imcoolanytime
Ran the script/Combo fix again… did not see any difference…
Below is the ComboFix log followed by HJlog
ComboFix 09-05-30.06 - shokher.gortik 06/02/2009 17:23.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1441 [GMT -4:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\shokher.gortik\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FILE ::
"C:\487656.bat"
"C:\VundoFix Backups"
"c:\winnt\Temp\bwgo0002fa63.exe"
"d:\docume~1\SHEKHA~1.GOR\LOCALS~1\temp\bwgo000350b1.exe"
"d:\docume~1\SHEKHA~1.GOR\LOCALS~1\temp\bwgo00039b66.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\487656.bat
c:\winnt\Temp\bwgo0002fa63.exe
d:\docume~1\SHEKHA~1.GOR\LOCALS~1\temp\bwgo000350b1.exe
d:\docume~1\SHEKHA~1.GOR\LOCALS~1\temp\bwgo00039b66.exe
d:\documents and settings\NetworkService\Application Data\ymnrfqye
d:\documents and settings\NetworkService\Application Data\ymnrfqye\profiles.ini
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\cert8.db
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\compatibility.ini
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\compreg.dat
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\cookies.sqlite
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\formhistory.sqlite
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\key3.db
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\localstore.rdf
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\permissions.sqlite
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\places.sqlite-journal
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\places.sqlite
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\pluginreg.dat
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\prefs.js
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\secmod.db
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\webappsstore.sqlite
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\xpti.dat
d:\documents and settings\NetworkService\Local Settings\Application Data\ymnrfqye
d:\documents and settings\NetworkService\Local Settings\Application Data\ymnrfqye\Profiles\5knfsos0.default\urlclassifier3.sqlite
d:\documents and settings\NetworkService\Local Settings\Application Data\ymnrfqye\Profiles\5knfsos0.default\XPC.mfl
c:\winnt\system32\proquota.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2009-05-02 to 2009-06-02 )))))))))))))))))))))))))))))))
.
2009-06-01 20:01 . 2009-06-01 20:01 ——– d—–w- d:\documents and settings\shokher.gortik\Application Data\Apple Computer
2009-05-31 12:03 . 2009-05-31 12:03 10134 —-a-r- d:\documents and settings\shokher.gortik\Application Data\Microsoft\Installer\{DDF6E319-BCD9-4FE3-9D69-26B2F47BEF7C}\ARPPRODUCTICON.exe
2009-05-31 04:14 . 2009-05-31 04:14 ——– d-s—w- d:\documents and settings\shokher.gortik\UserData
2009-05-31 04:14 . 2009-05-31 04:14 ——– d-s—w- d:\documents and settings\\shokher.gortik\UserData
2009-05-30 19:32 . 2009-05-30 19:32 ——– d—–w- d:\documents and settings\shokher.gortik\Application Data\ymnrfqye
2009-05-30 19:32 . 2009-05-30 19:32 ——– d—–w- d:\documents and settings\shokher.gortik\Local Settings\Application Data\ymnrfqye
2009-05-30 13:13 . 2009-05-30 13:13 ——– d—–w- c:\program files\Microsoft Learning
2009-05-27 20:39 . 2009-05-27 20:39 3371383 —-a-w- d:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-26 16:42 . 2009-05-26 16:42 ——– d—–w- c:\program files\Trend Micro
2009-05-26 16:34 . 2009-05-26 16:34 ——– d—–w- C:\VundoFix Backups
2009-05-26 13:17 . 2009-05-26 13:17 ——– d—–w- d:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-05-26 10:31 . 2009-05-26 10:31 48768 —-a-w- c:\winnt\system32\S32EVNT1.DLL
2009-05-26 10:31 . 2009-05-26 10:31 110952 —-a-w- c:\winnt\system32\drivers\SYMEVENT.SYS
2009-05-17 15:04 . 2009-05-17 15:04 ——– d—–w- d:\documents and settings\shokher.gortik\Application Data\IsolatedStorage
