Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with (listed below) Trojans & Google keeps redirecting


  • This topic is locked This topic is locked
24 replies to this topic

#1 DOSummers

DOSummers

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:06:07 PM

Posted 06 January 2012 - 01:48 AM

First time poster here: I have just read your instructions & downloads tried to follow them exactly. Background: I have laptop running Windows XP Pro (without Windows Firewall activated) and McAfee anti-virus Enterprise 4.5.0.1810 version - but no help from anti-virus program. Google redirecting-type Malware contracted over the holidays at relative's home. Tonight, I just installed Malwarebytes Anti-Malware program for the first time and names of three detected/cleaned files are copied and listed below. Thanks very much ahead of time for your help.

Anti-Malware program after clean-up keeps blocking numerous outgoing websites, for example:

83.133.124.95
83.133.121.147
83.133.125.41
66.179.234.169
94.63.240.74
208.91.207.10
206.161.121.2
91.212.226.123
206.161.121.2
199.80.55.123
199.80.55.117
94.100.26.54

etc. etc.

Names of detections by Anti-Malware (2)scans:

Files Detected: 2
C:\WINDOWS\Temp\oiu0.34950450725306426.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\wera0.11368061993046752.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Files Detected: 1
C:\Documents and Settings\TTolt\Application Data\Sun\Java\Deployment\cache\6.0\2\54c35f82-22982528 (Trojan.Agent) -> Quarantined and deleted successfully.

copied dds.txt file below:

DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by ttolt at 21:39:29 on 2012-01-05
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.999 [GMT -7:00]
.
AV: McAfee VirusScan Enterprise+AntiSpyware Enterprise *Enabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
============== Running Processes ===============
.
C:\Program Files\Novell\CASA\bin\micasad.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k eapsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k dot3svc
C:\Program Files\Novell\ZENworks\bin\ZenworksWindowsService.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\IBM\Lotus\Notes\nsd.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\IBM\Lotus\Notes\ntmulti.exe
C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
C:\Program Files\AT&T Global Network Client\NetClientSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Novell\ZENworks\bin\nzrWinVNC.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\system32\StacSV.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\WINDOWS\itlm\tlmagent.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Novell\Zenworks\bin\ZenNotifyIcon.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Novell\ZENworks\bin\ZenUserDaemon.exe
C:\Program Files\Novell\ZENworks\bin\handlers\runscriptenf.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\Util\MapDrives.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Citrix\ICA Client\WFCRUN32.EXE
C:\Program Files\PrintKey2000\Printkey2000.exe
C:\PROGRA~1\AT&TGL~1\NETLOG~1.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\ping.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\util\nircmd.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://intranet.wlgore.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.wlgore.com;127.0.0.1;localhost;157.204.*;32.85.*;192.168.*;<local>
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\program files\mcafee\siteadvisor enterprise\McIEPlg.dll
BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110322105323.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\program files\mcafee\siteadvisor enterprise\McIEPlg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\program files\mcafee\siteadvisor enterprise\McIEPlg.dll
EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [WebCam-Disable] c:\windows\util\nircmd.exe execmd c:\windows\util\devcon.exe disable usb\CLASS_0E
uRun: [NetSP - restore settings on power failure] "c:\program files\at&t global network client\NetSP.exe" -show
uRun: [Adobe Reader Synchronizer] "c:\program files\adobe\reader 10.0\reader\AdobeCollabSync.exe"
mRun: [NWTRAY] NWTRAY.EXE
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [Pistolstar_SSO] "c:\program files\pistolstar\password power client\APOSSO.exe"
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [AGNS_Config] nircmd execmd c:\windows\ATT_Config.cmd
mRun: [ZenNotifyIcon] c:\program files\novell\zenworks\bin\ZenNotifyIcon.exe
mRun: [NalView] c:\program files\novell\zenworks\bin\NALVIEW.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe"
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup
mRun: [UserLogin] nircmd.exe execmd "c:\program files\novell\zenworks\bin\zac.exe" bln UserLogin-USW
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [MapDrive] c:\windows\util\MapDrives.exe
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
dRun: [WebCam-Disable] c:\windows\util\nircmd.exe execmd c:\windows\util\devcon.exe disable usb\CLASS_0E
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\printk~1.lnk - c:\program files\printkey2000\Printkey2000.exe
uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1)
uPolicies-explorer: NoSMBalloonTip = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
uPolicies-explorer: DisablePersonalDirChange = 1 (0x1)
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-explorer: NoPublishingWizard = 1 (0x1)
mPolicies-explorer: NoWebServices = 1 (0x1)
mPolicies-system: DisableCAD = 1 (0x1)
mPolicies-system: CompatibleRUPSecurity = 1 (0x1)
mPolicies-system: LogonType = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: mswsock.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://128.146.233.169/activex/AMC.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{8F2B6A9E-3794-48B6-87A3-83E7DC939721} : DhcpNameServer = 75.75.75.75 75.75.76.76
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor enterprise\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor enterprise\McIEPlg.dll
Notify: LCredMgr - c:\program files\novell\casa\bin\lcredmgr.dll
Notify: nzrNotifier - nzrNotifier.dll
Notify: TPSvc - TPSvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: ZENworks Application Window: {763370c4-268e-4308-a60c-d8da0342be32} - c:\program files\novell\zenworks\bin\NalShell.dll
LSA: Authentication Packages = msv1_0 nwv1_0
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-3-22 436728]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2010-3-26 65584]
R1 enstart_;enstart_;c:\windows\system32\enstart_.sys [2011-6-17 25472]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2011-3-22 88544]
R2 CITMDRV;CITMDRV;c:\windows\system32\drivers\CITMDRV.SYS [2011-6-17 10752]
R2 enstart;enstart;c:\windows\system32\enstart.exe -s --> c:\windows\system32\enstart.exe -s [?]
R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;c:\program files\ibm\lotus\notes\nsd.exe [2009-9-29 3397000]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-1-5 652872]
R2 McAfee SiteAdvisor Enterprise Service;McAfee SiteAdvisor Enterprise Service;c:\program files\mcafee\siteadvisor enterprise\McSACore.exe [2011-5-12 324928]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2011-1-12 120128]
R2 McShield;McAfee McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-3-22 159320]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2011-1-12 209760]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-3-22 145936]
R2 NetClientSvc;AT&T Global Network Client Service;c:\program files\at&t global network client\NetClientSvc.exe [2009-6-9 336152]
R2 Novell Identity Store;Novell Identity Store;c:\program files\novell\casa\bin\micasad.exe [2010-10-10 245760]
R2 Novell ZENworks Agent Service;Novell ZENworks Agent Service;c:\program files\novell\zenworks\bin\ZenworksWindowsService.exe [2011-2-23 28672]
R2 nzwinvnc;Novell ZENworks Remote Management powered by VNC;c:\program files\novell\zenworks\bin\nzrWinVNC.exe [2011-2-24 2383872]
R2 tlmagent;IBM License Metric Tool and Tivoli Asset Discover Agent;c:\windows\itlm\tlmagent.exe [2011-4-21 573440]
R2 WNTHW;WNTHW;c:\windows\system32\drivers\WNTHW.SYS [2006-1-6 9176]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [2011-2-14 31896]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-1-5 20464]
R3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-3-22 171296]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-3-22 58456]
R3 NetLogSvc;NetLogSvc;c:\progra~1\at&tgl~1\NETLOG~1.EXE [2009-6-9 68888]
S0 vmscsi;vmscsi;c:\windows\system32\drivers\vmscsi.sys [1980-1-1 17968]
S1 mferkdk;VSCore mferkdk;\??\c:\program files\mcafee\virusscan enterprise\mferkdk.sys --> c:\program files\mcafee\virusscan enterprise\mferkdk.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-5 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-5 136176]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-3-22 85152]
S3 vmci;VMware VMCI Bus Driver;c:\windows\system32\drivers\vmci.sys --> c:\windows\system32\drivers\vmci.sys [?]
S3 vmmouse;VMware Pointing Device;c:\windows\system32\drivers\vmmouse.sys --> c:\windows\system32\drivers\vmmouse.sys [?]
S3 vmx_svga;vmx_svga;c:\windows\system32\drivers\vmx_svga.sys --> c:\windows\system32\drivers\vmx_svga.sys [?]
S3 vmxnet;VMware Ethernet Adapter Driver;c:\windows\system32\drivers\vmxnet.sys --> c:\windows\system32\drivers\vmxnet.sys [?]
S3 ZENPreAgent;Novell ZENworks Pre Agent;c:\windows\novell\zenworks\bin\ZENPreAgent.exe [2011-6-17 196608]
.
=============== Created Last 30 ================
.
2012-01-06 02:18:24 -------- d-----w- c:\documents and settings\ttolt\application data\Malwarebytes
2012-01-06 02:17:46 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-01-06 02:17:44 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-06 02:17:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-04 03:51:38 -------- d-----w- c:\windows\itlm_msi_cache
2012-01-02 04:54:33 -------- d-----w- c:\documents and settings\ttolt\local settings\application data\Help
2012-01-02 04:46:40 65536 ----a-r- c:\documents and settings\ttolt\application data\microsoft\installer\{e89d78b8-28f7-412f-8b26-c684739cbbdc}\PalmDesktopShortcut.exe
2012-01-02 04:46:40 65536 ----a-r- c:\documents and settings\ttolt\application data\microsoft\installer\{e89d78b8-28f7-412f-8b26-c684739cbbdc}\ARPPRODUCTICON.exe
2012-01-02 04:46:26 -------- d-----w- c:\program files\palmOne
2011-12-27 02:17:18 1409 ----a-w- c:\windows\QTFont.for
2011-12-23 04:28:25 14664 ----a-w- c:\windows\stinger.sys
2011-12-23 00:33:23 -------- d-----w- c:\program files\Axis Communications
.
==================== Find3M ====================
.
2010-10-11 06:29:34 114688 ----a-w- c:\program files\ad_ff.dll
.
============= FINISH: 21:39:54.78 ===============


_______________________________________________________________________________________________________

Attached Files



BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:09:07 PM

Posted 08 January 2012 - 03:28 AM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • please Do not Attach logs or put in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can help also.
  • Do not run anything while running a fix.
  • Do not run any other tool untill instructed to do so!


Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 DOSummers

DOSummers
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:06:07 PM

Posted 08 January 2012 - 03:48 PM

Hello Gringo,

Thank you very much for your timely response. Prior to your reply, I had read a few of the recent postings on Bleeping Computer and went ahead and downloaded and ran TDSSkiller. Afterwards, Malwarebytes Anti-Malware is no longer blocking out-going sites - as was happening continuously before I made my original post. This was encouraging and I then went and updated from Internet Explorer 7 to IE 8. At this time, my laptop appears to be running normal.

I am really a novice. I am quite worried about potential perosnal information that may have been taken off the laptop such as TurboTax data and log-in information to financial websites that my spouse may made in the days that the PC was infected.

Do you still want me to run combofix? Is there anyway of looking at any of the log sheets to see if any malicious virus may have been present that should force us to make significant changes ot our personal financial accounts?

Thank you kindly for your advice!

DO

#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:09:07 PM

Posted 08 January 2012 - 05:25 PM

Hello


Do you still want me to run combofix? Is there anyway of looking at any of the log sheets to see if any malicious virus may have been present that should force us to make significant changes ot our personal financial accounts?

Yes I do want you to run combofix - lets make sure you removed everything and that nothing will come back

Also as with any major infection it is a good idea to chang your online passwords just to be safe



gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 DOSummers

DOSummers
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:06:07 PM

Posted 08 January 2012 - 07:43 PM

Hello Again, Gringo

I have followed your instructions to the "t" and run Combofix. Before I ran it, I ran Malwarebytes scan one more addtional time and received a hit for "HijackControlPanel.." as a "Registry Value." type.

Early in the Combofix scan I received a message saying that I am infected with "Rootkit ZeroAccess! It has inserted itself in the tcp/ip stack." Here is the log after completion of the Combofix scan.

Thanks a lot, Gringo. Please advise for the next step. The laptop seems to be running well, but I've been surprised before.

Tom
____________________________________________________________________________________________________________________________________

ComboFix 12-01-07.03 - ttolt 01/08/2012 16:54:25.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1540 [GMT -7:00]
Running from: c:\documents and settings\TTolt\Desktop\bleeping computer logs\ComboFix.exe
AV: McAfee VirusScan Enterprise+AntiSpyware Enterprise *Enabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Application Data\Config
c:\documents and settings\Administrator\Application Data\Config\Robocopy.$$$
c:\documents and settings\SPike\Application Data\Config
c:\documents and settings\SPike\Application Data\Config\Robocopy.$$$
c:\documents and settings\TTolt\Application Data\Config
c:\documents and settings\TTolt\Application Data\Config\Robocopy.$$$
c:\windows\$NtUninstallKB33164$
c:\windows\$NtUninstallKB33164$\2037859762
c:\windows\$NtUninstallKB33164$\2042427440\@
c:\windows\$NtUninstallKB33164$\2042427440\bckfg.tmp
c:\windows\$NtUninstallKB33164$\2042427440\cfg.ini
c:\windows\$NtUninstallKB33164$\2042427440\Desktop.ini
c:\windows\$NtUninstallKB33164$\2042427440\keywords
c:\windows\$NtUninstallKB33164$\2042427440\kwrd.dll
c:\windows\$NtUninstallKB33164$\2042427440\L\whqmbfon
c:\windows\$NtUninstallKB33164$\2042427440\lsflt7.ver
c:\windows\$NtUninstallKB33164$\2042427440\U\00000001.@
c:\windows\$NtUninstallKB33164$\2042427440\U\00000002.@
c:\windows\$NtUninstallKB33164$\2042427440\U\00000004.@
c:\windows\$NtUninstallKB33164$\2042427440\U\80000000.@
c:\windows\$NtUninstallKB33164$\2042427440\U\80000004.@
c:\windows\$NtUninstallKB33164$\2042427440\U\80000032.@
c:\windows\EventSystem.log
c:\windows\sc.exe
c:\windows\system32\NWGina.dll
c:\windows\XSxS
.
.
((((((((((((((((((((((((( Files Created from 2011-12-09 to 2012-01-09 )))))))))))))))))))))))))))))))
.
.
2012-01-07 04:44 . 2012-01-07 04:44 -------- d-sh--w- c:\documents and settings\TTolt\IECompatCache
2012-01-07 04:41 . 2012-01-07 04:41 -------- d-sh--w- c:\documents and settings\TTolt\PrivacIE
2012-01-07 04:39 . 2012-01-07 04:39 -------- d-sh--w- c:\documents and settings\TTolt\IETldCache
2012-01-07 04:38 . 2012-01-07 04:38 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-01-07 04:34 . 2012-01-07 04:36 -------- dc-h--w- c:\windows\ie8
2012-01-06 04:20 . 2012-01-06 04:20 1324 ----a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\d3d9caps.tmp
2012-01-06 02:18 . 2012-01-06 02:18 -------- d-----w- c:\documents and settings\TTolt\Application Data\Malwarebytes
2012-01-06 02:17 . 2012-01-06 02:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-01-06 02:17 . 2011-12-10 22:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-06 02:17 . 2012-01-06 02:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-04 03:51 . 2012-01-04 03:51 -------- d-----w- c:\windows\itlm_msi_cache
2012-01-02 04:54 . 2012-01-02 04:54 -------- d-----w- c:\documents and settings\TTolt\Local Settings\Application Data\Help
2012-01-02 04:46 . 2012-01-02 04:46 65536 ----a-r- c:\documents and settings\TTolt\Application Data\Microsoft\Installer\{E89D78B8-28F7-412F-8B26-C684739CBBDC}\PalmDesktopShortcut.exe
2012-01-02 04:46 . 2012-01-02 04:46 65536 ----a-r- c:\documents and settings\TTolt\Application Data\Microsoft\Installer\{E89D78B8-28F7-412F-8B26-C684739CBBDC}\ARPPRODUCTICON.exe
2012-01-02 04:46 . 2012-01-02 05:01 -------- d-----w- c:\program files\palmOne
2011-12-27 02:17 . 2011-12-27 02:17 1409 ----a-w- c:\windows\QTFont.for
2011-12-23 04:28 . 2012-01-04 03:54 14664 ----a-w- c:\windows\stinger.sys
2011-12-23 00:33 . 2011-12-23 00:33 -------- d-----w- c:\program files\Axis Communications
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-07 02:29 . 2004-08-05 00:00 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
2010-10-11 06:29 . 2010-10-11 06:29 114688 ----a-w- c:\program files\ad_ff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WebCam-Disable"="c:\windows\util\nircmd.exe" [2010-02-21 31744]
"NetSP - restore settings on power failure"="c:\program files\AT&T Global Network Client\NetSP.exe" [2009-06-09 53528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGNS_Config"="nircmd execmd" [X]
"UserLogin"="nircmd.exe execmd" [X]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 28672]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"Pistolstar_SSO"="c:\program files\Pistolstar\Password Power Client\APOSSO.exe" [2010-01-07 32768]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2011-01-12 161088]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2011-01-13 215360]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-21 13594624]
"nwiz"="nwiz.exe" [2008-11-21 1657376]
