Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bkdr_delf Malware


  • This topic is locked This topic is locked
12 replies to this topic

#1 pmcilnay

pmcilnay

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:44 PM

Posted 02 October 2008 - 09:33 AM

I've searched posts and done the steps, but I don't understand what I'm looking at. Please help. I've included Hijack log, I also have a HaxFix log available.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:25:10 AM, on 10/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Frontier Connect\VPN Client\cvpnd.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\i2050QosSvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\TEMP\ETE9F8.EXE
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\dsltech\My Documents\Downloads\haxfix.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dogpile.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://home.fcinternal.net/fc/default.asp?ID=2
O2 - BHO: {3ef63436-e5e5-4998-a624-31254cefc121} - {121cfec4-5213-426a-8994-5e5e63436fe3} - C:\WINDOWS\system32\ejiind.dll
O2 - BHO: (no name) - {453F51E8-FEF5-4C54-B136-944BF434360C} - C:\WINDOWS\system32\ljJDUlLC.dll (file missing)
O2 - BHO: OIN Analytics - {6B221E01-F517-4959-8C41-81948E7F2F17} - C:\Program Files\OINAnalytics\OINAnalytics.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {96D1619A-9E8C-4C8A-9094-6CF4BDB4960D} - C:\WINDOWS\system32\iifFYrpn.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [BMc371be7a] Rundll32.exe "C:\WINDOWS\system32\kviuisou.dll",s
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
O4 - Global Startup: Mail.lnk = C:\profgen\mail.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1209132789957
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.cbsgames.com/games/play/zuma/popcaploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corp.pvt
O17 - HKLM\Software\..\Telephony: DomainName = corp.pvt
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corp.pvt
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = corp.pvt
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: viryanet - {CBC37B4C-A4A3-11D6-AA2F-000255F45826} - C:\PROGRA~1\Viryanet\MICROS~1\ViryaNetHttp.dll
O20 - AppInit_DLLs: ,avgrsstx.dll ejiind.dll
O20 - Winlogon Notify: ljJDUlLC - ljJDUlLC.dll (file missing)
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Frontier Connect\VPN Client\cvpnd.exe
O23 - Service: iSeries Access for Windows Remote Command (Cwbrxd) - IBM Corporation - C:\WINDOWS\CWBRXD.EXE
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nortel Networks i2050 QoS Service (i2050QoSSvc) - Nortel Networks Corp. - C:\WINDOWS\system32\i2050QosSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe

--
End of file - 8296 bytes

BC AdBot (Login to Remove)

 


m

#2 pmcilnay

pmcilnay
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:44 PM

Posted 02 October 2008 - 01:14 PM

HaxFix log:
HAXFIX logfile - by Marckie

version 5.021
Thu 10/02/2008 9:04:20.95
running from C:\HaxFix

--- Checking for Haxdoor ---

checking for a3d files
a3d files not found

checking for matching notify keys
no matching notify keys found

checking for matching services
matching services found
CmBatt

checking for matching safeboot services
no matching safeboot services found


--- Checking for Goldun ---

checking for SSODL keys
no ssodl keys found

checking for notify keys
no notify keys found

checking for services
no services found

checking for browser helper objects
no known browser helper objects found

checking for appinit files
no files found

checking for possible infected files
please submit these file here: http://www.bleepingcomputer.com/submit-mal....php?channel=11
[C:\WINDOWS\system32\SMSUnins.dll] AC819EB997E6AB5A7D0BD6F1C8E36431

checking iexplore.exe
iexplore.exe is not infected


--- Checking for other Goldun and Haxdoor files ---
no other Haxdoor or Goldun files found


--- Catchme logfile - thank you Gmer ---

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-02 09:04:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


--- Analysing Catchme logfile ---

no matching regkeys found


Finished!

#3 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:44 PM

Posted 07 October 2008 - 09:11 PM

Hello, pmcilnay.
HaxFix is a tool that deals with a specific infection; it shouldn't be run unless you are infected with a Haxdoor variant or Goldun rookit variants. You don't have these so it is unlikely that this will fix your issue :)

:thumbsup: to BleepingComputer.com

My name is Billy O'Neal and I will be helping you. (Billy or Bill is fine, if you like.)

I want to apologise that it has taken so long to get back to you. We on the HJT Team are working as fast as possible to get your log answered.

If you do not still need help, please let me know, so that I can move on to other users who still need help.

Please take note of the following:
  • While a HJT Team member is working with you, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. :)
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Please reply using the Posted Image button in the lower left hand corner of your screen.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave, and if there is no contact for that amount of time I will have to assume you have "vanished" :).
If you would still like help, please follow the instructions below:

We need to create an OTViewIt Report
  • Please download OTViewIt by OldTimer.
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
  • OTViewIt.txt <-- Will be opened
  • Extra.txt <-- Will be minimized
Please do an online scan with Kaspersky WebScanner.
  • Please visit the Kaspersky Online Scanner website.
    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
In your next reply, please include the following:
  • OTViewIt.txt
  • Extra.txt
  • Kaspersky's Log


Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#4 pmcilnay

pmcilnay
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:44 PM

Posted 08 October 2008 - 11:49 AM

Thanks Bill, I do need help. Here are the results as requested.

OTViewIt logfile created on: 10/8/2008 7:49:48 AM - Run
OTViewIt by OldTimer - Version 1.0.10.1 Folder = C:\Documents and Settings\dsltech\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.36 Mb Total Physical Memory | 97.00 Mb Available Physical Memory | 19.27% Memory free
1.20 Gb Paging File | 0.85 Gb Available in Paging File | 70.86% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 28.40 Gb Free Space | 76.24% Space Free | Partition Type: NTFS
Drive D: | 403.20 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NEKE00LXP042796
Current User Name: dsltech
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2006/02/28 13:16:08 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
[2006/02/28 13:18:10 | 00,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
[2008/09/27 14:19:58 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
[2005/04/07 15:26:10 | 01,421,336 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Frontier Connect\VPN Client\cvpnd.exe
[2008/05/30 12:16:38 | 00,137,200 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[2004/03/19 14:15:10 | 00,081,920 | ---- | M] (Nortel Networks Corp.) -- C:\WINDOWS\system32\i2050QosSvc.exe
[2005/11/17 19:38:12 | 00,491,520 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe
[2006/02/28 13:15:30 | 00,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
[2002/09/20 13:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
[2005/11/17 19:38:04 | 00,606,296 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe
[2005/01/28 12:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe
[2005/11/17 19:46:36 | 00,229,456 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
[2008/09/27 14:20:00 | 00,287,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
[2005/11/17 19:46:24 | 00,172,099 | ---- | M] () -- C:\WINDOWS\Temp\RZE59C.EXE
[2005/09/08 17:59:22 | 00,024,848 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\ssonsvr.exe
[2004/11/04 17:40:08 | 00,098,394 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[2004/11/04 17:38:54 | 00,688,218 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[2005/04/13 08:12:38 | 00,088,209 | ---- | M] (Agere Systems) -- C:\WINDOWS\AGRSMMSG.exe
[2004/12/21 10:11:32 | 00,126,976 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\hkcmd.exe
[2004/10/14 08:11:10 | 01,388,544 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
[2006/02/28 13:25:20 | 00,667,718 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
[2006/02/28 13:25:48 | 00,602,182 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
[2006/02/28 13:29:54 | 00,569,413 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
[2005/11/17 19:49:30 | 00,335,872 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\PccNTMon.exe
[2007/04/05 15:22:50 | 00,282,624 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\QuickTime\qttask.exe
[2008/09/29 09:33:36 | 01,234,712 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
[2008/09/04 11:31:08 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[2006/02/28 13:22:50 | 00,397,381 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
[2007/09/06 23:13:06 | 02,056,275 | ---- | M] (Cisco Systems, Inc) -- C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
[2008/09/14 05:20:53 | 00,634,368 | ---- | M] (Google Inc.) -- C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
[2008/09/14 05:20:53 | 00,634,368 | ---- | M] (Google Inc.) -- C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
[2008/10/08 07:48:06 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTViewIt.exe