2009-05-17 02:00 . 2009-05-17 02:00 ——– d—–w- d:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-16 13:36 . 2009-05-16 13:36 ——– d—–w- c:\program files\SQLXML 4.0
2009-05-16 13:29 . 2009-05-16 13:29 ——– d—–w- c:\program files\Common Files\Merge Modules
2009-05-16 13:27 . 2009-05-16 13:27 ——– d—–w- c:\program files\Microsoft Analysis Services
2009-05-16 13:26 . 2009-05-16 13:35 ——– d—–w- c:\program files\Microsoft.NET
2009-05-16 12:51 . 2009-05-16 13:29 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2009-05-15 19:07 . 2009-05-15 19:07 10134 —-a-r- d:\documents and settings\shokher.gortik\Application Data\Microsoft\Installer\{7D95B533-4BA1-4EED-8096-EFCB6DD6B95F}\ARPPRODUCTICON.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 18:22 . 2008-09-11 13:41 ——– d—–w- c:\program files\BearingPoint
2009-06-01 02:25 . 2008-09-11 15:40 ——– d—–w- c:\program files\SafeBoot
2009-05-27 20:39 . 2009-04-13 20:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-05-26 17:20 . 2009-04-13 20:45 40160 —-a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-05-26 17:19 . 2009-04-13 20:45 19096 —-a-w- c:\winnt\system32\drivers\mbam.sys
2009-05-26 13:42 . 2008-09-11 13:51 ——– d—–w- c:\program files\Symantec AntiVirus
2009-05-26 10:32 . 2008-09-11 13:51 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-05-26 10:31 . 2008-09-11 13:51 ——– d—–w- c:\program files\Symantec
2009-05-26 10:31 . 2009-05-26 10:31 805 —-a-w- c:\winnt\system32\drivers\SYMEVENT.INF
2009-05-26 10:31 . 2009-05-26 10:31 8014 —-a-w- c:\winnt\system32\drivers\SYMEVENT.CAT
2009-05-26 10:31 . 2008-09-11 13:51 ——– d—–w- d:\documents and settings\All Users\Application Data\Symantec
2009-05-23 05:28 . 2008-09-10 15:53 78624 —-a-w- c:\winnt\system32\nvModes.dat
2009-05-16 13:45 . 2008-09-11 13:42 ——– d—–w- d:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-16 13:42 . 2009-04-13 15:23 ——– d—–w- c:\program files\Microsoft SQL Server
2009-05-08 20:42 . 2009-04-09 15:11 ——– d—–w- d:\documents and settings\All Users\Application Data\WinZip
2009-05-08 14:31 . 2008-12-25 23:54 ——– d—–w- c:\program files\Google
2009-05-04 20:56 . 2008-09-11 13:55 ——– d—–w- c:\program files\CoKinetic
2009-05-01 18:30 . 2009-05-01 18:30 3366912 —-a-w- c:\winnt\system32\GPhotos.scr
2009-04-27 17:26 . 2008-09-11 15:11 ——– d—–w- d:\documents and settings\All Users\Application Data\FLEXnet
2009-04-26 05:34 . 2009-04-26 05:34 188501 —-a-w- d:\documents and settings\shokher.gortik\Application Data\ContentGuard\CGGuard2.dll
2009-04-26 05:34 . 2009-04-26 05:34 ——– d—–w- d:\documents and settings\shokher.gortik\Application Data\ContentGuard
2009-04-25 04:25 . 2009-04-25 04:25 ——– d—–w- c:\program files\DivX
2009-04-25 04:25 . 2009-04-25 04:25 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-04-24 18:03 . 2009-04-24 18:03 ——– d—–w- c:\program files\DIFX
2009-04-24 18:02 . 2009-04-24 18:02 ——– d—–w- d:\documents and settings\All Users\Application Data\Applications
2009-04-24 17:28 . 2009-04-24 17:28 ——– d—–w- c:\program files\Microsoft Silverlight
2009-03-14 00:30 . 2009-04-24 18:03 81736 —-a-w- c:\winnt\system32\lmdimon8.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-05-31_04.07.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-02 18:50 . 2009-06-02 18:50 16384 c:\winnt\Temp\Perflib_Perfdata_84.dat
+ 2009-06-02 18:50 . 2009-06-02 18:50 16384 c:\winnt\Temp\Perflib_Perfdata_344.dat
+ 2008-09-10 22:42 . 2009-05-31 04:10 98336 c:\winnt\system32\perfc009.dat
- 2008-09-10 22:42 . 2009-05-16 13:44 98336 c:\winnt\system32\perfc009.dat
+ 2008-09-10 22:42 . 2009-05-31 04:10 501682 c:\winnt\system32\perfh009.dat
- 2008-09-10 22:42 . 2009-05-16 13:44 501682 c:\winnt\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2004-08-04 15360]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" [2008-07-31 95744]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-09 39408]