"NVHotkey"="nvHotkey.dll" [2008-11-21 90112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-21 86016]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"ZenNotifyIcon"="c:\program files\Novell\Zenworks\bin\ZenNotifyIcon.exe" [2011-02-24 147456]
"NalView"="c:\program files\Novell\Zenworks\bin\NALVIEW.exe" [2011-02-24 54784]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-03-26 103848]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-15 2565520]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-03-03 155648]
"MapDrive"="c:\windows\Util\MapDrives.exe" [2011-11-04 277697]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-25 460872]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"WebCam-Disable"="c:\windows\util\nircmd.exe" [2010-02-21 31744]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Printkey2000.lnk - c:\program files\PrintKey2000\Printkey2000.exe [2005-3-4 869376]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"CompatibleRUPSecurity"= 1 (0x1)
"LogonType"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
"NoPublishingWizard"= 1 (0x1)
"NoWebServices"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{763370C4-268E-4308-A60C-D8DA0342BE32}"= "c:\program files\Novell\ZENworks\bin\NalShell.dll" [2011-02-24 933888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LCredMgr]
2010-10-11 06:29 61440 ----a-w- c:\program files\Novell\CASA\bin\lcredmgr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nzrNotifier]
2011-02-25 03:51 69632 ----a-w- c:\windows\system32\nzrNotifier.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\System32\\DPMW32.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\AT&T Global Network Client\\NetClient.exe"=
"c:\\Program Files\\Novell\\ZENworks\\bin\\nzrWinVNC.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7628:TCP"= 7628:TCP:ZENworks TCP - Port 7628
"7628:UDP"= 7628:UDP:ZENworks UDP - Port 7628
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 vmscsi;vmscsi;c:\windows\system32\drivers\vmscsi.sys [1/1/1980 5:00 AM 17968]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [3/26/2010 2:51 AM 65584]
R1 enstart_;enstart_;c:\windows\system32\enstart_.sys [6/17/2011 6:04 AM 25472]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [3/22/2011 7:53 AM 88544]
R2 CITMDRV;CITMDRV;c:\windows\system32\drivers\CITMDRV.SYS [6/17/2011 6:04 AM 10752]
R2 enstart;enstart;c:\windows\system32\enstart.exe -s --> c:\windows\system32\enstart.exe -s [?]
R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;c:\program files\IBM\Lotus\Notes\nsd.exe [9/29/2009 8:29 AM 3397000]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/5/2012 7:17 PM 652872]
R2 McAfee SiteAdvisor Enterprise Service;McAfee SiteAdvisor Enterprise Service;c:\program files\McAfee\SiteAdvisor Enterprise\McSACore.exe [5/12/2011 11:48 AM 324928]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [3/22/2011 7:53 AM 145936]
R2 NetClientSvc;AT&T Global Network Client Service;c:\program files\AT&T Global Network Client\NetClientSvc.exe [6/9/2009 2:30 PM 336152]
R2 Novell Identity Store;Novell Identity Store;c:\program files\Novell\CASA\bin\micasad.exe [10/10/2010 11:29 PM 245760]
R2 Novell ZENworks Agent Service;Novell ZENworks Agent Service;c:\program files\Novell\ZENworks\bin\ZenworksWindowsService.exe [2/23/2011 7:55 PM 28672]
R2 nzwinvnc;Novell ZENworks Remote Management powered by VNC;c:\program files\Novell\ZENworks\bin\nzrWinVNC.exe [2/24/2011 8:50 PM 2383872]
R2 tlmagent;IBM License Metric Tool and Tivoli Asset Discover Agent;c:\windows\itlm\tlmagent.exe [4/21/2011 8:04 PM 573440]
R2 WNTHW;WNTHW;c:\windows\system32\drivers\WNTHW.SYS [1/6/2006 2:37 AM 9176]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [2/14/2011 7:48 AM 31896]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [1/5/2012 7:17 PM 20464]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/5/2011 3:51 PM 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/5/2011 3:51 PM 136176]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [3/22/2011 7:53 AM 85152]
S3 NetLogSvc;NetLogSvc;c:\progra~1\AT&TGL~1\NETLOG~1.EXE [6/9/2009 2:30 PM 68888]
S3 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys --> c:\windows\system32\DRIVERS\vmci.sys [?]
S3 vmmouse;VMware Pointing Device;c:\windows\system32\DRIVERS\vmmouse.sys --> c:\windows\system32\DRIVERS\vmmouse.sys [?]
S3 vmx_svga;vmx_svga;c:\windows\system32\DRIVERS\vmx_svga.sys --> c:\windows\system32\DRIVERS\vmx_svga.sys [?]
S3 vmxnet;VMware Ethernet Adapter Driver;c:\windows\system32\DRIVERS\vmxnet.sys --> c:\windows\system32\DRIVERS\vmxnet.sys [?]
S3 ZENPreAgent;Novell ZENworks Pre Agent;c:\windows\novell\zenworks\bin\ZENPreAgent.exe [6/17/2011 6:09 AM 196608]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
*Deregistered* - uphcleanhlp
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-05 22:51]
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-05 22:51]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://intranet.wlgore.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.wlgore.com;127.0.0.1;localhost;157.204.*;32.85.*;192.168.*;<local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://128.146.233.169/activex/AMC.cab
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Adobe Reader Synchronizer - c:\program files\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe
HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
HKLM-Run-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe
Notify-TPSvc - TPSvc.dll
SafeBoot-37079337.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-08 17:05
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
c:\windows\system32\enstart.exe [1820] 0x8A597B28
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1276)
c:\windows\system32\nzrNotifier.dll
c:\program files\Novell\ZENworks\bin\c-extlogger.dll
c:\windows\system32\NETWIN32.DLL
.
- - - - - - - > 'explorer.exe'(4872)
c:\windows\system32\NETWIN32.DLL
c:\program files\McAfee\Common Framework\McTrayLegacySupportPlugin.dll
c:\program files\McAfee\Common Framework\McTrayInterfaceLib.dll
c:\program files\McAfee\Common Framework\McAfeeWin32GUISupportDLL.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\McAfee\VirusScan Enterprise\mfeann.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\IBM\Lotus\Notes\ntmulti.exe
c:\program files\AT&T Global Network Client\netcfgsvr.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\StacSV.exe
c:\program files\UPHClean\uphclean.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Citrix\ICA Client\ssonsvr.exe
c:\windows\system32\NWTRAY.EXE
c:\program files\McAfee\Common Framework\McTray.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\Citrix\ICA Client\WFCRUN32.EXE
c:\program files\Novell\ZENworks\bin\ZenUserDaemon.exe
c:\program files\Novell\ZENworks\bin\handlers\runscriptenf.exe
.
**************************************************************************
.
Completion time: 2012-01-08 17:08:31 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-09 00:08
.
Pre-Run: 38,801,887,232 bytes free
Post-Run: 39,715,315,712 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - F9EC0B0078CBCAC86E6D64ACE44B0A4D