========== (O23) Win32 Services ==========

[2008/09/27 14:19:58 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
[2005/04/07 15:26:10 | 01,421,336 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Frontier Connect\VPN Client\cvpnd.exe -- (CVPND [Auto | Running])
[2002/02/04 05:20:00 | 00,053,296 | ---- | M] (IBM Corporation) -- C:\WINDOWS\cwbrxd.exe -- (Cwbrxd [On_Demand | Stopped])
[2006/02/28 13:16:08 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng [Auto | Running])
[2008/05/30 12:16:38 | 00,137,200 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Auto | Running])
[2004/03/19 14:15:10 | 00,081,920 | ---- | M] (Nortel Networks Corp.) -- C:\WINDOWS\system32\i2050QosSvc.exe -- (i2050QoSSvc [Auto | Running])
[2005/11/17 19:38:12 | 00,491,520 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe -- (ntrtscan [Auto | Running])
[2005/11/17 19:46:36 | 00,229,456 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe -- (OfcPfwSvc [Auto | Running])
[2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2003/11/04 16:10:18 | 00,065,795 | ---- | M] (HP) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZIPM12.EXE -- (Pml Driver HPZ12 [On_Demand | Stopped])
[2006/02/28 13:15:30 | 00,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc [Auto | Running])
[2006/02/28 13:18:10 | 00,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor [Auto | Running])
[2002/09/20 13:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default) [Auto | Running])
[2005/11/17 19:38:04 | 00,606,296 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe -- (tmlisten [Auto | Running])
[2005/01/28 12:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running])

========== Driver Services ==========

[2004/11/08 13:10:36 | 00,127,744 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (aeaudio [On_Demand | Running])
[2006/08/03 07:34:41 | 00,021,275 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP [Auto | Running])
[2005/04/13 08:12:38 | 01,066,278 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem [On_Demand | Running])
[2008/09/27 14:20:33 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (AvgLdx86 [System | Running])
[2008/09/27 14:20:24 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (AvgMfx86 [System | Running])
[2004/11/16 12:46:38 | 00,190,592 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k [On_Demand | Running])
File not found -- C:\DOCUME~1\dsltech\LOCALS~1\Temp\catchme.sys -- (catchme [On_Demand | Stopped])
[2005/02/08 09:27:00 | 00,005,185 | ---- | M] (Cisco Systems, Inc.) -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA [On_Demand | Stopped])
[2005/04/07 15:23:50 | 00,299,083 | ---- | M] (Cisco Systems, Inc.) -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA [Auto | Running])
[2003/07/24 17:55:50 | 00,139,604 | ---- | M] (Deterministic Networks, Inc.) -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE [On_Demand | Running])
[2005/05/31 10:46:26 | 00,087,936 | R--- | M] (Texas Instruments) -- C:\WINDOWS\system32\drivers\gtipci21.sys -- (GTIPCI21 [On_Demand | Running])
[2004/12/21 10:44:18 | 00,776,349 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\ialmnt5.sys -- (ialm [On_Demand | Running])
[2003/02/23 03:05:00 | 00,002,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\idisw2km.sys -- (idisw2km [Disabled | Stopped])
[2003/02/23 03:05:00 | 00,007,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\kbstuff5.sys -- (kbstuff [On_Demand | Running])
[2001/08/23 07:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2001/08/23 07:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\rootmdm.sys -- (ROOTMODEM [On_Demand | Running])
[2006/02/28 14:35:56 | 00,013,568 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans [Auto | Running])
[2004/08/03 23:07:48 | 00,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\sdbus.sys -- (sdbus [On_Demand | Running])
[2007/11/13 05:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2001/08/17 07:10:28 | 00,035,913 | ---- | M] (SMC) -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA [On_Demand | Running])
[2004/10/13 13:25:54 | 00,259,840 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])
[2004/11/04 17:26:42 | 00,186,016 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP [On_Demand | Running])
[2005/06/23 08:16:08 | 00,162,176 | ---- | M] (Texas Instruments) -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21 [On_Demand | Running])
[2008/08/16 03:00:52 | 00,205,328 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys -- (TmFilter [Auto | Running])
[2008/08/16 03:00:46 | 00,036,368 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\tmpreflt.sys -- (TmPreFilter [Auto | Running])
[2004/08/03 23:07:56 | 00,059,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio [On_Demand | Stopped])
[2008/07/23 16:45:58 | 00,022,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbsermpt.sys -- (usbsermpt [On_Demand | Stopped])
[2008/08/16 02:53:50 | 01,195,448 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\vsapiNT.sys -- (VSApiNt [Auto | Running])
[2005/01/26 03:22:20 | 00,280,344 | ---- | M] (Zone Labs LLC) -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant [On_Demand | Running])
[2006/02/09 09:03:18 | 03,298,432 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51 [On_Demand | Running])
[2004/08/03 18:07:42 | 00,008,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wmiacpi.sys -- (WmiAcpi [System | Running])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.dogpile.com/

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-112473\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://home.fcinternal.net/fc/default.asp?ID=2

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-112473\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-112473\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-112473\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-81713\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://home.fcinternal.net/fc/default.asp?ID=2

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-81713\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-81713\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-81713\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-88595\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://home.fcinternal.net/fc/default.asp?ID=2

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-88595\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-88595\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-88595\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.dogpile.com/

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1011\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://home.fcinternal.net/fc/default.asp?ID=2

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1011\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1011\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1011\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{121cfec4-5213-426a-8994-5e5e63436fe3} (HKLM) -- C:\WINDOWS\system32\ejiind.dll ()
{453F51E8-FEF5-4C54-B136-944BF434360C} (HKLM) -- C:\WINDOWS\system32\ljJDUlLC.dll File not found
{6B221E01-F517-4959-8C41-81948E7F2F17} (HKLM) -- C:\Program Files\OINAnalytics\OINAnalytics.dll File not found
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (Sun Microsystems, Inc.)
{96D1619A-9E8C-4C8A-9094-6CF4BDB4960D} (HKLM) -- C:\WINDOWS\system32\iifFYrpn.dll File not found
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (HKLM) -- C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll (Google Inc.)

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"=AGRSMMSG.exe (Agere Systems)
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
"BMc371be7a"=Rundll32.exe "C:\WINDOWS\system32\kviuisou.dll",s File not found
"Client Access Check Version"="C:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN (IBM Corporation)
"Client Access Express Welcome"="C:\Program Files\IBM\Client Access\cwbwlwiz.exe" (IBM Corporation)
"Client Access Help Update"="C:\Program Files\IBM\Client Access\cwbinhlp.exe" (IBM Corporation)
"Client Access Service"="C:\Program Files\IBM\Client Access\cwbsvstr.exe" (IBM Corporation)
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" (Intel Corporation)
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless (Intel Corporation)
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" (Intel Corporation)
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe" -HideWindow (Trend Micro Inc.)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray (Analog Devices, Inc.)
"SoundMAXPnP"=C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
"WatchDog"=C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)

========== (O4) Startup Folders ==========

[2007/09/06 23:13:06 | 02,056,275 | ---- | M] (Cisco Systems, Inc) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
[2006/04/18 05:33:04 | 00,163,597 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Mail.lnk = C:\profgen\mail.EXE

========== (O6 & O7) Current Version Policies ==========

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-112473\Software\policies\microsoft\internet explorer\Restrictions]
"NoExternalBranding"=1

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-81713\Software\policies\microsoft\internet explorer\Restrictions]
"NoExternalBranding"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoWelcomeScreen"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=1
"legalnoticecaption"=Legal Notice
"legalnoticetext"=This computer system and the data contained herein are property of Frontier Communications. Any unauthorized access and/or use of the data will be investigated and prosecuted to the full extent of the law. This system is to be used for business purposes. All information stored or processed is property of Frontier Communications and is subject to inspection.
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-112473\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"ForceStartMenuLogOff"=1
"NoWelcomeScreen"=1

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-81713\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"ForceStartMenuLogOff"=1
"NoWelcomeScreen"=1

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-88595\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1011\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.5.0_10\bin\NPJPI150_10.dll [2006/11/09 15:21:53 | 00,075,528 | ---- | M] (Sun Microsystems, Inc.)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-112473\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-81713\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-88595\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1011\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-112473\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
czn.com: http in Local intranet
czncorp.com: http in Local intranet
fcinternal.net: http in Local intranet
frontiercorp.com: http in Local intranet
4 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_USERS\S-1-5-21-329068152-838170752-682003330-81713\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
czn.com: http in Local intranet
czncorp.com: http in Local intranet
fcinternal.net: http in Local intranet
frontiercorp.com: http in Local intranet
4 domain(s) and sub-domain(s) not assigned to a zone.