"Google Update"="d:\documents and settings\shokher.gortik\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-02 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"NvCplDaemon"="c:\winnt\system32\NvCpl.dll" [2007-04-29 8429568]
"NvMediaCenter"="c:\winnt\system32\NvMcTray.dll" [2007-04-29 81920]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-04-16 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"NPSMan"="c:\winnt\system32\NPSMan.exe" [2008-09-11 65536]
"BearingPoint TV"="d:\program files\BETV\7398437\Program\BearingPoint TV.exe" [2008-09-11 36903]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-02-20 1191936]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"SBMGRNT.EXE"="c:\progra~1\SafeBoot\SBMGRNT.EXE" [2008-09-11 49212]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-19 185872]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-03-14 125632]
"nwiz"="nwiz.exe" - c:\winnt\system32\nwiz.exe [2007-04-29 1626112]
"NVHotkey"="nvHotkey.dll" - c:\winnt\system32\nvhotkey.dll [2007-04-29 67584]
"SigmatelSysTrayApp"="stsystra.exe" - c:\winnt\stsystra.exe [2007-02-19 303104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-12-05 3900936]
d:\documents and settings\All Users\Start Menu\Programs\Startup\
BearingPoint TV.lnk - d:\program files\BETV\7398437\Program\BearingPoint TV.exe [2008-9-11 36903]
VPN Client.lnk - c:\winnt\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2008-9-18 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"LogonType"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogoff"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
"ForceStartMenuLogoff"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
"ForceStartMenuLogoff"= 1 (0x1)
"NoThemesTab"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\0\0]
"Script"=c:\winnt\system32\BECiscoFirewall.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\BETV\\7398437\\Program\\BearingPoint TV.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5556:TCP"= 5556:TCP:SafeBoot
"4657:TCP"= 4657:TCP:@xpsp2res.dll,-22009
R0 SafeBoot;SafeBoot;c:\winnt\system32\drivers\safeboot.sys [9/11/2008 11:40 AM 30267]
R0 SBAlg;SBAlg;c:\winnt\system32\drivers\sbalg.sys [9/11/2008 11:40 AM 44848]
R1 RsvLock;RsvLock;c:\winnt\system32\drivers\rsvlock.sys [9/11/2008 11:40 AM 4752]
R1 SBFlop;SBFlop;c:\winnt\system32\drivers\sbflop.sys [9/11/2008 11:40 AM 6096]
R1 SbPrcCtl;SbPrcCtl;c:\winnt\system32\drivers\sbprcctl.sys [9/11/2008 11:40 AM 14864]
R2 agnwifi;AT&T Wi-Fi Support Driver;c:\winnt\system32\drivers\agnwifi.sys [9/11/2008 9:57 AM 19328]
R2 MsDtsServer;SQL Server Integration Services;c:\program files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe [10/14/2005 3:45 AM 199384]
R2 msftesql$ACURA;SQL Server FullText Search (ACURA);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe [8/26/2005 4:00 PM 92880]
R2 MSOLAP$ACURA;SQL Server Analysis Services (ACURA);c:\program files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe [10/14/2005 3:46 AM 14557912]
R2 MSSQL$ACURA;SQL Server (ACURA);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [10/14/2005 3:51 AM 28768528]
R2 PowManSvc;Power Management Service;c:\winnt\system32\PowManSvc.exe [9/11/2008 10:00 AM 40960]
R2 SafeBootConfigurationManager;SafeBoot Configuration Manager;c:\program files\SafeBoot\sbmgrnt.exe [9/11/2008 11:40 AM 49212]
R2 Security maintenance service;Security maintenance service;c:\winnt\system32\SecMaint.exe [9/11/2008 10:00 AM 90112]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/26/2009 9:15 AM 101936]
S2 SQLAgent$ACURA;SQL Server Agent (ACURA);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE [10/14/2005 3:51 AM 318680]
S3 IgniteService;IgniteService;d:\program files\BETV\7398437\Program\IgniteService.exe [9/11/2008 10:00 AM 81920]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [3/14/2007 7:48 PM 116416]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808]
.