#6 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:09:07 PM

Posted 08 January 2012 - 09:31 PM

Greetings

Good That cleaned up some bad guys but I see some other stuff that we need to go after, so I want you to run this custom script for me.

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

ClearJavaCache::


Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#7 DOSummers

DOSummers
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:06:07 PM

Posted 08 January 2012 - 11:50 PM

Hi Gringo,

Here is the Combofix log report after I reran it with your added script. I didn't have any problems or extra messages running Combofix this time around. Laptop seems to be running fine, but I haven't done anything significant other than answering your reply. Let me know how the log looks and if there are any other surprise steps! You've been a super help - obviously! I guess my concern I stated earlier was if I should worry about identity theft type activity because the Malewarebyteshowed all these outgoing attempts to contact malicious websites outgoing from the PC (an this was likely going on for days before I caught it.). We have sensitive personal information that I don't know if it was at risk. Any more advice would be appreciated.

D.O.

________________________________________________________________________________________________________________________________________________________________________

ComboFix 12-01-07.04 - TTolt 01/08/2012 21:26:24.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1358 [GMT -7:00]
Running from: c:\documents and settings\TTolt\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\TTolt\Desktop\CFScript.txt
AV: McAfee VirusScan Enterprise+AntiSpyware Enterprise *Disabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
.
((((((((((((((((((((((((( Files Created from 2011-12-09 to 2012-01-09 )))))))))))))))))))))))))))))))
.
.
2012-01-09 02:33 . 2012-01-09 02:33 -------- d-----w- C:\Old Job Stuff
2012-01-09 02:04 . 2012-01-09 04:16 -------- d-----w- C:\Family Photos-Movies IV
2012-01-09 02:04 . 2012-01-09 03:55 -------- d-----w- C:\Family Photos-Movies III
2012-01-07 04:44 . 2012-01-07 04:44 -------- d-sh--w- c:\documents and settings\TTolt\IECompatCache
2012-01-07 04:41 . 2012-01-07 04:41 -------- d-sh--w- c:\documents and settings\TTolt\PrivacIE
2012-01-07 04:39 . 2012-01-07 04:39 -------- d-sh--w- c:\documents and settings\TTolt\IETldCache
2012-01-07 04:38 . 2012-01-07 04:38 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-01-07 04:34 . 2012-01-07 04:36 -------- dc-h--w- c:\windows\ie8
2012-01-06 04:20 . 2012-01-06 04:20 1324 ----a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\d3d9caps.tmp
2012-01-06 02:18 . 2012-01-06 02:18 -------- d-----w- c:\documents and settings\TTolt\Application Data\Malwarebytes
2012-01-06 02:17 . 2012-01-06 02:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-01-06 02:17 . 2011-12-10 22:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-06 02:17 . 2012-01-06 02:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-04 03:51 . 2012-01-04 03:51 -------- d-----w- c:\windows\itlm_msi_cache
2012-01-02 04:54 . 2012-01-02 04:54 -------- d-----w- c:\documents and settings\TTolt\Local Settings\Application Data\Help
2012-01-02 04:46 . 2012-01-02 04:46 65536 ----a-r- c:\documents and settings\TTolt\Application Data\Microsoft\Installer\{E89D78B8-28F7-412F-8B26-C684739CBBDC}\PalmDesktopShortcut.exe
2012-01-02 04:46 . 2012-01-02 04:46 65536 ----a-r- c:\documents and settings\TTolt\Application Data\Microsoft\Installer\{E89D78B8-28F7-412F-8B26-C684739CBBDC}\ARPPRODUCTICON.exe
2012-01-02 04:46 . 2012-01-02 05:01 -------- d-----w- c:\program files\palmOne
2011-12-27 02:17 . 2011-12-27 02:17 1409 ----a-w- c:\windows\QTFont.for
2011-12-23 04:28 . 2012-01-04 03:54 14664 ----a-w- c:\windows\stinger.sys
2011-12-23 00:33 . 2011-12-23 00:33 -------- d-----w- c:\program files\Axis Communications
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-07 02:29 . 2004-08-05 00:00 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
2010-10-11 06:29 . 2010-10-11 06:29 114688 ----a-w- c:\program files\ad_ff.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-09_00.05.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-09 00:56 . 2012-01-09 00:56 16384 c:\windows\Temp\Perflib_Perfdata_ae4.dat
+ 2012-01-09 04:30 . 2012-01-09 04:30 16384 c:\windows\Temp\Perflib_Perfdata_1050.dat
+ 2004-08-05 00:00 . 2012-01-09 00:08 72582 c:\windows\system32\perfc009.dat
- 2004-08-05 00:00 . 2012-01-09 00:06 72582 c:\windows\system32\perfc009.dat
+ 2004-08-05 00:00 . 2012-01-09 00:08 443482 c:\windows\system32\perfh009.dat
- 2004-08-05 00:00 . 2012-01-09 00:06 443482 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WebCam-Disable"="c:\windows\util\nircmd.exe" [2010-02-21 31744]
"NetSP - restore settings on power failure"="c:\program files\AT&T Global Network Client\NetSP.exe" [2009-06-09 53528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGNS_Config"="nircmd execmd" [X]
"UserLogin"="nircmd.exe execmd" [X]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 28672]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"Pistolstar_SSO"="c:\program files\Pistolstar\Password Power Client\APOSSO.exe" [2010-01-07 32768]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2011-01-12 161088]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2011-01-13 215360]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-21 13594624]
"nwiz"="nwiz.exe" [2008-11-21 1657376]
"NVHotkey"="nvHotkey.dll" [2008-11-21 90112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-21 86016]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"ZenNotifyIcon"="c:\program files\Novell\Zenworks\bin\ZenNotifyIcon.exe" [2011-02-24 147456]
"NalView"="c:\program files\Novell\Zenworks\bin\NALVIEW.exe" [2011-02-24 54784]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-03-26 103848]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-03-15 2565520]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-03-03 155648]
"MapDrive"="c:\windows\Util\MapDrives.exe" [2011-11-04 277697]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-25 460872]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"WebCam-Disable"="c:\windows\util\nircmd.exe" [2010-02-21 31744]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Printkey2000.lnk - c:\program files\PrintKey2000\Printkey2000.exe [2005-3-4 869376]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"CompatibleRUPSecurity"= 1 (0x1)
"LogonType"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
"NoPublishingWizard"= 1 (0x1)
"NoWebServices"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"DisablePersonalDirChange"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{763370C4-268E-4308-A60C-D8DA0342BE32}"= "c:\program files\Novell\ZENworks\bin\NalShell.dll" [2011-02-24 933888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LCredMgr]
2010-10-11 06:29 61440 ----a-w- c:\program files\Novell\CASA\bin\lcredmgr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nzrNotifier]
2011-02-25 03:51 69632 ----a-w- c:\windows\system32\nzrNotifier.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\System32\\DPMW32.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\AT&T Global Network Client\\NetClient.exe"=
"c:\\Program Files\\Novell\\ZENworks\\bin\\nzrWinVNC.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7628:TCP"= 7628:TCP:ZENworks TCP - Port 7628
"7628:UDP"= 7628:UDP:ZENworks UDP - Port 7628
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 vmscsi;vmscsi;c:\windows\system32\drivers\vmscsi.sys [1/1/1980 5:00 AM 17968]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [3/26/2010 2:51 AM 65584]
R1 enstart_;enstart_;c:\windows\system32\enstart_.sys [6/17/2011 6:04 AM 25472]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [3/22/2011 7:53 AM 88544]
R2 CITMDRV;CITMDRV;c:\windows\system32\drivers\CITMDRV.SYS [6/17/2011 6:04 AM 10752]
R2 enstart;enstart;c:\windows\system32\enstart.exe -s --> c:\windows\system32\enstart.exe -s [?]
R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;c:\program files\IBM\Lotus\Notes\nsd.exe [9/29/2009 8:29 AM 3397000]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/5/2012 7:17 PM 652872]
R2 McAfee SiteAdvisor Enterprise Service;McAfee SiteAdvisor Enterprise Service;c:\program files\McAfee\SiteAdvisor Enterprise\McSACore.exe [5/12/2011 11:48 AM 324928]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [3/22/2011 7:53 AM 145936]
R2 NetClientSvc;AT&T Global Network Client Service;c:\program files\AT&T Global Network Client\NetClientSvc.exe [6/9/2009 2:30 PM 336152]
R2 Novell Identity Store;Novell Identity Store;c:\program files\Novell\CASA\bin\micasad.exe [10/10/2010 11:29 PM 245760]
R2 Novell ZENworks Agent Service;Novell ZENworks Agent Service;c:\program files\Novell\ZENworks\bin\ZenworksWindowsService.exe [2/23/2011 7:55 PM 28672]
R2 nzwinvnc;Novell ZENworks Remote Management powered by VNC;c:\program files\Novell\ZENworks\bin\nzrWinVNC.exe [2/24/2011 8:50 PM 2383872]
R2 WNTHW;WNTHW;c:\windows\system32\drivers\WNTHW.SYS [1/6/2006 2:37 AM 9176]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [2/14/2011 7:48 AM 31896]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [1/5/2012 7:17 PM 20464]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/5/2011 3:51 PM 136176]
S2 tlmagent;IBM License Metric Tool and Tivoli Asset Discover Agent;c:\windows\itlm\tlmagent.exe [4/21/2011 8:04 PM 573440]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/5/2011 3:51 PM 136176]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [3/22/2011 7:53 AM 85152]
S3 NetLogSvc;NetLogSvc;c:\progra~1\AT&TGL~1\NETLOG~1.EXE [6/9/2009 2:30 PM 68888]
S3 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys --> c:\windows\system32\DRIVERS\vmci.sys [?]
S3 vmmouse;VMware Pointing Device;c:\windows\system32\DRIVERS\vmmouse.sys --> c:\windows\system32\DRIVERS\vmmouse.sys [?]
S3 vmx_svga;vmx_svga;c:\windows\system32\DRIVERS\vmx_svga.sys --> c:\windows\system32\DRIVERS\vmx_svga.sys [?]
S3 vmxnet;VMware Ethernet Adapter Driver;c:\windows\system32\DRIVERS\vmxnet.sys --> c:\windows\system32\DRIVERS\vmxnet.sys [?]
S3 ZENPreAgent;Novell ZENworks Pre Agent;c:\windows\novell\zenworks\bin\ZENPreAgent.exe [6/17/2011 6:09 AM 196608]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
*Deregistered* - uphcleanhlp
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-05 22:51]
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-05 22:51]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://intranet.wlgore.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.wlgore.com;127.0.0.1;localhost;157.204.*;32.85.*;192.168.*;<local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://128.146.233.169/activex/AMC.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-08 21:31
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
c:\windows\system32\enstart.exe [1820] 0x8A597B28
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1276)
c:\windows\system32\nzrNotifier.dll
c:\program files\Novell\ZENworks\bin\c-extlogger.dll
c:\windows\system32\NETWIN32.DLL
.
- - - - - - - > 'explorer.exe'(4216)
c:\windows\system32\NETWIN32.DLL
c:\program files\McAfee\Common Framework\McTrayLegacySupportPlugin.dll
c:\program files\McAfee\Common Framework\McTrayInterfaceLib.dll
c:\program files\McAfee\Common Framework\McAfeeWin32GUISupportDLL.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
Completion time: 2012-01-08 21:32:35
ComboFix-quarantined-files.txt 2012-01-09 04:32
.
Pre-Run: 25,174,511,616 bytes free
Post-Run: 25,297,342,464 bytes free
.
- - End Of File - - F86AA6F055570846F348CEF2B6015A3D

#8 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:09:07 PM

Posted 09 January 2012 - 12:08 AM

Hello

as with any major infection I would change all online passwords just to be safe and keep an eye on things just tyo be sure


Please print out these instructions, or copy them to a Notepad file. It will make it easier for you to follow the instructions and complete all of the necessary steps..

uninstall some programs

NOTE** Because of the cleanup process some of the programs I have listed may not be in add/remove anymore this is fine just move to the next item on the list.

1. click on start
2. then go to settings
3. after that you need control panel
4. look for the icon add/remove programs
click on the following programs

Adobe Reader
Java™ 6 Update 16


and click on remove

Update Adobe Reader

Recently there have been vulnerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version.

You can download it from http://www.adobe.com/products/acrobat/readstep2.html
After installing the latest Adobe Reader, uninstall all previous versions.
If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

If you don't like Adobe Reader (53 MB), you can download Foxit PDF Reader(7 MB) from here. It's a much smaller file to download and uses a lot less resources than Adobe Reader.

Note: When installing FoxitReader, be careful not to install anything to do with AskBar.
[/list]

Install Java:

Please go here to install Java

  • click on the Free Java Download Button
  • click on Agree and start Free download
  • click on Run
  • click on run again
  • click on install
  • when install is complete click on close

TFC(Temp File Cleaner):

  • Please download TFC to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • If prompted, click "Yes" to reboot.
Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.

: Malwarebytes' Anti-Malware :

  • I would like you to rerun MBAM
  • Double-click mbam icon
  • go to the update tab at the top
  • click on check for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
  • If you accidentally close it, the log file is saved here and will be named like this:
  • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Download HijackThis

If you have any problems running Hijackthis see NOTE** below (Host file not read, blank notepad ...)