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}: http://www.apple.com/qtactivex/qtplugin.cab -- QuickTime Object
{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}: http://download.microsoft.com/download/0/f...tualEarth3D.cab -- Reg Error: Key does not exist or could not be opened.
{6414512B-B978-451D-A0D8-FCFDF33E833C}: http://www.update.microsoft.com/windowsupd...b?1209132789957 -- WUWebControl Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_10
{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}: http://java.sun.com/products/plugin/1.4/ji...indows-i586.cab -- Java Plug-in 1.4.1_02
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_06
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_10
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_10
{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}: http://www.cbsgames.com/games/play/zuma/popcaploader_v10.cab -- PopCapLoader Object
Microsoft XML Parser for Java: file://C:\WINDOWS\Java\classes\xmldso.cab -- Reg Error: Key does not exist or could not be opened.

========== (O17) DNS Name Servers ==========

{33457D43-9EF7-485B-9A14-8A1F734CB7E8} (Servers: | Description: )
{72D8AC0E-79E3-42B5-8E65-E7394C07903B} (Servers: | Description: Intel® PRO/Wireless 2200BG Network Connection)
{DE965516-35EB-464D-B0AB-3FCA64D7D910} (Servers: | Description: Broadcom NetXtreme Gigabit Ethernet)

========== (O20) AppInit_DLLs ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls"=,avgrsstx.dll ejiind.dll
>File not found --
>File not found --

========== (O20) Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
igfxcui: "DllName" = igfxsrvc.dll -- C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
ljJDUlLC: "DllName" = ljJDUlLC.dll -- File not found

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{453F51E8-FEF5-4C54-B136-944BF434360C}" (HKLM) -- C:\WINDOWS\system32\ljJDUlLC.dll File not found

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=msv1_0,C:\WINDOWS\system32\iifFYrpn,
>File not found --

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
[2006/06/27 12:43:49 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]


========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e7a7dcbe-7420-11db-84e0-001560c9c5f6}\Shell\AutoRun\command]
""=JDSecure\Windows\JDSecure31.exe

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[2008/10/08 07:48:05 | 00,421,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTViewIt.exe
[2008/10/02 16:52:31 | 00,015,872 | ---- | C] () -- C:\Documents and Settings\dsltech\My Documents\PraMac.xls
[2008/10/02 14:12:18 | 00,001,910 | ---- | C] () -- C:\Documents and Settings\dsltech\Desktop\Business Element Manager.lnk
[2008/10/02 13:08:13 | 12,302,6196 | ---- | C] (Macrovision) -- C:\Documents and Settings\dsltech\My Documents\BCMElementMgrInstaller.exe
[2008/10/02 09:24:41 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\dsltech\Desktop\HijackThis.lnk
[2008/10/02 09:04:01 | 00,484,958 | ---- | C] (Marckie ) -- C:\HaxFix.exe
[2008/10/02 09:03:58 | 00,000,000 | ---D | C] -- C:\HaxFix
[2008/09/30 14:13:57 | 00,947,237 | -HS- | C] () -- C:\WINDOWS\System32\dlhcpplg.ini
[2008/09/30 14:10:54 | 00,124,030 | ---- | C] () -- C:\WINDOWS\System32\TmEncryptTemp.000
[2008/09/30 14:10:54 | 00,123,904 | ---- | C] () -- C:\WINDOWS\System32\ejiind.dll
[2008/09/29 13:09:22 | 00,990,996 | -HS- | C] () -- C:\WINDOWS\System32\bkinajco.ini
[2008/09/28 13:14:27 | 00,000,000 | ---D | C] -- C:\Program Files\Twain
[2008/09/28 13:09:28 | 00,000,000 | ---D | C] -- C:\Program Files\Webtools
[2008/09/28 13:06:54 | 00,990,996 | -HS- | C] () -- C:\WINDOWS\System32\pxscgljs.ini
[2008/09/28 13:04:36 | 00,000,000 | ---D | C] -- C:\Program Files\Mjcore
[2008/09/27 15:48:27 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2008/09/27 14:20:38 | 00,001,507 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2008/09/27 14:20:37 | 00,010,520 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2008/09/27 14:20:33 | 00,097,928 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2008/09/27 14:20:24 | 00,026,824 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2008/09/27 14:20:17 | 28,348,635 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2008/09/27 14:20:17 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2008/09/27 14:20:17 | 00,249,919 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/09/27 14:20:17 | 00,068,419 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2008/09/27 14:20:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2008/09/27 14:19:57 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2008/09/27 14:19:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2008/09/27 13:08:23 | 00,986,883 | -HS- | C] () -- C:\WINDOWS\System32\ndpenmfr.ini
[2008/09/27 13:03:58 | 00,112,955 | ---- | C] () -- C:\WINDOWS\BMc371be7a.xml
[2008/09/27 13:03:58 | 00,000,022 | ---- | C] () -- C:\WINDOWS\pskt.ini
[2008/09/27 13:01:53 | 00,000,000 | ---D | C] -- C:\Program Files\VnrBlock
[2008/09/27 12:59:14 | 00,882,302 | -HS- | C] () -- C:\WINDOWS\System32\nprYFfii.ini2
[2008/09/27 12:59:07 | 00,882,302 | -HS- | C] () -- C:\WINDOWS\System32\nprYFfii.ini
[2008/09/27 12:54:47 | 00,041,724 | -HS- | C] () -- C:\Program Files\Common Files\Yazzle1554OinUninstaller.exe
[2008/09/27 12:54:39 | 00,000,000 | ---D | C] -- C:\Program Files\sуstem32
** - C:\Program Files\s?stem32
[2008/09/27 12:53:46 | 00,000,000 | ---D | C] -- C:\Program Files\OINAnalytics
[2008/09/25 15:47:45 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbprint.sys
[2008/09/25 15:47:45 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbprint.sys
[2008/09/10 14:34:14 | 00,013,824 | ---- | C] () -- C:\Documents and Settings\dsltech\My Documents\supplyrequest.xls

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2008/10/08 07:48:06 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTViewIt.exe
[2008/10/07 20:17:21 | 28,348,635 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2008/10/07 16:40:07 | 00,359,948 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2008/10/07 16:40:07 | 00,315,076 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2008/10/07 16:40:07 | 00,041,238 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2008/10/07 16:37:01 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008/10/07 16:35:54 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/10/07 16:35:50 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008/10/07 12:58:03 | 02,814,422 | -H-- | M] () -- C:\Documents and Settings\dsltech\Local Settings\Application Data\IconCache.db
[2008/10/05 08:59:24 | 00,068,419 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2008/10/02 16:52:31 | 00,015,872 | ---- | M] () -- C:\Documents and Settings\dsltech\My Documents\PraMac.xls
[2008/10/02 14:12:18 | 00,001,910 | ---- | M] () -- C:\Documents and Settings\dsltech\Desktop\Business Element Manager.lnk
[2008/10/02 13:09:02 | 12,302,6196 | ---- | M] (Macrovision) -- C:\Documents and Settings\dsltech\My Documents\BCMElementMgrInstaller.exe
[2008/10/02 09:24:42 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\dsltech\Desktop\HijackThis.lnk
[2008/10/02 09:02:42 | 00,484,958 | ---- | M] (Marckie ) -- C:\HaxFix.exe
[2008/10/01 16:16:44 | 00,112,955 | ---- | M] () -- C:\WINDOWS\BMc371be7a.xml
[2008/10/01 16:16:41 | 00,000,022 | ---- | M] () -- C:\WINDOWS\pskt.ini
[2008/09/30 22:02:26 | 00,882,302 | -HS- | M] () -- C:\WINDOWS\System32\nprYFfii.ini
[2008/09/30 22:02:04 | 00,882,302 | -HS- | M] () -- C:\WINDOWS\System32\nprYFfii.ini2
[2008/09/30 17:09:00 | 00,947,237 | -HS- | M] () -- C:\WINDOWS\System32\dlhcpplg.ini
[2008/09/30 14:10:53 | 00,124,030 | ---- | M] () -- C:\WINDOWS\System32\TmEncryptTemp.000
[2008/09/30 14:10:53 | 00,123,904 | ---- | M] () -- C:\WINDOWS\System32\ejiind.dll
[2008/09/29 13:09:34 | 00,990,996 | -HS- | M] () -- C:\WINDOWS\System32\bkinajco.ini
[2008/09/29 13:08:29 | 00,990,996 | -HS- | M] () -- C:\WINDOWS\System32\pxscgljs.ini
[2008/09/27 15:44:48 | 00,249,919 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/09/27 14:20:38 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2008/09/27 14:20:37 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2008/09/27 14:20:33 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2008/09/27 14:20:24 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2008/09/27 14:20:17 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2008/09/27 13:08:26 | 00,986,883 | -HS- | M] () -- C:\WINDOWS\System32\ndpenmfr.ini
[2008/09/27 12:54:47 | 00,041,724 | -HS- | M] () -- C:\Program Files\Common Files\Yazzle1554OinUninstaller.exe
[2008/09/13 16:20:05 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2008/09/10 14:34:14 | 00,013,824 | ---- | M] () -- C:\Documents and Settings\dsltech\My Documents\supplyrequest.xls
< End of report >