Contents of the 'Scheduled Tasks' folder
2009-06-02 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1202660629-682003330-281317.job
- d:\documents and settings\shokher.gortik\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-02 18:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bearingpoint.com/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = hxxp://inside.corp.bearingpoint.com;
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\winnt\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: bearingpoint.com
Trusted Zone: cisco.com\meetings
Trusted Zone: localhost
Trusted Zone: plateau.com
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Web-Based Email Tools - hxxp://email02.secureserver.net/Download.CAB
DPF: {427BD09A-B354-4AF3-89CC-7EB3B315554B} - hxxp://odohrwebnew.od.nih.gov/bizflow/controls/hwau.cab
DPF: {B20D9D6A-0DEC-4d76-9BEF-175896006B4A}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-02 17:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\msftesql$ACURA]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:ACURA"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ccEvtMgr]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SAVRT]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SNDSrvc]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SYMTDI]
"ImagePath"="-"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1308)
c:\program files\SafeBoot\SBGINA.DLL
c:\program files\SafeBoot\SBIPC.DLL
.
Completion time: 2009-06-02 17:28
ComboFix-quarantined-files.txt 2009-06-02 21:28
ComboFix2.txt 2009-06-02 13:38
ComboFix3.txt 2009-06-01 13:58
ComboFix4.txt 2009-05-31 04:11
Pre-Run: 1,143,459,840 bytes free
Post-Run: 1,126,043,648 bytes free
245
———————————————————————————————————————————————————————————-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:55:13 AM, on 6/2/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\SafeBoot\SBMGRNT.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\PowManSvc.exe
C:\WINNT\system32\SecMaint.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\WINNT\system32\StacSV.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\WINNT\TEMP\bwgo0002fa63.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINNT\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
D:\DOCUME~1\SHEKHA~1.GOR\LOCALS~1\Temp\bwgo000350b1.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
D:\Documents and Settings\shokher.gortik\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\DOCUME~1\SHEKHA~1.GOR\LOCALS~1\Temp\bwgo00039b66.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINNT\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\shokher.gortik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\shokher.gortik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\shokher.gortik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bearingpoint.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://inside.corp.bearingpoint.com;
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NPSMan] C:\WINNT\system32\NPSMan.exe
O4 - HKLM\..\Run: [BearingPoint TV] "D:\Program Files\BETV\7398437\Program\BearingPoint TV.exe" -startup
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SBMGRNT.EXE] C:\PROGRA~1\SafeBoot\SBMGRNT.EXE -WinLogon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\shokher.gortik\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - Global Startup: BearingPoint TV.lnk = D:\Program Files\BETV\7398437\Program\BearingPoint TV.exe
O4 - Global Startup: VPN Client.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINNT\system32\GPhotos.scr/200
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file:About:Blank
O15 - Trusted Zone: *.bearingpoint.com (HKLM)
O15 - Trusted Zone: http://meetings.cisco.com (HKLM)
O15 - Trusted Zone: *.plateau.com (HKLM)
O16 - DPF: Web-Based Email Tools - http://email02.secureserver.net/Download.CAB