  • Go Here to download HijackThis Installer
  • Save HijackThis Installer to your desktop.
  • Double-click on the HijackThis Installer icon on your desktop. (Vista and Win 7 right click and run as admin)
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed it will launch Hijackthis.
  • Click on the Do a system scan and save a log file button. It will scan and the log should open in notepad.
  • Click on Edit > Select All then click on Edit > Copy to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT use the Analyze This button its findings are dangerous if misinterpreted.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

NOTE**
sometimes we have to run it like this To run HijackThis as an administrator, right-click HijackThis.exe
(located: C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe)<--32bit
(located: C:\Program Files(86)\Trend Micro\HiJackThis\HiJackThis.exe)<--64bit
and select to run as administrator

"information and logs"

  • In your next post I need the following

  • Log From MBAM
  • report from Hijackthis
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#9 DOSummers

DOSummers
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:06:07 PM

Posted 11 January 2012 - 10:35 PM

Hi Gringo,

Sorry! just back after a three day hiatus (busy with work)....I followed your last instructions except that - for some unknown reason - I wasn't able to run Temporary File Cleaner from oldtimer. Instead, I just deleted my temporary Internet files before running MWAW and HijackThis. Today an IT person at work suggested that I they use CCleaner so I downloaded it and ran it as well. However, the two requested log files from MWAW and HijackThis were made PRIOR to running CCLeaner. Let me know whta's next. You are a great help and teacher!

D.O.

______________________________________________________________________________

_____________________________________________________________________________________
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:17:07 PM, on 1/10/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Novell\CASA\bin\micasad.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Novell\ZENworks\bin\ZenworksWindowsService.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\IBM\Lotus\Notes\nsd.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
C:\Program Files\IBM\Lotus\Notes\ntmulti.exe
C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
C:\Program Files\AT&T Global Network Client\NetClientSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Novell\ZENworks\bin\nzrWinVNC.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\system32\StacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Novell\ZENworks\bin\handlers\runscriptenf.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Novell\Zenworks\bin\ZenNotifyIcon.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Citrix\ICA Client\WFCRUN32.EXE
C:\WINDOWS\Util\MapDrives.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PrintKey2000\Printkey2000.exe
C:\Program Files\Novell\ZENworks\bin\ZenUserDaemon.exe
C:\PROGRA~1\AT&TGL~1\NETLOG~1.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\util\nircmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet.wlgore.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.wlgore.com;127.0.0.1;localhost;157.204.*;32.85.*;192.168.*;<local>
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110322105323.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Pistolstar_SSO] "C:\Program Files\Pistolstar\Password Power Client\APOSSO.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [AGNS_Config] nircmd execmd C:\WINDOWS\ATT_Config.cmd
O4 - HKLM\..\Run: [ZenNotifyIcon] C:\Program Files\Novell\Zenworks\bin\ZenNotifyIcon.exe
O4 - HKLM\..\Run: [NalView] C:\Program Files\Novell\Zenworks\bin\NALVIEW.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [UserLogin] nircmd.exe execmd "C:\Program Files\Novell\ZENworks\bin\zac.exe" bln UserLogin-USW
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MapDrive] C:\WINDOWS\Util\MapDrives.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [WebCam-Disable] C:\Windows\util\nircmd.exe execmd C:\Windows\util\devcon.exe disable USB\CLASS_0E
O4 - HKCU\..\Run: [NetSP - restore settings on power failure] "C:\Program Files\AT&T Global Network Client\NetSP.exe" -show
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [WebCam-Disable] C:\Windows\util\nircmd.exe execmd C:\Windows\util\devcon.exe disable USB\CLASS_0E (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [WebCam-Disable] C:\Windows\util\nircmd.exe execmd C:\Windows\util\devcon.exe disable USB\CLASS_0E (User 'Default user')
O4 - Global Startup: Printkey2000.lnk = C:\Program Files\PrintKey2000\Printkey2000.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://128.146.233.169/activex/AMC.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wlgore.com
O17 - HKLM\Software\..\Telephony: DomainName = wlgore.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wlgore.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = wlgore.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wlgore.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = wlgore.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = wlgore.com
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O20 - Winlogon Notify: LCredMgr - C:\Program Files\Novell\CASA\bin\lcredmgr.dll
O20 - Winlogon Notify: nzrNotifier - nzrNotifier.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: enstart - Unknown owner - C:\WINDOWS\system32\enstart.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lotus Notes Diagnostics - IBM - C:\Program Files\IBM\Lotus\Notes\nsd.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee SiteAdvisor Enterprise Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files\IBM\Lotus\Notes\ntmulti.exe
O23 - Service: AT&T Network Configuration Service (netcfgsvr) - AT&T - C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
O23 - Service: AT&T Global Network Client Service (NetClientSvc) - AT&T - C:\Program Files\AT&T Global Network Client\NetClientSvc.exe
O23 - Service: NetLogSvc - AT&T - C:\PROGRA~1\AT&TGL~1\NETLOG~1.EXE
O23 - Service: Novell Identity Store - Novell, Inc - C:\Program Files\Novell\CASA\bin\micasad.exe
O23 - Service: Novell ZENworks Agent Service - Novell, Inc. - C:\Program Files\Novell\ZENworks\bin\ZenworksWindowsService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Novell ZENworks Remote Management powered by VNC (nzwinvnc) - Novell, Inc. - C:\Program Files\Novell\ZENworks\bin\nzrWinVNC.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: IBM License Metric Tool and Tivoli Asset Discover Agent (tlmagent) - Unknown owner - C:\WINDOWS\itlm\tlmagent.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: Novell ZENworks Pre Agent (ZENPreAgent) - Unknown owner - C:\WINDOWS\novell\zenworks\bin\ZENPreAgent.exe

--
End of file - 13772 bytes

________________________________________________________________________________________________________________________

Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.11.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
TTolt :: USW-4CYKTG1 [administrator]

Protection: Enabled
1/10/2012 10:07:02 PM
mbam-log-2012-01-10 (22-07-02).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 199266
Time elapsed: 3 minute(s), 12 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

________________________________________________



_______________________________________________________________________

#10 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:09:07 PM

Posted 11 January 2012 - 11:43 PM

Greetings

These logs are looking very good, we are almost done!!! Just one more scan to go.

:Remove unneeded start-up entries:

This part of the fix is purely optional
These are programs that start up when you turn on your computer but don't need to be, any of these programs you can click on their icons (or start from the control panel) and start the program when you need it. By stopping these programs you will boot up faster and your computer will work faster.

If you have any problems running Hijackthis see NOTE** below (Host file not read, blank notepad ...)

  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    • O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
      O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
      O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
      O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
      O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
      O4 - Global Startup: Printkey2000.lnk = C:\Program Files\PrintKey2000\Printkey2000.exe
  • Close all open windows and browsers/email, etc...
  • Click on the "Fix Checked" button
  • When completed, close the application.

    NOTE**You can research each of those lines >here< and see if you want to keep them or not
    just copy the name between the brackets and paste into the search space
    O4 - HKLM\..\Run: [IntelliPoint]


NOTE**
sometimes we have to run it like this To run HijackThis as an administrator, right-click HijackThis.exe
(located: C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe)<--32bit
(located: C:\Program Files(86)\Trend Micro\HiJackThis\HiJackThis.exe)<--64bit
and select to run as administrator

Eset Online Scanner

**Note** You will need to use Internet explorer for this scan - Vista and win 7 right click on IE shortcut and run as admin

Go Eset web page to run an online scanner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • click on the ESET Online Scanner button
  • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
  • When asked, allow the ActiveX control to install
    • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options
    Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Click on copy to clipboard and paste the results here in this topic
  • you may also find here C:\Program Files\Eset\Eset Online Scanner\log.txt
Copy and paste that log as a reply to this topic

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#11 DOSummers

DOSummers
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:06:07 PM

Posted 12 January 2012 - 12:54 AM

Hi Gringo,

Something went terribly wrong tonight. My whole personnel profile settings for sign in have been reset and I cannot find any of my "My Documents" folders and files - even when I look under my user name under C:\documents and settings. Please don't tell me that I lost all of my files stored in My docs and desktop. Is this really possible?? Was it this CCleaner software used incorrectly?

A bit panicky now.

D.O.

#12 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:09:07 PM

Posted 12 January 2012 - 01:09 AM

Hello


when you ran CCleaner did you just run the temp file cleaner or did you also run the registry cleaner


try to run this to see if they are hiddn - http://download.bleepingcomputer.com/grinler/unhide.exe


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#13 DOSummers

DOSummers
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:06:07 PM

Posted 12 January 2012 - 12:24 PM

Hi Gringo,

Still missing those "My Document" folders after running the unhide.exe program. I think I ran the wrong version of CCleaner. There was a Network Enterprise version that I downloaded and ran and then I followed that with the personal PC version. Things were going so well; now it seems like I accidentally reconfigured the entire windows. Strange.

D.O.

#14 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:09:07 PM

Posted 12 January 2012 - 02:18 PM

Download and run OTL

Download OTL by Old Timer and save it to your Desktop.
  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Under the Custom Scan box paste this in

    %TEMP%\smtmp\*.* /s

  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened and the that I need posted back here
    • Extra.txt <-- Will be minimized - save this one on your desktop in case I ask for it later
  • Please post the contents of OTListIt.txt in your next reply.


information and logs:

  • In your next post I need the following

  • .logs from OTL
  • let me know of any problems you may have had

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#15 DOSummers

DOSummers
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:06:07 PM

Posted 12 January 2012 - 09:03 PM

Hi Gringo,

Here is the first log from Oldtimer. There were no problems encountered. Thansk for your continued support.