OTViewIt Extras logfile created on: 10/8/2008 7:49:50 AM - Run
OTViewIt by OldTimer - Version 1.0.10.1 Folder = C:\Documents and Settings\dsltech\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.36 Mb Total Physical Memory | 97.00 Mb Available Physical Memory | 19.27% Memory free
1.20 Gb Paging File | 0.85 Gb Available in Paging File | 70.86% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 28.40 Gb Free Space | 76.24% Space Free | Partition Type: NTFS
Drive D: | 403.20 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NEKE00LXP042796
Current User Name: dsltech
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=1
"FirewallDisableNotify"=1
"UpdatesDisableNotify"=1
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2004/08/04 00:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
File not found -- C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE:*:Enabled:OUTLOOK.EXE
[2004/08/04 00:56:50 | 01,032,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\NetMeeting\conf.exe:*:Enabled:conf.exe
File not found -- D:\SETUP.EXE:*:Enabled:Setup

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2004/08/04 00:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
File not found -- C:\Program Files\SmartFTP\SmartFTP.exe:*:Enabled:SmartFTP
[2004/08/04 00:56:50 | 01,032,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\NetMeeting\conf.exe:*:Enabled:conf.exe
File not found -- C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE:*:Enabled:OUTLOOK.EXE
[2004/08/04 00:56:52 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer
File not found -- C:\WINDOWS\system32\~.exe:*:Enabled:Browser
[2008/09/27 14:20:00 | 00,641,304 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 12:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/09/27 14:20:13 | 00,079,128 | ---- | M] (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG8\avgpp.dll (linkscanner:{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} (HKLM) [XPLPPFilter Class])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 12:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 12:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2003/12/03 21:09:50 | 00,139,264 | ---- | M] () C:\Program Files\Viryanet\MicroServer\ViryaNetHttp.dll (viryanet:{CBC37B4C-A4A3-11D6-AA2F-000255F45826} (HKLM) [HttpFilter Class])

========== (O18) Protocol Filters ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2007/04/19 13:57:40 | 00,046,432 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00020409-78E1-11D2-B60F-006097C998E7}"=Microsoft Office 2000 SR-1 Standard
"{06DD140B-AA3D-4BD4-84B9-217897127DC6}"=Nortel Networks i2050 Software Phone
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}"=mLogView
"{172423F9-522A-483A-AD65-03600CE4CA4F}"=Microsoft Works 6-9 Converter
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}"=Google Earth
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}"=mProSafe
"{3248F0A8-6813-11D6-A77B-00B0D0150060}"=J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150100}"=J2SE Runtime Environment 5.0 Update 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}"=mIWA
"{41C18715-AFF0-49E9-B940-287A50532D33}"=Cisco Clean Access Agent
"{552171BC-30F8-3B29-9C4F-E3FE590B7CAC}"=Google Gears
"{5624C000-B109-11D4-9DB4-00E0290FCAC5}"=VPN Client
"{5D97A4A7-C274-4B63-86D9-07A33435F505}"=InterVideo DVD Check
"{5E8A1B08-0FBD-4543-9646-F2C2D0D05750}"=Macromedia Flash Player 8
"{7148F0A8-6813-11D6-A77B-00B0D0142030}"=Java 2 Runtime Environment, SE v1.4.2_03
"{71B90506-005A-4F6C-AAAC-AC8F9CEC1F86}"=Business Series Terminals Desktop Assistant v 1.4
"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable
"{8A708DD8-A5E6-11D4-A706-000629E95E20}"=Intel® Graphics Media Accelerator Driver for Mobile
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}"=mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}"=mHelp
"{90120409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Standard Edition 2003
"{90B0D222-8C21-4B35-9262-53B042F18AF9}"=mPfWiz
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}"=InterVideo WinDVD
"{94658027-9F16-4509-BBD7-A59FE57C3023}"=mZConfig
"{9CC89556-3578-48DD-8408-04E66EBEF401}"=mXML
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}"=mDriver
"{AC76BA86-7AD7-1033-7B44-A70000000000}"=Adobe Reader 7.0.8
"{B502B428-3386-40A9-98DB-079AAB72E64F}"=mEoU
"{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}"=Motorola Phone Tools
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}"=Broadcom NetXtreme Ethernet Controller
"{E81667C6-2856-46D6-ABEA-6A2F42166779}"=mCore
"{E92B7A19-5FD5-4AEE-9FEF-7AD5DD3A675E}"=MetaFrame Presentation Server Client
"{EFCE5837-FC21-11D6-9D24-00010240CE95}"=Java 2 Runtime Environment, SE v1.4.1_02
"{F0A37341-D692-11D4-A984-009027EC0A9C}"=SoundMAX
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}"=mMHouse
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}"=mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}"=mWlsSafe
"{FF6F491D-BC82-4DCC-A72F-1824957C6466}"=TIxx21
"ActiveTouchMeetingClient"=WebEx
"Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player Plugin
"Agere Systems Soft Modem"=Agere Systems AC'97 Modem
"AVG8Uninstall"=AVG Free 8.0
"BCM Monitor"=BCM Monitor
"ClientAccessExpress"=IBM iSeries Access for Windows
"Google Updater"=Google Updater
"HijackThis"=HijackThis 2.0.2
"hp LaserJet 4200 Uninstaller"=hp LaserJet 4200 Uninstaller
"InstallShield_{71B90506-005A-4F6C-AAAC-AC8F9CEC1F86}"=Nortel Networks Desktop Assistant v 1.4
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}"=Broadcom NetXtreme Ethernet Controller
"InstallShield_{FF6F491D-BC82-4DCC-A72F-1824957C6466}"=Texas Instruments PCIxx21/x515 drivers.
"Java Web Start"=Java Web Start
"Macromedia Authorware Web Player"=Macromedia Authorware Web Player
"Macromedia Shockwave Player"=Macromedia Shockwave Player
"Nortel BCM Element Manager"=Nortel BCM Element Manager
"Nortel Business Element Manager"=Nortel Business Element Manager
"OfficeScanNT"=Trend Micro OfficeScan Client
"OINAnalytics"=OIN Analytics
"ProInst"=Intel® PROSet/Wireless Software
"ShockwaveFlash"=Adobe Flash Player 9 ActiveX
"SynTPDeinstKey"=Synaptics Pointing Device Driver
"Unified Manager Client"=Unified Manager Client
"Viryanet Sync Agent"=Viryanet Sync Agent
"WIC"=Windows Imaging Component
"Windows Media Format Runtime"=Windows Media Format Runtime
"Windows Media Player"=Windows Media Player 10

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome"=Google Chrome

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome"=Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/7/2008 1:50:59 AM | Computer Name = NEKE00LXP042796 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 10/7/2008 9:50:59 AM | Computer Name = NEKE00LXP042796 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 10/7/2008 2:37:32 PM | Computer Name = NEKE00LXP042796 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 10/7/2008 2:38:32 PM | Computer Name = NEKE00LXP042796 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 10/7/2008 3:45:06 PM | Computer Name = NEKE00LXP042796 | Source = Google Update | ID = 20
Description =

Error - 10/7/2008 4:45:07 PM | Computer Name = NEKE00LXP042796 | Source = Google Update | ID = 20
Description =

Error - 10/7/2008 5:35:54 PM | Computer Name = NEKE00LXP042796 | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 10/7/2008 5:36:56 PM | Computer Name = NEKE00LXP042796 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 10/7/2008 5:45:30 PM | Computer Name = NEKE00LXP042796 | Source = Google Update | ID = 20
Description =

Error - 10/8/2008 1:36:57 AM | Computer Name = NEKE00LXP042796 | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

[ System Events ]
Error - 10/7/2008 6:06:38 PM | Computer Name = NEKE00LXP042796 | Source = NETLOGON | ID = 3224
Description = Changing machine account password for account NEKE00LXP042796$ failed
with the following error: %%1311

Error - 10/7/2008 6:50:04 PM | Computer Name = NEKE00LXP042796 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 10/7/2008 7:05:39 PM | Computer Name = NEKE00LXP042796 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.

Error - 10/7/2008 7:35:22 PM | Computer Name = NEKE00LXP042796 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 59 minutes. NtpClient has no source of accurate
time.