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.andhrajyothy.com/wfplayer/tdserver.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {427BD09A-B354-4AF3-89CC-7EB3B315554B} (HWAUCtrl Class) - http://odohrwebnew.od.nih.gov/bizflow/controls/hwau.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/50.10/uploader2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {B20D9D6A-0DEC-4d76-9BEF-175896006B4A} (RptViewerAX Class) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://be.webex.com/client/T25L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corp.kpmgconsulting.com
O17 - HKLM\Software\..\Telephony: DomainName = corp.kpmgconsulting.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corp.kpmgconsulting.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = corp.bearingpoint.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = corp.kpmgconsulting.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = corp.bearingpoint.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = corp.kpmgconsulting.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = corp.bearingpoint.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.bearingpoint.com
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IgniteService - Unknown owner - D:\Program Files\BETV\7398437\Program\IgniteService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Power Management Service (PowManSvc) - NPS software - C:\WINNT\system32\PowManSvc.exe
O23 - Service: SafeBoot Configuration Manager (SafeBootConfigurationManager) - Control Break International - C:\Program Files\SafeBoot\SBMGRNT.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Security maintenance service - BearingPoint - Global - C:\WINNT\system32\SecMaint.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINNT\system32\StacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
–
End of file - 12898 bytes
Below is the ComboFix log followed by HJlog
ComboFix 09-05-30.06 - shokher.gortik 06/02/2009 17:23.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1441 [GMT -4:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\shokher.gortik\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FILE ::
"C:\487656.bat"
"C:\VundoFix Backups"
"c:\winnt\Temp\bwgo0002fa63.exe"
"d:\docume~1\SHEKHA~1.GOR\LOCALS~1\temp\bwgo000350b1.exe"
"d:\docume~1\SHEKHA~1.GOR\LOCALS~1\temp\bwgo00039b66.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\487656.bat
c:\winnt\Temp\bwgo0002fa63.exe
d:\docume~1\SHEKHA~1.GOR\LOCALS~1\temp\bwgo000350b1.exe
d:\docume~1\SHEKHA~1.GOR\LOCALS~1\temp\bwgo00039b66.exe
d:\documents and settings\NetworkService\Application Data\ymnrfqye
d:\documents and settings\NetworkService\Application Data\ymnrfqye\profiles.ini
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\cert8.db
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\compatibility.ini
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\compreg.dat
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\cookies.sqlite
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\formhistory.sqlite
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\key3.db
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\localstore.rdf
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\permissions.sqlite
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\places.sqlite-journal
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\places.sqlite
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\pluginreg.dat
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\prefs.js
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\secmod.db
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\webappsstore.sqlite
d:\documents and settings\NetworkService\Application Data\ymnrfqye\Profiles\5knfsos0.default\xpti.dat
d:\documents and settings\NetworkService\Local Settings\Application Data\ymnrfqye
d:\documents and settings\NetworkService\Local Settings\Application Data\ymnrfqye\Profiles\5knfsos0.default\urlclassifier3.sqlite
d:\documents and settings\NetworkService\Local Settings\Application Data\ymnrfqye\Profiles\5knfsos0.default\XPC.mfl
c:\winnt\system32\proquota.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2009-05-02 to 2009-06-02 )))))))))))))))))))))))))))))))
.