DO



OTL logfile created on: 1/12/2012 6:49:39 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\TTolt.USE\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.17 Gb Available Physical Memory | 58.68% Memory free
3.84 Gb Paging File | 2.89 Gb Available in Paging File | 75.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 41.68 Gb Free Space | 55.92% Space Free | Partition Type: NTFS

Computer Name: USW-4CYKTG1 | User Name: TTolt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\TTolt.USE\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\util\MapDrives.exe ()
PRC - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\Novell\ZENworks\bin\handlers\runscriptenf.exe (Novell, Inc.)
PRC - C:\Program Files\Novell\ZENworks\bin\nzrWinVNC.exe (Novell, Inc.)
PRC - C:\Program Files\Novell\ZENworks\bin\ZenNotifyIcon.exe (Novell, Inc.)
PRC - C:\Program Files\Novell\ZENworks\bin\ZenworksWindowsService.exe (Novell, Inc.)
PRC - C:\Program Files\Novell\ZENworks\bin\ZenUserDaemon.exe (Novell, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\Novell\CASA\bin\micasad.exe (Novell, Inc)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\ssonsvr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\IBM\Lotus\Notes\ntmulti.exe (IBM Corp)
PRC - C:\Program Files\IBM\Lotus\Notes\nsd.exe (IBM)
PRC - C:\Program Files\AT&T Global Network Client\NetLogSvc.exe (AT&T)
PRC - C:\Program Files\AT&T Global Network Client\netcfgsvr.exe (AT&T)
PRC - C:\Program Files\AT&T Global Network Client\NetClientSvc.exe (AT&T)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\nwtray.exe (Novell, Inc.)
PRC - C:\Program Files\PrintKey2000\Printkey2000.exe (Fred's Software)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\util\MapDrives.exe ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\8e97e27ae5070d7c05eeeaa7539d1727\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\282ec4253b02b4398ffb7cc5bea02181\CustomMarshalers.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\350bea50fa9cb415e03568275e77f3dc\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\c5229fa6848f7de73b06d511f8251a95\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\023858003bae1015c0bd0b06a60952e5\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\e8f78cf6cfd3eb37424df907f2caf5b9\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\172602e5d923bb1050bba65e019163bb\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\3b8c3cbee7288bd60caf2ad4e072713d\System.DirectoryServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\5c1627dbffd9692b596e9379b6cdf0ad\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\66e5fdf7cdbfbf88ddf2ef46463d09d1\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\44cd60d4c7e4e59e08ead8ab07ac619c\System.Security.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\ff6b98d441c510546f2bd01f285271fc\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\fc173f01a6944170e76152dfb27b8098\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\5f7d079baf6ecc9695ce96b9f06231ea\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\04f2a7167f8f850e5454d9d529255784\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data.SQLite\1.0.61.0__db937bc2d44ff139\System.Data.SQLite.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\log4net\1.2.10.0__1b44e1d426115821\log4net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.Reporter\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.Reporter.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Map.WindowsFirewallUtilities\5.0.136.0__7ce6deabcb36a8ea\Intuit.Spc.Map.WindowsFirewallUtilities.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Api.Net\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Api.Net.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract\1.0.0.0__540d4816ead86321\Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Core\3.1.26.0__540d4816ead86321\Intuit.Spc.Esd.Core.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.DataAccess\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.DataAccess.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.Common\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.Common.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Intuit.Spc.Esd.Client.BusinessLogic\3.1.31.0__540d4816ead86321\Intuit.Spc.Esd.Client.BusinessLogic.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Novell.Casa.Client.Auth\1.7.0.0__ed0eb71059ea593b\Novell.Casa.Client.Auth.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\XmlSerializers\GenericActions.XmlSerializers.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\XmlSerializers\InventoryManager.XmlSerializers.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\XmlSerializers\Novell.Zenworks.PolicyManager.XmlSerializers.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\XmlSerializers\AppModule.XmlSerializers.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\XmlSerializers\ContainmentRefresh.XmlSerializers.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\XmlSerializers\requirements.XmlSerializers.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\XmlSerializers\ActionManager.XmlSerializers.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\XmlSerializers\RegistrationModule.XmlSerializers.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\XmlSerializers\zmd.XmlSerializers.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\XmlSerializers\Localizer.XmlSerializers.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\xmltok.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\xmlparse.dll ()
MOD - C:\Program Files\Novell\ZENworks\bin\sqlite3.dll ()
MOD - C:\Program Files\McAfee\Common Framework\boost_thread-vc80-mt-1_32.dll ()
MOD - C:\WINDOWS\system32\nwshlxnt.dll ()
MOD - C:\WINDOWS\system32\nls\ENGLISH\nwshlxnr.dll ()
MOD - C:\WINDOWS\system32\preflib.dll ()
MOD - C:\WINDOWS\system32\bcm1xsup.dll ()
MOD - C:\Program Files\McAfee\Common Framework\ccme_base.dll ()
MOD - C:\Program Files\McAfee\Common Framework\cryptocme2.dll ()
MOD - C:\WINDOWS\system32\DLAAPI_W.DLL ()


========== Win32 Services (SafeList) ==========

SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (ZENPreAgent) -- C:\WINDOWS\novell\zenworks\bin\ZENPreAgent.exe ()
SRV - (enstart) -- C:\WINDOWS\System32\enstart.exe ()
SRV - (tlmagent) -- C:\WINDOWS\itlm\tlmagent.exe ()
SRV - (McAfee SiteAdvisor Enterprise Service) -- C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.)
SRV - (mfevtp) -- C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (nzwinvnc) -- C:\Program Files\Novell\ZENworks\bin\nzrWinVNC.exe (Novell, Inc.)
SRV - (Novell ZENworks Agent Service) -- C:\Program Files\Novell\ZENworks\bin\ZenworksWindowsService.exe (Novell, Inc.)
SRV - (McTaskManager) -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (McAfeeFramework) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (Novell Identity Store) -- C:\Program Files\Novell\CASA\bin\micasad.exe (Novell, Inc)
SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (Multi-user Cleanup Service) -- C:\Program Files\IBM\Lotus\Notes\ntmulti.exe (IBM Corp)
SRV - (Lotus Notes Diagnostics) -- C:\Program Files\IBM\Lotus\Notes\nsd.exe (IBM)
SRV - (NetLogSvc) -- C:\Program Files\AT&T Global Network Client\NetLogSvc.exe (AT&T)
SRV - (netcfgsvr) -- C:\Program Files\AT&T Global Network Client\netcfgsvr.exe (AT&T)
SRV - (NetClientSvc) -- C:\Program Files\AT&T Global Network Client\NetClientSvc.exe (AT&T)
SRV - (cusrvc) -- C:\WINDOWS\system32\cusrvc.exe (Novell, Inc.)
SRV - (STacSV) -- C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
SRV - (UPHClean) -- C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (enstart_) -- C:\WINDOWS\system32\enstart_.sys (Guidance Software Inc.)
DRV - (mfetdi2k) -- C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) -- C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (dfmirage) -- C:\WINDOWS\system32\drivers\dfmirage.sys (DemoForge, LLC)
DRV - (CITMDRV) -- C:\WINDOWS\system32\drivers\CITMDRV.SYS ()
DRV - (vmscsi) -- C:\WINDOWS\system32\DRIVERS\vmscsi.sys (VMware, Inc.)
DRV - (ctxusbm) -- C:\WINDOWS\system32\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV - (agnwifi) -- C:\WINDOWS\system32\drivers\agnwifi.sys (AT&T)
DRV - (avpnnic) -- C:\WINDOWS\system32\drivers\avpnnic.sys (AT&T)
DRV - (agnfilt) -- C:\WINDOWS\system32\drivers\agnfilt.sys (AT&T)
DRV - (NetwareWorkstation) -- C:\WINDOWS\system32\NetWare\nwfs.sys (Novell, Inc.)
DRV - (SRVLOC) -- C:\WINDOWS\system32\NetWare\srvloc.sys (Novell, Inc.)
DRV - (NWSIPX32) Novell Simple Naming Services (NWSNS) -- C:\WINDOWS\system32\NetWare\nwsipx32.sys (Novell, Inc.)
DRV - (NWFILTER) -- C:\WINDOWS\system32\NetWare\nwfilter.sys (Novell, Inc.)
DRV - (RESMGR) -- C:\WINDOWS\system32\NetWare\resmgr.sys (Novell, Inc.)
DRV - (NWDNS) -- C:\WINDOWS\system32\NetWare\nwdns.sys (Novell, Inc.)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (NWSLP) -- C:\WINDOWS\system32\NetWare\nwslp.sys (Novell, Inc.)
DRV - (NICM) -- C:\WINDOWS\System32\Drivers\Nicm.sys (Novell, Inc.)
DRV - (BCM43XX) -- C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corp.)
DRV - (BCMWLNPF) -- C:\WINDOWS\system32\drivers\BCMWLNPF.SYS (CACE Technologies)
DRV - (ApfiltrService) -- C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (NWSAP) -- C:\WINDOWS\system32\NetWare\nwsap.sys ()
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (guardian2) -- C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (DLADResM) -- C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) -- C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (WNTHW) -- C:\WINDOWS\system32\drivers\WNTHW.SYS ()
DRV - (NWDHCP) -- C:\WINDOWS\system32\NetWare\nwdhcp.sys (Novell, Inc.)
DRV - (NWHOST) -- C:\WINDOWS\system32\NetWare\nwhost.sys (Novell, Inc.)
DRV - (NWSNS) -- C:\WINDOWS\system32\NetWare\nwsns.sys (Novell, Inc.)
DRV - (ati2mtaa) -- C:\WINDOWS\system32\drivers\ati2mtaa.sys (ATI Technologies Inc.)
DRV - (es1371) Creative AudioPCI (ES1371,ES1373) (WDM) -- C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)
DRV - (EL90XBC) -- C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.wlgore.com;127.0.0.1;localhost;157.204.*;32.85.*;192.168.*;<local>