Error - 10/7/2008 8:35:22 PM | Computer Name = NEKE00LXP042796 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 119 minutes. NtpClient has no source of accurate
time.

Error - 10/7/2008 9:36:11 PM | Computer Name = NEKE00LXP042796 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CORP due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.

Error - 10/7/2008 10:35:22 PM | Computer Name = NEKE00LXP042796 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 239 minutes. NtpClient has no source of accurate
time.

Error - 10/8/2008 1:51:11 AM | Computer Name = NEKE00LXP042796 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CORP due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.

Error - 10/8/2008 2:35:23 AM | Computer Name = NEKE00LXP042796 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 479 minutes. NtpClient has no source of accurate
time.

Error - 10/8/2008 5:51:11 AM | Computer Name = NEKE00LXP042796 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain CORP due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.


< End of report >

KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, October 8, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, October 08, 2008 10:36:47
Records in database: 1299683


Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area My Computer
C:\
D:\

Scan statistics
Files scanned 64717
Threat name 13
Infected objects 17
Suspicious objects 0
Duration of the scan 01:45:41

File name Threat name Threats count
C:\Documents and Settings\dsltech\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-6bfc845e Infected: Trojan.Java.ClassLoader.as 3

C:\Program Files\Common Files\Yazzle1554OinUninstaller.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gp 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\ctxad-580.0000 Infected: Backdoor.Win32.Small.emn 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\ctxad.exe Infected: not-a-virus:AdWare.Win32.PurityScan.if 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\ctxad.exe Infected: not-a-virus:AdWare.Win32.PurityScan.id 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\ctxad.exe Infected: not-a-virus:AdWare.Win32.PurityScan.hh 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\ctxad.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\iggade.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.altx 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\swbvjndo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.altx 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\tsvljuji.dll Infected: Backdoor.Win32.Delf.mid 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\uamybtui.dll Infected: Trojan.Win32.Agent.afqd 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\Yazzle1554OinAdmin.exe Infected: Trojan-Downloader.Win32.PurityScan.gb 1

C:\Program Files\Trend Micro\OfficeScan Client\Suspect\~.exe Infected: Trojan.Win32.Agent.afhv 1

C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b 1

C:\WINDOWS\system32\TmEncryptTemp.000 Infected: Backdoor.Win32.Delf.mid 1

The selected area was scanned.

#5 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:44 PM

Posted 08 October 2008 - 07:41 PM

Hello, pmcilnay.
One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do.

If you wish to move on, please follow the following instructions:

We need to execute an OTMoveIt3 script
  • Please download OTMoveIt3 by OldTimer and save it to your desktop.
  • Double click the Posted Image icon on your desktop.
  • Paste the following code under the Posted Image area. Do not include the word "Code".
    :processes
    RZE59C.EXE
    :files
    C:\WINDOWS\system32\ejiind.dll
    C:\WINDOWS\system32\ljJDUlLC.dll
    C:\Program Files\OINAnalytics
    C:\WINDOWS\system32\iifFYrpn.dll
    C:\WINDOWS\system32\kviuisou.dll
    C:\HaxFix.exe
    C:\HaxFix
    C:\WINDOWS\System32\dlhcpplg.ini
    C:\WINDOWS\System32\ejiind.dll
    C:\WINDOWS\System32\bkinajco.ini
    C:\WINDOWS\System32\pxscgljs.ini
    C:\Program Files\Mjcore
    C:\WINDOWS\System32\ndpenmfr.ini
    C:\WINDOWS\BMc371be7a.xml
    C:\WINDOWS\pskt.ini
    C:\Program Files\VnrBlock
    C:\WINDOWS\System32\nprYFfii.ini2
    C:\WINDOWS\System32\nprYFfii.ini
    C:\Program Files\Common Files\Yazzle1554OinUninstaller.exe
    C:\Program Files\s?stem32 /u
    C:\Documents and Settings\dsltech\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-6bfc845e
    C:\Program Files\Trend Micro\OfficeScan Client\Suspect\*
    C:\WINDOWS\Downloaded Program Files\popcaploader.dll
    C:\WINDOWS\system32\TmEncryptTemp.000
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{121cfec4-5213-426a-8994-5e5e63436fe3}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{453F51E8-FEF5-4C54-B136-944BF434360C}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B221E01-F517-4959-8C41-81948E7F2F17}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96D1619A-9E8C-4C8A-9094-6CF4BDB4960D}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BMc371be7a"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_Dlls"="avgrsstx.dll"
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ljJDUlLC]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{453F51E8-FEF5-4C54-B136-944BF434360C}"=-
    Registry::
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
    :commands
    [Purity]
    [EmptyTemp]
  • Push the large Posted Image button.
  • OTMI3 may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the Posted Image line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
We need to create an OTViewIt Report
  • Please download OTViewIt by OldTimer.
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
  • OTViewIt.txt <-- Will be opened
  • Extra.txt <-- Will be minimized
In your next reply, please include the following:
  • OTMoveIt3's Log
  • OTViewIt.txt
  • Extra.txt

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#6 pmcilnay

pmcilnay
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:44 PM

Posted 10 October 2008 - 08:36 PM

I ran the OTMoveIt3 and received the following errors, each in its own window:



OTMoveIt3: OTMoveIt3.exe - Bad Image

The applicatoin or DLL C:\Program Files\Trend Micro\OfficeScan Client\Suspect\iggade.dll is not a valid
Windows image. Please check this againt your intallation disketee.


OTMoveIt3: OTMoveIt3.exe - Bad Image

The applicatoin or DLL C:\Program Files\Trend Micro\OfficeScan Client\Suspect\swbvjndo.dll is not a valid
Windows image. Please check this againt your intallation disketee.


OTMoveIt3: OTMoveIt3.exe - Bad Image

The applicatoin or DLL C:\Program Files\Trend Micro\OfficeScan Client\Suspect\tsvljuji.dll is not a valid
Windows image. Please check this againt your intallation disketee.


OTMoveIt3: OTMoveIt3.exe - Bad Image

The applicatoin or DLL C:\Program Files\Trend Micro\OfficeScan Client\Suspect\uamybtui.dll is not a valid
Windows image. Please check this againt your intallation disketee.

The app became unresponsive, so I couldn't copy the log. I followed your instructions on retrieving the moved items folder, but couldn't find the file. I then did a search for files *.log, the only result that matched the time that I ran the app was a system32 log that contained my network ip address. I went ahead and ran the OTviewit:



OTViewIt logfile created on: 10/9/2008 5:02:48 PM - Run 2
OTViewIt by OldTimer - Version 1.0.10.1 Folder = C:\Documents and Settings\dsltech\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.36 Mb Total Physical Memory | 187.20 Mb Available Physical Memory | 37.19% Memory free
1.20 Gb Paging File | 0.84 Gb Available in Paging File | 69.80% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 28.31 Gb Free Space | 75.98% Space Free | Partition Type: NTFS
Drive D: | 403.20 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NEKE00LXP042796
Current User Name: dsltech
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2006/02/28 13:16:08 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
[2006/02/28 13:18:10 | 00,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
[2008/09/27 14:19:58 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
[2005/04/07 15:26:10 | 01,421,336 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Frontier Connect\VPN Client\cvpnd.exe
[2008/05/30 12:16:38 | 00,137,200 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[2004/03/19 14:15:10 | 00,081,920 | ---- | M] (Nortel Networks Corp.) -- C:\WINDOWS\system32\i2050QosSvc.exe
[2005/11/17 19:38:12 | 00,491,520 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe
[2006/02/28 13:15:30 | 00,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
[2002/09/20 13:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
[2005/11/17 19:38:04 | 00,606,296 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe
[2005/01/28 12:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe
[2005/11/17 19:46:36 | 00,229,456 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
[2008/09/27 14:20:00 | 00,287,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
[2005/11/17 19:46:24 | 00,172,099 | ---- | M] () -- C:\WINDOWS\Temp\RZE59C.EXE
[2005/09/08 17:59:22 | 00,024,848 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\ssonsvr.exe
[2004/11/04 17:40:08 | 00,098,394 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[2004/11/04 17:38:54 | 00,688,218 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[2005/04/13 08:12:38 | 00,088,209 | ---- | M] (Agere Systems) -- C:\WINDOWS\AGRSMMSG.exe
[2004/12/21 10:11:32 | 00,126,976 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\hkcmd.exe
[2004/10/14 08:11:10 | 01,388,544 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
[2006/02/28 13:25:20 | 00,667,718 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
[2006/02/28 13:25:48 | 00,602,182 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
[2006/02/28 13:29:54 | 00,569,413 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
[2005/11/17 19:49:30 | 00,335,872 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\PccNTMon.exe
[2007/04/05 15:22:50 | 00,282,624 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\QuickTime\qttask.exe
[2008/09/04 11:31:08 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[2006/02/28 13:22:50 | 00,397,381 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
[2007/09/06 23:13:06 | 02,056,275 | ---- | M] (Cisco Systems, Inc) -- C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
[2008/10/08 07:58:04 | 00,147,456 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
[2008/09/14 05:20:53 | 00,634,368 | ---- | M] (Google Inc.) -- C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
[2008/09/14 05:20:53 | 00,634,368 | ---- | M] (Google Inc.) -- C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
[2008/10/09 16:53:52 | 00,334,848 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTMoveIt3.exe
[2008/10/09 16:59:17 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTViewIt (1).exe