2009-06-01 20:01 . 2009-06-01 20:01 ——– d—–w- d:\documents and settings\shokher.gortik\Application Data\Apple Computer
2009-05-31 12:03 . 2009-05-31 12:03 10134 —-a-r- d:\documents and settings\shokher.gortik\Application Data\Microsoft\Installer\{DDF6E319-BCD9-4FE3-9D69-26B2F47BEF7C}\ARPPRODUCTICON.exe
2009-05-31 04:14 . 2009-05-31 04:14 ——– d-s—w- d:\documents and settings\shokher.gortik\UserData
2009-05-31 04:14 . 2009-05-31 04:14 ——– d-s—w- d:\documents and settings\\shokher.gortik\UserData
2009-05-30 19:32 . 2009-05-30 19:32 ——– d—–w- d:\documents and settings\shokher.gortik\Application Data\ymnrfqye
2009-05-30 19:32 . 2009-05-30 19:32 ——– d—–w- d:\documents and settings\shokher.gortik\Local Settings\Application Data\ymnrfqye
2009-05-30 13:13 . 2009-05-30 13:13 ——– d—–w- c:\program files\Microsoft Learning
2009-05-27 20:39 . 2009-05-27 20:39 3371383 —-a-w- d:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-26 16:42 . 2009-05-26 16:42 ——– d—–w- c:\program files\Trend Micro
2009-05-26 16:34 . 2009-05-26 16:34 ——– d—–w- C:\VundoFix Backups
2009-05-26 13:17 . 2009-05-26 13:17 ——– d—–w- d:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-05-26 10:31 . 2009-05-26 10:31 48768 —-a-w- c:\winnt\system32\S32EVNT1.DLL
2009-05-26 10:31 . 2009-05-26 10:31 110952 —-a-w- c:\winnt\system32\drivers\SYMEVENT.SYS
2009-05-17 15:04 . 2009-05-17 15:04 ——– d—–w- d:\documents and settings\shokher.gortik\Application Data\IsolatedStorage
2009-05-17 02:00 . 2009-05-17 02:00 ——– d—–w- d:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-16 13:36 . 2009-05-16 13:36 ——– d—–w- c:\program files\SQLXML 4.0
2009-05-16 13:29 . 2009-05-16 13:29 ——– d—–w- c:\program files\Common Files\Merge Modules
2009-05-16 13:27 . 2009-05-16 13:27 ——– d—–w- c:\program files\Microsoft Analysis Services
2009-05-16 13:26 . 2009-05-16 13:35 ——– d—–w- c:\program files\Microsoft.NET
2009-05-16 12:51 . 2009-05-16 13:29 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2009-05-15 19:07 . 2009-05-15 19:07 10134 —-a-r- d:\documents and settings\shokher.gortik\Application Data\Microsoft\Installer\{7D95B533-4BA1-4EED-8096-EFCB6DD6B95F}\ARPPRODUCTICON.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 18:22 . 2008-09-11 13:41 ——– d—–w- c:\program files\BearingPoint
2009-06-01 02:25 . 2008-09-11 15:40 ——– d—–w- c:\program files\SafeBoot
2009-05-27 20:39 . 2009-04-13 20:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-05-26 17:20 . 2009-04-13 20:45 40160 —-a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-05-26 17:19 . 2009-04-13 20:45 19096 —-a-w- c:\winnt\system32\drivers\mbam.sys
2009-05-26 13:42 . 2008-09-11 13:51 ——– d—–w- c:\program files\Symantec AntiVirus
2009-05-26 10:32 . 2008-09-11 13:51 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-05-26 10:31 . 2008-09-11 13:51 ——– d—–w- c:\program files\Symantec
2009-05-26 10:31 . 2009-05-26 10:31 805 —-a-w- c:\winnt\system32\drivers\SYMEVENT.INF
2009-05-26 10:31 . 2009-05-26 10:31 8014 —-a-w- c:\winnt\system32\drivers\SYMEVENT.CAT
2009-05-26 10:31 . 2008-09-11 13:51 ——– d—–w- d:\documents and settings\All Users\Application Data\Symantec
2009-05-23 05:28 . 2008-09-10 15:53 78624 —-a-w- c:\winnt\system32\nvModes.dat
2009-05-16 13:45 . 2008-09-11 13:42 ——– d—–w- d:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-16 13:42 . 2009-04-13 15:23 ——– d—–w- c:\program files\Microsoft SQL Server
2009-05-08 20:42 . 2009-04-09 15:11 ——– d—–w- d:\documents and settings\All Users\Application Data\WinZip
2009-05-08 14:31 . 2008-12-25 23:54 ——– d—–w- c:\program files\Google
2009-05-04 20:56 . 2008-09-11 13:55 ——– d—–w- c:\program files\CoKinetic
2009-05-01 18:30 . 2009-05-01 18:30 3366912 —-a-w- c:\winnt\system32\GPhotos.scr