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.wlgore.com;127.0.0.1;localhost;157.204.*;32.85.*;192.168.*;<local>

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-21-3542245194-2364831464-1968421150-5037\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://intranet.wlgore.com/
IE - HKU\S-1-5-21-3542245194-2364831464-1968421150-5037\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3542245194-2364831464-1968421150-5037\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor Enterprise\ [2011/12/07 23:04:10 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2012/01/08 17:05:00 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110322105323.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-3542245194-2364831464-1968421150-5037\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [AGNS_Config] C:\WINDOWS\System32\nircmd.exe (NirSoft)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MapDrive] C:\WINDOWS\util\MapDrives.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NalView] C:\Program Files\Novell\ZENworks\bin\NalView.exe (Novell, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [NWTRAY] C:\WINDOWS\System32\nwtray.exe (Novell, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Pistolstar_SSO] C:\Program Files\Pistolstar\Password Power Client\APOSSO.exe (Pistolstar, Inc.)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [UserLogin] C:\WINDOWS\System32\nircmd.exe (NirSoft)
O4 - HKLM..\Run: [ZenNotifyIcon] C:\Program Files\Novell\ZENworks\bin\ZenNotifyIcon.exe (Novell, Inc.)
O4 - HKU\.DEFAULT..\Run: [WebCam-Disable] C:\Windows\util\nircmd.exe (NirSoft)
O4 - HKU\S-1-5-18..\Run: [WebCam-Disable] C:\Windows\util\nircmd.exe (NirSoft)
O4 - HKU\S-1-5-21-3542245194-2364831464-1968421150-5037..\Run: [SET_NOTES] C:\WINDOWS\nircmd.exe (NirSoft)
O4 - HKU\S-1-5-21-3542245194-2364831464-1968421150-5037..\Run: [WebCam-Disable] C:\Windows\util\nircmd.exe (NirSoft)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk = C:\Program Files\PrintKey2000\Printkey2000.exe (Fred's Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\New Windows present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPublishingWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWebServices = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: CompatibleRUPSecurity = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonType = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3542245194-2364831464-1968421150-5037\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\NetWare\nwws2nds.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\system32\NetWare\nwws2sap.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\WINDOWS\system32\NetWare\nwws2slp.dll (Novell, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} http://128.146.233.169/activex/AMC.cab (AxisMediaControlEmb Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wlgore.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F2B6A9E-3794-48B6-87A3-83E7DC939721}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - %SystemRoot%\system32\inetcomm.dll File not found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LCredMgr: DllName - (C:\Program Files\Novell\CASA\bin\lcredmgr.dll) - C:\Program Files\Novell\CASA\bin\lcredmgr.dll ()
O20 - Winlogon\Notify\nzrNotifier: DllName - (nzrNotifier.dll) - C:\WINDOWS\System32\nzrNotifier.dll (Novell, Inc.)
O28 - HKLM ShellExecuteHooks: {763370C4-268E-4308-A60C-D8DA0342BE32} - C:\Program Files\Novell\ZENworks\bin\NalShell.dll (Novell, Inc.)
O30 - LSA: Authentication Packages - (nwv1_0) -C:\WINDOWS\System32\nwv1_0.dll (Novell, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/03/04 16:09:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{cc36a7a3-6b60-11e0-be57-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{cc36a7a3-6b60-11e0-be57-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cc36a7a3-6b60-11e0-be57-806d6172696f}\Shell\AutoRun\command - "" = D:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/12 18:47:39 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\TTolt.USE\Desktop\OTL.exe
[2012/01/12 10:19:27 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/01/12 08:32:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\Lotus
[2012/01/11 23:17:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Desktop\EVUS
[2012/01/11 23:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Desktop\Tom
[2012/01/11 23:17:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Desktop\TurboTax
[2012/01/11 23:16:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Desktop\Zhidan
[2012/01/11 22:48:39 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\TTolt.USE\PrivacIE
[2012/01/11 22:48:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data\Canon Easy-WebPrint EX
[2012/01/11 22:47:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\IsolatedStorage
[2012/01/11 22:46:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\Intuit
[2012/01/11 22:46:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data\Intuit
[2012/01/11 22:22:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\Temp
[2012/01/11 22:22:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\Adobe
[2012/01/11 22:22:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data\Adobe
[2012/01/11 22:18:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data\ICAClient
[2012/01/11 22:18:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\Roxio
[2012/01/11 22:18:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\Citrix
[2012/01/11 22:18:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\PowerDVD DX
[2012/01/11 22:17:59 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\TTolt.USE\IETldCache
[2012/01/11 22:17:54 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\TTolt.USE\Cookies
[2012/01/11 22:17:18 | 000,000,000 | R--D | C] -- C:\Documents and Settings\TTolt.USE\Favorites
[2012/01/11 22:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data\Sun
[2012/01/11 22:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft
[2012/01/11 22:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data\McAfee
[2012/01/11 22:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data\Macromedia
[2012/01/11 22:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Desktop
[2012/01/11 22:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data\Config
[2012/01/11 22:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data
[2012/01/11 22:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Application Data\Apple Computer
[2012/01/11 22:17:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\TTolt.USE\Recent
[2012/01/11 22:17:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\TTolt.USE\My Documents\My Videos
[2012/01/11 22:17:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\TTolt.USE\My Documents\My Pictures
[2012/01/11 22:17:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\TTolt.USE\My Documents\My Music
[2012/01/11 22:17:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\TTolt.USE\My Documents
[2012/01/11 22:17:17 | 000,000,000 | R--D | C] -- C:\Documents and Settings\TTolt.USE\Start Menu\Programs\Administrative Tools
[2012/01/11 22:17:17 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\TTolt.USE\UserData
[2012/01/11 22:17:17 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Templates
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Start Menu\Programs\Startup
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Start Menu
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\SendTo
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\PrintHood
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\PCHealth
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\NetHood
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\Microsoft
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\ApplicationHistory
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Local Settings\Application Data\Apple Computer
[2012/01/11 22:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\TTolt.USE\Start Menu\Programs\Accessories
[2012/01/11 21:56:47 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2012/01/11 20:19:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2012/01/11 20:16:09 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner Network Edition
[2012/01/10 22:16:31 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2012/01/10 21:47:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012/01/10 21:47:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/01/10 21:47:07 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2012/01/10 21:47:07 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2012/01/10 21:47:07 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2012/01/10 21:47:07 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2012/01/10 21:47:07 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2012/01/10 21:46:48 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/01/10 21:44:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2012/01/10 21:43:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012/01/10 21:43:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2012/01/08 22:39:07 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/01/08 19:33:41 | 000,000,000 | ---D | C] -- C:\Old Job Stuff
[2012/01/08 19:04:27 | 000,000,000 | ---D | C] -- C:\Family Photos-Movies IV
[2012/01/08 19:04:07 | 000,000,000 | ---D | C] -- C:\Family Photos-Movies III
[2012/01/08 16:43:51 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/01/08 16:41:51 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/01/08 16:41:51 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/01/08 16:41:51 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/01/08 16:41:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/01/08 16:14:04 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/06 21:34:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8
[2012/01/05 19:17:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/05 19:17:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/01/05 19:17:44 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/01/05 19:17:43 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/03 20:51:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\itlm_msi_cache
[2012/01/01 21:46:26 | 000,000,000 | ---D | C] -- C:\Program Files\palmOne
[2011/12/26 10:39:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/22 21:28:25 | 000,014,664 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\stinger.sys
[2011/12/22 21:06:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/22 21:06:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/12/22 17:33:23 | 000,000,000 | ---D | C] -- C:\Program Files\Axis Communications
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\NetworkService\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/12 18:47:48 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\TTolt.USE\Desktop\OTL.exe
[2012/01/12 18:41:54 | 000,167,379 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2012/01/12 18:41:51 | 000,201,276 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012/01/12 18:41:28 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/12 18:41:17 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/12 18:39:34 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/12 18:39:30 | 2145,349,632 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/12 15:06:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/12 13:13:19 | 000,443,482 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/12 13:13:19 | 000,072,582 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/01/12 10:19:30 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2012/01/12 10:08:07 | 000,001,493 | ---- | M] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk
[2012/01/12 09:52:49 | 000,684,297 | ---- | M] () -- C:\Documents and Settings\TTolt.USE\Desktop\unhide.exe
[2012/01/12 08:54:08 | 000,000,258 | RHS- | M] () -- C:\Documents and Settings\TTolt.USE\ntuser.pol
[2012/01/12 08:47:57 | 000,098,626 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