========== (O23) Win32 Services ==========

[2008/09/27 14:19:58 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
[2005/04/07 15:26:10 | 01,421,336 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Frontier Connect\VPN Client\cvpnd.exe -- (CVPND [Auto | Running])
[2002/02/04 05:20:00 | 00,053,296 | ---- | M] (IBM Corporation) -- C:\WINDOWS\cwbrxd.exe -- (Cwbrxd [On_Demand | Stopped])
[2006/02/28 13:16:08 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng [Auto | Running])
[2008/05/30 12:16:38 | 00,137,200 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Auto | Running])
[2004/03/19 14:15:10 | 00,081,920 | ---- | M] (Nortel Networks Corp.) -- C:\WINDOWS\system32\i2050QosSvc.exe -- (i2050QoSSvc [Auto | Running])
[2005/11/17 19:38:12 | 00,491,520 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe -- (ntrtscan [Auto | Running])
[2005/11/17 19:46:36 | 00,229,456 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe -- (OfcPfwSvc [Auto | Running])
[2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2003/11/04 16:10:18 | 00,065,795 | ---- | M] (HP) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZIPM12.EXE -- (Pml Driver HPZ12 [On_Demand | Stopped])
[2006/02/28 13:15:30 | 00,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc [Auto | Running])
[2006/02/28 13:18:10 | 00,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor [Auto | Running])
[2002/09/20 13:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default) [Auto | Running])
[2005/11/17 19:38:04 | 00,606,296 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe -- (tmlisten [Auto | Running])
[2005/01/28 12:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running])
[2008/10/08 07:58:04 | 00,147,456 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])

========== Driver Services ==========

[2004/11/08 13:10:36 | 00,127,744 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (aeaudio [On_Demand | Running])
[2006/08/03 07:34:41 | 00,021,275 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP [Auto | Running])
[2005/04/13 08:12:38 | 01,066,278 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem [On_Demand | Running])
[2008/09/27 14:20:33 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (AvgLdx86 [System | Running])
[2008/09/27 14:20:24 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (AvgMfx86 [System | Running])
[2004/11/16 12:46:38 | 00,190,592 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k [On_Demand | Running])
File not found -- C:\DOCUME~1\dsltech\LOCALS~1\Temp\catchme.sys -- (catchme [On_Demand | Stopped])
[2005/02/08 09:27:00 | 00,005,185 | ---- | M] (Cisco Systems, Inc.) -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA [On_Demand | Stopped])
[2005/04/07 15:23:50 | 00,299,083 | ---- | M] (Cisco Systems, Inc.) -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA [Auto | Running])
[2003/07/24 17:55:50 | 00,139,604 | ---- | M] (Deterministic Networks, Inc.) -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE [On_Demand | Running])
[2005/05/31 10:46:26 | 00,087,936 | R--- | M] (Texas Instruments) -- C:\WINDOWS\system32\drivers\gtipci21.sys -- (GTIPCI21 [On_Demand | Running])
[2004/12/21 10:44:18 | 00,776,349 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\ialmnt5.sys -- (ialm [On_Demand | Running])
[2003/02/23 03:05:00 | 00,002,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\idisw2km.sys -- (idisw2km [Disabled | Stopped])
[2003/02/23 03:05:00 | 00,007,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\kbstuff5.sys -- (kbstuff [On_Demand | Running])
[2001/08/23 07:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2001/08/23 07:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\rootmdm.sys -- (ROOTMODEM [On_Demand | Running])
[2006/02/28 14:35:56 | 00,013,568 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans [Auto | Running])
[2004/08/03 23:07:48 | 00,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\sdbus.sys -- (sdbus [On_Demand | Running])
[2007/11/13 05:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2001/08/17 07:10:28 | 00,035,913 | ---- | M] (SMC) -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA [On_Demand | Running])
[2004/10/13 13:25:54 | 00,259,840 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])
[2004/11/04 17:26:42 | 00,186,016 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP [On_Demand | Running])
[2005/06/23 08:16:08 | 00,162,176 | ---- | M] (Texas Instruments) -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21 [On_Demand | Running])
[2008/08/16 03:00:52 | 00,205,328 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys -- (TmFilter [Auto | Running])
[2008/08/16 03:00:46 | 00,036,368 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\tmpreflt.sys -- (TmPreFilter [Auto | Running])
[2004/08/03 23:07:56 | 00,059,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio [On_Demand | Stopped])
[2008/07/23 16:45:58 | 00,022,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbsermpt.sys -- (usbsermpt [On_Demand | Stopped])
[2008/08/16 02:53:50 | 01,195,448 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\OfficeScan Client\vsapiNT.sys -- (VSApiNt [Auto | Running])
[2005/01/26 03:22:20 | 00,280,344 | ---- | M] (Zone Labs LLC) -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant [On_Demand | Running])
[2006/02/09 09:03:18 | 03,298,432 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51 [On_Demand | Running])
[2004/08/03 18:07:42 | 00,008,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wmiacpi.sys -- (WmiAcpi [System | Running])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.dogpile.com/

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.dogpile.com/

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (HKLM) -- C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (HKLM) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"=AGRSMMSG.exe (Agere Systems)
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
"Client Access Check Version"="C:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN (IBM Corporation)
"Client Access Express Welcome"="C:\Program Files\IBM\Client Access\cwbwlwiz.exe" (IBM Corporation)
"Client Access Help Update"="C:\Program Files\IBM\Client Access\cwbinhlp.exe" (IBM Corporation)
"Client Access Service"="C:\Program Files\IBM\Client Access\cwbsvstr.exe" (IBM Corporation)
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" (Intel Corporation)
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless (Intel Corporation)
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" (Intel Corporation)
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe" -HideWindow (Trend Micro Inc.)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray (Analog Devices, Inc.)
"SoundMAXPnP"=C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
"WatchDog"=C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)

========== (O4) Startup Folders ==========

[2007/09/06 23:13:06 | 02,056,275 | ---- | M] (Cisco Systems, Inc) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
[2006/04/18 05:33:04 | 00,163,597 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Mail.lnk = C:\profgen\mail.EXE

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoWelcomeScreen"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=1
"legalnoticecaption"=Legal Notice
"legalnoticetext"=This computer system and the data contained herein are property of Frontier Communications. Any unauthorized access and/or use of the data will be investigated and prosecuted to the full extent of the law. This system is to be used for business purposes. All information stored or processed is property of Frontier Communications and is subject to inspection.
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-854152917-509491024-1205494865-1010\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\system32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 11:24:37 | 01,694,208 | ---- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}: http://www.apple.com/qtactivex/qtplugin.cab -- QuickTime Object
{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}: http://download.microsoft.com/download/0/f...tualEarth3D.cab -- Reg Error: Key does not exist or could not be opened.
{6414512B-B978-451D-A0D8-FCFDF33E833C}: http://www.update.microsoft.com/windowsupd...b?1209132789957 -- WUWebControl Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_10
{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}: http://java.sun.com/products/plugin/1.4/ji...indows-i586.cab -- Java Plug-in 1.4.1_02
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_06
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_10
{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_10
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_10
{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}: http://www.cbsgames.com/games/play/zuma/popcaploader_v10.cab -- Reg Error: Key does not exist or could not be opened.
Microsoft XML Parser for Java: file://C:\WINDOWS\Java\classes\xmldso.cab -- Reg Error: Key does not exist or could not be opened.

