN\ncpsec.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\WatchGuard\Mobile VPN\rwsrsu.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\OEM02Mon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ACT\ACT for Windows\Act8.exe
C:\Program Files\WatchGuard\Mobile VPN\ncpbudgt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\udaterui.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\McTray.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\McAfee\Common Framework360\Common Framework\McScript_InUse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## [ Registre Startup ]

HKCU_Main: "Local Page"="C:\\windows\\system32\\blank.htm"
HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
HKCU_Main: "Start Page"="http://www.google.ae/"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="abdulk"
HKLM_logon: "AltDefaultUserName"="abdulk"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: SigmatelSysTrayApp=%ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
HKLM_Run: OEM02Mon.exe=C:\WINDOWS\OEM02Mon.exe
HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM_Run: Dell QuickSet=C:\Program Files\Dell\QuickSet\quickset.exe
HKLM_Run: Act! Preloader="C:\Program Files\ACT\ACT for Windows\Act8.exe" -stayrunning
HKLM_Run: NcpBudget="C:\Program Files\WatchGuard\Mobile VPN\ncpbudgt.exe"
HKLM_Run: NcpPopup="C:\Program Files\WatchGuard\Mobile VPN\ncppopup.exe" noerrmsg
HKLM_Run: McAfeeUpdaterUI="C:\Program Files\McAfee\Common Framework360\Common Framework\udaterui.exe" /StartedFromRunKey
HKLM_Run: HP Software Update=D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
HKLM_Run: Logitech Hardware Abstraction Layer=KHALMNPR.EXE
HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
HKLM_Run: Google Desktop Search="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
HKLM_Run: ShStatEXE="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
HKLM_Run: Synchronization Manager=%SystemRoot%\system32\mobsync.exe /logon
HKLM_Run: JobHisInit=C:\Program Files\RDS\RMClient\JobHisInit.exe
HKLM_Run: MplSetUp=C:\Program Files\RDS\RMClient\MplSetUp.exe
HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
HKCU_Run: H/PC Connection Agent="C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

################## [ Fichiers # Dossiers infectieux ]


################## [ Registre # Clés Run infectieuses ]


################## [ Registre # Mountpoints2 ]

HKCU\...\Explorer\MountPoints2\{74ded809-8b44-11dd-b4b1-001c26f3d4b9}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{c6cd2d43-4506-11de-b610-001c2385bab9}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{d2207c90-cec0-11dd-b536-001c26f3d4b9}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{e573b301-2aac-11de-b5d5-001c2385bab9}\Shell\AutoRun\Command

################## [ ! Fin du rapport # UsbFix V3.029 ! ]


Waiting to hear from you,

Thanks!
Abs81.

#14 pauline addis

  • Group: Visiting Consultant
  • Posts: 777
  • Joined: 06-September 08

Posted 11 June 2009 - 01:28 AM

Hello Abs81,

Your drives are ok and your system is clean :)
I'm not sure what makes your startup longer than before. If you need any advice to optimize your system, you can create a new topic in the Windows part of the forum.

Below are some advices to protect your system from a future infection. For your work laptop, please skip the MVPS Hosts file part, as your hosts file is setup to allow you connecting on your company private network. I let this part as it can be useful for your personal laptop.

  • Plug all your external drives and USB keys
  • Double-click the UsbFix V3.xxx on your desktop to launch the application
  • Type 3, and press ENTER
  • Once done, a report will popup to confirm that a safe autorun folder had been created on each drives to protect them from future autorun infection:
    # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
    # D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
  • Close the report



Now, in order to finalize the cleaning process, here some few steps to follow

First, Some housekeeping :) Remove Combofix and all the tools that you have used This is so that should you ever be re-infected, you will download updated versions. It will also remove the quarantined Malware from your computer.
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there
    Posted Image


  • Download OTC by Old Timer to your desktop
  • Double-click OTC.exe to run it
  • Click Yes to begin the Cleanup process and remove these components, including this application
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes


  • Double-click the UsbFix V3.xxx on your desktop to launch the application
  • Type 5, and press ENTER
  • A window will popup, to confirm the removal of UsbFix, click Ok
  • Once done, a window will popup, saying that UsbFix had been uninstalled successfully, click Ok
Now delete any logs that you have left over on your desktop


Second, To help you prevent from a future infection, I recommend you to keep Windows, Java and Adobe Reader updated

Visit the Microsoft Windows Update website to download the latest security updates and Service Pack.
You can keep your computer update while turning on the automatic updates (Start > Control Panel > Automatic Updates).

There are certain programs that are security vulnerabilities, it is recommended that you keep everything updated. Two of the main vulnerabilities are Java and Adobe Reader.

Install JavaRa a simple tool that does a simple job: it removes old and redundant versions of the Java Runtime Environment (JRE). And it removes some log files and temporary files that JRE leaves behind.

Visit the Adobe Reader Update page to download the latest version.

In addition, you can also use FileHippo Update Checker, an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.


To have installed on your computer these protection programs

One Antivirus to protect your system from most infections - If you do not already have one, install Anti-Vir or AVG Anti-Virus (good and free)

SpywareGuard - works as a Spyware "Shield" to protect your computer from getting malware in the first place
A tutorial can be found here

Malware Byte's Anti Malware - excellent tool for anyone's antimalware arsenal.

And for a safe surf on Internet

One Firewall to help to prevent unauthorized access both to and from the internet or your local network. A firewall is considered a first line of defense in protecting private information. If you do not already have one, install Sunbelt Personal Firewall or Online Armor (good and free). See Understanding and Using Firewalls for more information

SpywareBlaster - protects against bad ActiveX, great prevention tool to keep nasties from installing on your system
A tutorial can be found here

MVPS Hosts file - replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

FireFox - an alternate free web browser more secure than Internet Explorer
NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

To be able to catch the new malware variants that may come out, all the protection programs, must be updated regularly and a scan of your system must be launch every week!


You can also have

ATF Cleaner by Atribune - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


And to finish, some readings :)

If you want to understand better how you got infected, read this topic How did I get infected in the first place?

#15 abs81

  • Group: Member
  • Posts: 13
  • Joined: 05-June 09

Posted 11 June 2009 - 02:12 AM

Hi Pauline,

Many thanks for your help, you are a Star! :) It says that you are from Addis, I do alot of business in Ethiopia, and have beent there twice last year, Addis is a lovely city!

I am at work at the moment, do not have my USB drives with me, will get home in the evening, will follow your recommendations exactly, and then will let you know if my boot up is back to normal. Also will close this topic if required, after alot of flowery thank yous of course!

Will post again in the evening.
Thanks again!
Regards,
Abs81

Share this topic:


  • 2 Pages +
  • 1
  • 2