[2012/01/12 08:34:04 | 000,001,508 | ---- | M] () -- C:\Documents and Settings\TTolt.USE\Desktop\Webcam Disable.lnk
[2012/01/12 08:34:03 | 000,001,504 | ---- | M] () -- C:\Documents and Settings\TTolt.USE\Desktop\Webcam Enable.lnk
[2012/01/12 08:30:24 | 000,167,379 | ---- | M] () -- C:\WINDOWS\System32\nvModes.dat
[2012/01/11 22:45:44 | 000,002,393 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2010.lnk
[2012/01/11 22:18:23 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/11 22:05:21 | 000,177,056 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/11 21:58:23 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/01/11 21:54:29 | 000,002,299 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AT&T Global Network Client.lnk
[2012/01/11 20:19:46 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\mbios55.rom
[2012/01/11 20:18:28 | 000,004,995 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\lsvsdncd.hix
[2012/01/10 21:46:53 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2012/01/10 21:46:53 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2012/01/10 21:46:53 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2012/01/10 21:46:53 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2012/01/10 21:46:53 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2012/01/10 21:44:13 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/08 17:05:00 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/01/08 16:43:56 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/01/06 15:47:12 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/05 19:17:51 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/03 20:54:53 | 000,014,664 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\stinger.sys
[2012/01/03 20:32:47 | 000,001,404 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PLM Prod Environment.lnk
[2012/01/01 21:53:59 | 000,000,000 | ---- | M] () -- C:\WINDOWS\QuickInstall.INI
[2011/12/29 09:55:23 | 000,054,156 | ---- | M] () -- C:\WINDOWS\QTFont.qfn
[2011/12/26 19:17:18 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2011/12/22 20:13:31 | 000,003,552 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\825464l2s864n588q817j4buq4w1
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/12 10:19:30 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2012/01/12 09:52:36 | 000,684,297 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Desktop\unhide.exe
[2012/01/12 08:34:04 | 000,001,508 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Desktop\Webcam Disable.lnk
[2012/01/12 08:34:03 | 000,001,504 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Desktop\Webcam Enable.lnk
[2012/01/11 22:18:23 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Start Menu\Programs\Internet Explorer.lnk
[2012/01/11 22:17:24 | 000,001,878 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Lotus Notes 8.5.lnk
[2012/01/11 22:17:24 | 000,001,838 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2012/01/11 22:17:24 | 000,001,834 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk
[2012/01/11 22:17:24 | 000,001,825 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office PowerPoint 2003.lnk
[2012/01/11 22:17:24 | 000,001,623 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Zap Notes.lnk
[2012/01/11 22:17:24 | 000,001,493 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk
[2012/01/11 22:17:24 | 000,000,867 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Message Manager.lnk
[2012/01/11 22:17:24 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/11 22:17:24 | 000,000,488 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Electronic Log.lnk
[2012/01/11 22:17:24 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/01/11 22:17:18 | 000,000,788 | ---- | C] () -- C:\Documents and Settings\TTolt.USE\Start Menu\Programs\Windows Media Player.lnk
[2012/01/11 22:17:17 | 000,000,258 | RHS- | C] () -- C:\Documents and Settings\TTolt.USE\ntuser.pol
[2012/01/11 21:56:42 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2012/01/11 20:19:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\mbios55.rom
[2012/01/11 20:18:28 | 000,004,995 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\lsvsdncd.hix
[2012/01/10 21:44:13 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/10 21:44:12 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/08 16:41:51 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/01/08 16:41:51 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/01/08 16:41:51 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/01/08 16:41:51 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/01/08 16:41:51 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/01/05 19:17:51 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/01 21:53:59 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2011/12/26 19:17:18 | 000,054,156 | ---- | C] () -- C:\WINDOWS\QTFont.qfn
[2011/12/26 19:17:18 | 000,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2011/12/22 20:10:00 | 000,003,552 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\825464l2s864n588q817j4buq4w1
[2011/10/01 15:41:09 | 001,248,632 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/06/17 06:13:22 | 000,056,056 | ---- | C] () -- C:\WINDOWS\System32\DLAAPI_W.DLL
[2011/06/17 06:13:22 | 000,000,169 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2011/06/17 06:08:12 | 000,000,562 | ---- | C] () -- C:\WINDOWS\msg_mgr.ini
[2011/06/17 06:08:12 | 000,000,290 | ---- | C] () -- C:\WINDOWS\attwktop.ini
[2011/06/17 06:04:53 | 000,737,280 | ---- | C] () -- C:\WINDOWS\System32\enstart_.exe
[2011/06/17 06:04:51 | 000,737,280 | ---- | C] () -- C:\WINDOWS\System32\enstart.exe
[2011/06/17 06:04:25 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\CITMDRV.SYS
[2011/06/17 06:04:08 | 000,000,404 | ---- | C] () -- C:\WINDOWS\swdis.ini
[2011/06/17 06:02:13 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2011/06/17 06:02:10 | 000,024,064 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2011/06/17 06:02:09 | 000,753,664 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2011/06/17 06:00:37 | 000,167,379 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat
[2011/03/30 03:10:04 | 000,051,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\atnt40k.sys
[2010/10/10 23:29:34 | 000,114,688 | ---- | C] () -- C:\Program Files\ad_ff.dll
[2010/10/10 23:29:14 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\jmicasa.dll
[2010/10/10 23:29:04 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\micasa.dll
[2010/10/10 23:28:52 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\micasacache.dll
[2010/07/10 00:24:14 | 000,006,253 | ---- | C] () -- C:\Program Files\eula.rtf
[2010/05/28 07:39:16 | 000,335,872 | ---- | C] () -- C:\WINDOWS\System32\casa_authtoken.dll
[2009/06/09 14:11:06 | 000,192,490 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DeviceManager.xml.rc4
[2009/05/07 02:08:06 | 001,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/05/07 02:08:06 | 001,346,080 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2009/05/07 02:08:06 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009/05/07 02:08:04 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/05/07 02:08:04 | 001,657,376 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2009/05/07 02:08:04 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/05/07 02:08:04 | 000,449,056 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2009/05/07 02:08:04 | 000,432,672 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2009/05/05 05:59:21 | 000,088,576 | ---- | C] () -- C:\WINDOWS\choice.exe
[2009/01/14 07:21:40 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2009/01/13 09:00:08 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2007/08/29 16:52:48 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2007/05/22 18:03:26 | 000,031,232 | ---- | C] () -- C:\WINDOWS\cmdow.exe
[2007/04/04 19:47:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\WINSETUP.INI
[2007/03/04 11:53:54 | 000,015,360 | ---- | C] () -- C:\WINDOWS\soon.exe
[2007/02/15 11:29:02 | 000,041,472 | ---- | C] () -- C:\WINDOWS\WINMSG.EXE
[2006/10/02 15:14:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\asasrv.ini
[2006/09/16 20:36:50 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 20:36:50 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2006/08/12 09:30:16 | 000,036,864 | ---- | C] () -- C:\WINDOWS\exist.exe
[2006/06/02 13:10:40 | 000,060,928 | ---- | C] () -- C:\WINDOWS\scanreg.exe
[2006/05/15 18:50:24 | 000,002,048 | ---- | C] () -- C:\WINDOWS\NalRefresh.exe
[2006/04/28 14:07:16 | 000,062,464 | ---- | C] () -- C:\WINDOWS\timeout.exe
[2006/04/28 14:07:16 | 000,024,576 | ---- | C] () -- C:\WINDOWS\setx.exe
[2006/04/28 14:07:16 | 000,011,776 | ---- | C] () -- C:\WINDOWS\pathman.exe
[2006/01/06 02:37:38 | 000,009,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\WNTHW.SYS
[2006/01/06 02:32:01 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\setx.exe
[2006/01/06 02:31:56 | 000,062,464 | ---- | C] () -- C:\WINDOWS\System32\timeout.exe
[2006/01/06 02:31:56 | 000,031,232 | ---- | C] () -- C:\WINDOWS\System32\cmdow.exe
[2005/09/23 22:25:02 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\IMGFX6MU.DLL
[2005/09/23 22:09:53 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/03/04 22:23:57 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2005/03/04 21:31:05 | 000,003,698 | ---- | C] () -- C:\WINDOWS\System32\iprint.ini
[2005/03/04 20:37:15 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\nwslog32.dll
[2005/03/04 20:37:11 | 000,065,619 | ---- | C] () -- C:\WINDOWS\System32\setupw2k.dll
[2005/03/04 20:37:11 | 000,015,898 | ---- | C] () -- C:\WINDOWS\System32\vlmsup.exe
[2005/03/04 20:37:11 | 000,001,724 | ---- | C] () -- C:\WINDOWS\System32\vipx.exe
[2005/03/04 20:37:10 | 000,262,227 | ---- | C] () -- C:\WINDOWS\System32\nwshlxnt.dll
[2005/03/04 20:37:08 | 000,051,200 | ---- | C] () -- C:\WINDOWS\System32\lgncon32.dll
[2005/03/04 20:37:08 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\dplgnw32.dll
[2005/03/04 20:37:04 | 000,002,757 | ---- | C] () -- C:\WINDOWS\System32\rdrstats.ini
[2005/03/04 20:36:58 | 000,225,356 | ---- | C] () -- C:\WINDOWS\System32\lgnwnt32.dll
[2005/03/04 20:36:58 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\prtwin32.dll
[2005/03/04 20:36:58 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\nwpsrv32.dll
[2005/03/04 20:29:35 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/03/04 18:22:01 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/03/04 16:16:00 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/03/04 16:04:39 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/03/04 15:55:27 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/03/04 15:54:10 | 000,177,056 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/04 17:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 17:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 17:00:00 | 000,443,482 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 17:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 17:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 17:00:00 | 000,072,582 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 17:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 17:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 17:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 17:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 17:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 17:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/03/17 01:39:12 | 000,454,761 | ---- | C] () -- C:\WINDOWS\System32\boost_regex-vc6-mt-1_31.dll
[2004/03/17 01:38:26 | 000,467,052 | ---- | C] () -- C:\WINDOWS\System32\boost_regex-vc6-mt-gd-1_31.dll
[2002/04/17 12:21:44 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\XMLPARSE.DLL
[1999/08/06 23:05:16 | 000,212,480 | ---- | C] () -- C:\WINDOWS\System32\DBPORT6.DLL

========== Custom Scans ==========


< %TEMP%\smtmp\*.* /s >

< >

< >

< End of report >




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users