========== (O17) DNS Name Servers ==========

{33457D43-9EF7-485B-9A14-8A1F734CB7E8} (Servers: | Description: )
{72D8AC0E-79E3-42B5-8E65-E7394C07903B} (Servers: | Description: Intel® PRO/Wireless 2200BG Network Connection)
{DE965516-35EB-464D-B0AB-3FCA64D7D910} (Servers: | Description: Broadcom NetXtreme Gigabit Ethernet)

========== (O20) AppInit_DLLs ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls"=avgrsstx.dll
>[2008/09/27 14:20:37 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\avgrsstx.dll

========== (O20) Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
igfxcui: "DllName" = igfxsrvc.dll -- C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=msv1_0,C:\WINDOWS\system32\iifFYrpn,
>File not found --

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
[2006/06/27 12:43:49 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]


========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e7a7dcbe-7420-11db-84e0-001560c9c5f6}\Shell\AutoRun\command]
""=JDSecure\Windows\JDSecure31.exe

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[2008/10/09 16:59:17 | 00,421,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTViewIt (1).exe
[2008/10/09 16:55:46 | 00,000,000 | ---D | C] -- C:\_OTMoveIt
[2008/10/09 16:53:54 | 00,334,848 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTMoveIt3.exe
[2008/10/08 11:42:11 | 00,006,061 | ---- | C] () -- C:\Documents and Settings\dsltech\Desktop\kas.html
[2008/10/08 07:48:05 | 00,421,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTViewIt.exe
[2008/10/02 16:52:31 | 00,026,624 | ---- | C] () -- C:\Documents and Settings\dsltech\My Documents\PraMac.xls
[2008/10/02 14:12:18 | 00,001,910 | ---- | C] () -- C:\Documents and Settings\dsltech\Desktop\Business Element Manager.lnk
[2008/10/02 13:08:13 | 12,302,6196 | ---- | C] (Macrovision) -- C:\Documents and Settings\dsltech\My Documents\BCMElementMgrInstaller.exe
[2008/10/02 09:24:41 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\dsltech\Desktop\HijackThis.lnk
[2008/09/28 13:14:27 | 00,000,000 | ---D | C] -- C:\Program Files\Twain
[2008/09/28 13:09:28 | 00,000,000 | ---D | C] -- C:\Program Files\Webtools
[2008/09/27 15:48:27 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2008/09/27 14:20:38 | 00,001,507 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2008/09/27 14:20:37 | 00,010,520 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2008/09/27 14:20:33 | 00,097,928 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2008/09/27 14:20:24 | 00,026,824 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2008/09/27 14:20:17 | 28,409,136 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2008/09/27 14:20:17 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2008/09/27 14:20:17 | 00,307,238 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/09/27 14:20:17 | 00,068,419 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2008/09/27 14:20:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2008/09/27 14:19:57 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2008/09/27 14:19:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2008/09/25 15:47:45 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbprint.sys
[2008/09/25 15:47:45 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbprint.sys
[2008/09/10 14:34:14 | 00,013,824 | ---- | C] () -- C:\Documents and Settings\dsltech\My Documents\supplyrequest.xls

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2008/10/09 16:59:17 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTViewIt (1).exe
[2008/10/09 16:53:52 | 00,334,848 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTMoveIt3.exe
[2008/10/09 16:53:13 | 28,409,136 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2008/10/09 16:53:13 | 00,307,238 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/10/09 16:27:36 | 00,026,624 | ---- | M] () -- C:\Documents and Settings\dsltech\My Documents\PraMac.xls
[2008/10/08 11:42:11 | 00,006,061 | ---- | M] () -- C:\Documents and Settings\dsltech\Desktop\kas.html
[2008/10/08 07:48:06 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\dsltech\Desktop\OTViewIt.exe
[2008/10/07 16:40:07 | 00,359,948 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2008/10/07 16:40:07 | 00,315,076 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2008/10/07 16:40:07 | 00,041,238 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2008/10/07 16:37:01 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008/10/07 16:35:54 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/10/07 16:35:50 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008/10/07 12:58:03 | 02,814,422 | -H-- | M] () -- C:\Documents and Settings\dsltech\Local Settings\Application Data\IconCache.db
[2008/10/05 08:59:24 | 00,068,419 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2008/10/02 14:12:18 | 00,001,910 | ---- | M] () -- C:\Documents and Settings\dsltech\Desktop\Business Element Manager.lnk
[2008/10/02 13:09:02 | 12,302,6196 | ---- | M] (Macrovision) -- C:\Documents and Settings\dsltech\My Documents\BCMElementMgrInstaller.exe
[2008/10/02 09:24:42 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\dsltech\Desktop\HijackThis.lnk
[2008/09/27 14:20:38 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2008/09/27 14:20:37 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2008/09/27 14:20:33 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2008/09/27 14:20:24 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2008/09/27 14:20:17 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2008/09/13 16:20:05 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2008/09/10 14:34:14 | 00,013,824 | ---- | M] () -- C:\Documents and Settings\dsltech\My Documents\supplyrequest.xls
< End of report >

#7 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:44 PM

Posted 10 October 2008 - 08:40 PM

Hello, pmcilnay.
We need to run ComboFix.In your next reply, please include the following:
  • ComboFix.txt

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#8 pmcilnay

pmcilnay
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:44 PM

Posted 11 October 2008 - 10:52 AM

ComboFix 08-10-10.09 - dsltech 2008-10-11 10:42:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.153 [GMT -5:00]
Running from: C:\Documents and Settings\dsltech\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\dsltech\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\dsltech\Local Settings\Temporary Internet Files\CPV.stt
C:\WINDOWS\BMc371be7a.txt
C:\WINDOWS\system32\mdm.exe

----- BITS: Possible infected sites -----

hxxp://mnbv00s2kps01
.
((((((((((((((((((((((((( Files Created from 2008-09-11 to 2008-10-11 )))))))))))))))))))))))))))))))
.

2008-10-09 16:55 . 2008-10-09 16:55 <DIR> d-------- C:\_OTMoveIt
2008-10-08 07:57 . 2008-10-08 07:57 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-10-08 07:57 . 2008-10-08 07:57 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-28 13:14 . 2008-09-29 04:02 <DIR> d-------- C:\Program Files\Twain
2008-09-28 13:09 . 2008-09-28 13:09 <DIR> d-------- C:\Program Files\Webtools
2008-09-27 15:48 . 2008-10-06 06:41 <DIR> d--h----- C:\$AVG8.VAULT$
2008-09-27 14:20 . 2008-10-10 20:17 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-09-27 14:20 . 2008-09-27 14:20 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-27 14:20 . 2008-09-27 14:20 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-09-27 14:19 . 2008-09-27 14:19 <DIR> d-------- C:\Program Files\AVG
2008-09-27 14:19 . 2008-09-27 14:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-09-27 14:16 . 2008-09-27 14:21 8,192 --a------ C:\Documents and Settings\frontier
2008-09-25 15:47 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-09-25 15:47 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-11 14:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-08 12:56 --------- d-----w C:\Program Files\Java
2008-10-07 18:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-02 14:24 --------- d-----w C:\Program Files\Trend Micro
2008-09-27 19:11 --------- d-----w C:\Program Files\AIM
2008-09-27 19:11 --------- d-----w C:\Documents and Settings\dsltech\Application Data\Aim
2008-07-23 21:45 24,192 ----a-w C:\Documents and Settings\dsltech\usbsermptxp.sys
2008-07-23 21:45 22,768 ----a-w C:\Documents and Settings\dsltech\usbsermpt.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-04 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-12-21 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-12-21 126976]
"WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2004-12-08 184320]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-02-28 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-02-28 602182]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2006-02-28 569413]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\Pccntmon.exe" [2005-11-17 335872]
"Client Access Service"="C:\Program Files\IBM\Client Access\cwbsvstr.exe" [2002-05-07 20530]
"Client Access Help Update"="C:\Program Files\IBM\Client Access\cwbinhlp.exe" [2002-05-07 24626]
"Client Access Check Version"="C:\Program Files\IBM\Client Access\cwbckver.exe" [2002-05-07 45056]
"Client Access Express Welcome"="C:\Program Files\IBM\Client Access\cwbwlwiz.exe" [2002-05-07 20530]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-05 282624]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-10-08 144792]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-13 C:\WINDOWS\AGRSMMSG.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Clean Access Agent.lnk - C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe [2007-09-06 2056275]
Mail.lnk - C:\profgen\mail.EXE [2006-09-21 163597]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"<NO NAME>"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:@xpsp2res.dll,-22002
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"2701:TCP"= 2701:TCP:Remote Information
"<NO NAME>"=
"2701:UDP"= 2701:UDP:Remote Information
"2702:TCP"= 2702:TCP:Remote Control
"2702:UDP"= 2702:UDP:Remote Control
"2703:TCP"= 2703:TCP:Chat
"2703:UDP"= 2703:UDP:Chat
"2704:TCP"= 2704:TCP:File Transfer
"2704:UDP"= 2704:UDP:File Transfer
"6129:TCP"= 6129:TCP:DameWare
"4001:TCP"= 4001:TCP:Witness
"4001:UDP"= 4001:UDP:Witness
"4004:TCP"= 4004:TCP:Witness
"4004:UDP"= 4004:UDP:Witness
"15000:TCP"= 15000:TCP:Witness
"15000:UDP"= 15000:UDP:Witness
"15001:TCP"= 15001:TCP:Witness
"15001:UDP"= 15001:UDP:Witness

R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-27 97928]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-27 231704]
R2 i2050QoSSvc;Nortel Networks i2050 QoS Service;C:\WINDOWS\system32\i2050QosSvc.exe [2004-03-19 81920]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-08 147456]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 87936]
S3 rcvpn;SonicWALL VPN Adapter;C:\WINDOWS\system32\DRIVERS\rcvpn.sys [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7a7dcbe-7420-11db-84e0-001560c9c5f6}]
\Shell\AutoRun\command - JDSecure\Windows\JDSecure31.exe
.
Contents of the 'Scheduled Tasks' folder

2008-10-11 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\dsltech\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 11:31]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\dsltech\Application Data\Mozilla\Firefox\Profiles\an89kvw0.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.dogpile.com/
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-11 10:46:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\Frontier Connect\VPN Client\cvpnd.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Temp\GUFF7B.EXE
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2008-10-11 10:51:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-11 15:51:08

Pre-Run: 30,298,292,224 bytes free
Post-Run: 30,559,043,584 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

172 --- E O F --- 2008-09-13 21:20:30

#9 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:44 PM

Posted 11 October 2008 - 05:27 PM

Hello, pmcilnay.
That looks much better. How are things running?

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE)6 Update 7...allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-Language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u7-windows-i586-p.exe
  • Follow the on screen instructions to install the latest Java version.
We need to clear out some temporary data.
Please download ATF Cleaner by Atribune. (This program is for XP and Windows 2000 only)Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

I would like us to use ESET (NOD32)'s Online Scanner
  • Please go to ESET OnlineScan (NOD32)
  • You will then see the Terms of Use, tick the check-box infront of YES, I accept the Terms of Use
  • Now click Start
  • Should you face a Security Warning that asks if you want to install and run a file called "OnlineScanner.cab", click Yes
  • Click Start
    • Note: (the Onlinescanner will now prepare itself for running on your pc)
  • To do a full-scan, tick: "Remove found threats" and "Scan potentially unwanted applications"
  • Press Scan
  • The Onlinescan will now start and scan your pc (this could take a while)
  • When the scan has finished, it will show a screen with two tabs "overview" and "details" and the option to get information or buy software, just close the window
  • Click Start >> Run... >> type: C:\Program Files\EsetOnlineScanner\log.txt
  • The Scanresults will now open in Notepad
  • Click into the text area, right-click and chose "select all" (or use +A)
  • Right-click again and chose "Copy" (or +C)
  • Close/Exit Notepad
  • Navigate to this thread and post your log along with anything else requested from us, by right-clicking and "paste" (or ctrl+v) in the text area of the reply post you just created.
Note: For Vista Users: Eset is compatible but Internet Explorer must be run as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.)

You Need to Update Windows (And other Microsoft Software)
Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.

If you are using Windows XP or earlier
Visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!

If you are using Windows Vista
  • Click the "Start Menu" (or Windows Orb)
  • Click "All Programs"
  • Click "Windows Update"
  • On the left, choose "Change Settings"
  • Ensure that the checkbox "Use Microsoft Update" at the bottom of the window is checked.
  • Press OK and accept the UAC prompt.
    Note: You shouldn't need to check this checkbox every single time you update, only the first time.
  • Click "Check for Updates" in the upper left corner.
  • Follow the instructions to install the latest updates.
  • Reboot and repeat the "Check for Updates" until there are no more critical updates to install
In your next reply, please include the following:
  • ESET OnlineScan's Log

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#10 pmcilnay

pmcilnay
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:44 PM

Posted 14 October 2008 - 09:45 PM

Everything seems to be running great. I've downloaded the java, but haven't installed it yet. The ESET log is as follows:

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3522 (20081014)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=6bc0831fb77f124fa330bb92e92455b6
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-10-15 02:39:48
# local_time=2008-10-14 09:39:48 (-0600, Central Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=465300
# found=8
# scan_time=2971
C:\_OTMoveIt\MovedFiles\10092008_165546\Documents and Settings\dsltech\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-6bfc845e multiple infiltrations (deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\10092008_165546\Documents and Settings\dsltech\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-6bfc845e »ZIP »BnnnnBaa.class Java/ClassLoader trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\10092008_165546\Documents and Settings\dsltech\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-6bfc845e »ZIP »VaannnaaBaa.class Java/ClassLoader trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\10092008_165546\Documents and Settings\dsltech\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-6bfc845e »ZIP »Dnnny.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\10092008_165546\Documents and Settings\dsltech\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-6bfc845e »ZIP »Bnnnnn.class Java/ClassLoader.AS trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\10092008_165546\Documents and Settings\dsltech\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-6bfc845e »ZIP »Den.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\10092008_165546\Documents and Settings\dsltech\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-6bfc845e »ZIP »Din.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\10092008_165546\Documents and Settings\dsltech\Application Data\Sun\Java\Deployment\cache\6.0\52\37011574-6bfc845e »ZIP »Dun.class Java/Exploit.Bytverify trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000

#11 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:44 PM

Posted 14 October 2008 - 09:51 PM

Hello, pmcilnay.
Congratulations! You now appear clean! :thumbsup:

Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware
We Need to Remove ComboFix
  • Please go to Start -> Run
  • Enter "ComboFix /u" (without quotes). Note the space betwen "ComboFix" and "/u", it needs to be there.
    Posted Image
  • Press OK (Or hit enter).
  • Allow ComboFix to remove itself.
We Need to Clean Up Our Mess
  • Please download OTCleanIt from one of the following mirrors and save it to your desktop:
  • Double click the Posted Image icon.
  • Push the large "Cleanup" button.
  • Allow your system to reboot.
Reset System Restore
Windows' "System Restore" feature can cause malware files to be cached and retained by your system. Resetting System Restore will clean these files from your system, and will allow you to use System Restore without fear of reinfection.
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Note: You should only do this once, not on a regular basis!
You will not be able to restore computer to any earlier than today!

Recommendations
Below are some recommendations to lower your chances of (re)infection.
  • Install and maintain an outbound firewall
  • Install Spyware Blaster and update it regularly
    If you wish, the commercial version provides automatic updating.
  • Install the MVPs hosts file, and update it regularly
    You can use the HostMan host file manager to do this automaticly if you wish.
    For more information on the hosts file, and what it can do for you, you can view the Tutorial on the Hosts file
  • Install an Anti-Spyware program, and update it regularly
    Malware Byte's Anti Malware is an excellent Anti-Spyware scanner. It's scan times are usually under ten minutes, and has excellent detection and removal rates.
    SUPERAntiSpyware is another good scanner with high detection and removal rates.
    Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.
  • Keep Windows (and your other Microsoft software) up to date!
    I cannot stress how important this is enough. Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.

    If you are using Windows XP or earlier
    Visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!

    If you are using Windows Vista
    • Click the "Start Menu" (or Windows Orb)
    • Click "All Programs"
    • Click "Windows Update"
    • On the left, choose "Change Settings"
    • Ensure that the checkbox "Use Microsoft Update" at the bottom of the window is checked.
    • Press OK and accept the UAC prompt.
      Note: You shouldn't need to check this checkbox every single time you update, only the first time.
    • Click "Check for Updates" in the upper left corner.
    • Follow the instructions to install the latest updates.
    • Reboot and repeat the "Check for Updates" until there are no more critical updates to install
  • Keep your other software up to date as well
    Software does not need to be made by Microsoft to be insecure. You can use the Secunia Online Software occasionally to help you check for out of date software on your machine.
  • Stay up to date!
    The MOST IMPORTANT part of any security setup is keeping the software up to date. Malware writers release new variants every single day. If your software updates don't keep up, then the malware will always be one step ahead. Not a good thing :).
Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#12 pmcilnay

pmcilnay
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:09:44 PM

Posted 16 October 2008 - 04:50 PM

Everything looks and runs great. Thanks so much! :thumbsup:

#13 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,301 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:07:44 PM

Posted 16 October 2008 - 06:22 PM

Hello, pmcilnay.
Since this issue appears resolved, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users