2009-04-27 17:26 . 2008-09-11 15:11 ——– d—–w- d:\documents and settings\All Users\Application Data\FLEXnet
2009-04-26 05:34 . 2009-04-26 05:34 188501 —-a-w- d:\documents and settings\shokher.gortik\Application Data\ContentGuard\CGGuard2.dll
2009-04-26 05:34 . 2009-04-26 05:34 ——– d—–w- d:\documents and settings\shokher.gortik\Application Data\ContentGuard
2009-04-25 04:25 . 2009-04-25 04:25 ——– d—–w- c:\program files\DivX
2009-04-25 04:25 . 2009-04-25 04:25 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-04-24 18:03 . 2009-04-24 18:03 ——– d—–w- c:\program files\DIFX
2009-04-24 18:02 . 2009-04-24 18:02 ——– d—–w- d:\documents and settings\All Users\Application Data\Applications
2009-04-24 17:28 . 2009-04-24 17:28 ——– d—–w- c:\program files\Microsoft Silverlight
2009-03-14 00:30 . 2009-04-24 18:03 81736 —-a-w- c:\winnt\system32\lmdimon8.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-05-31_04.07.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-02 18:50 . 2009-06-02 18:50 16384 c:\winnt\Temp\Perflib_Perfdata_84.dat
+ 2009-06-02 18:50 . 2009-06-02 18:50 16384 c:\winnt\Temp\Perflib_Perfdata_344.dat
+ 2008-09-10 22:42 . 2009-05-31 04:10 98336 c:\winnt\system32\perfc009.dat
- 2008-09-10 22:42 . 2009-05-16 13:44 98336 c:\winnt\system32\perfc009.dat
+ 2008-09-10 22:42 . 2009-05-31 04:10 501682 c:\winnt\system32\perfh009.dat
- 2008-09-10 22:42 . 2009-05-16 13:44 501682 c:\winnt\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2004-08-04 15360]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" [2008-07-31 95744]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-09 39408]
"Google Update"="d:\documents and settings\shokher.gortik\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-02 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"NvCplDaemon"="c:\winnt\system32\NvCpl.dll" [2007-04-29 8429568]
"NvMediaCenter"="c:\winnt\system32\NvMcTray.dll" [2007-04-29 81920]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-04-16 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"NPSMan"="c:\winnt\system32\NPSMan.exe" [2008-09-11 65536]
"BearingPoint TV"="d:\program files\BETV\7398437\Program\BearingPoint TV.exe" [2008-09-11 36903]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-02-20 1191936]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"SBMGRNT.EXE"="c:\progra~1\SafeBoot\SBMGRNT.EXE" [2008-09-11 49212]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-19 185872]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-03-14 125632]
"nwiz"="nwiz.exe" - c:\winnt\system32\nwiz.exe [2007-04-29 1626112]
"NVHotkey"="nvHotkey.dll" - c:\winnt\system32\nvhotkey.dll [2007-04-29 67584]
"SigmatelSysTrayApp"="stsystra.exe" - c:\winnt\stsystra.exe [2007-02-19 303104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-12-05 3900936]
d:\documents and settings\All Users\Start Menu\Programs\Startup\
BearingPoint TV.lnk - d:\program files\BETV\7398437\Program\BearingPoint TV.exe [2008-9-11 36903]
VPN Client.lnk - c:\winnt\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2008-9-18 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"LogonType"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogoff"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
"ForceStartMenuLogoff"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
"ForceStartMenuLogoff"= 1 (0x1)
"NoThemesTab"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\0\0]
"Script"=c:\winnt\system32\BECiscoFirewall.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\BETV\\7398437\\Program\\BearingPoint TV.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5556:TCP"= 5556:TCP:SafeBoot
"4657:TCP"= 4657:TCP:@xpsp2res.dll,-22009
R0 SafeBoot;SafeBoot;c:\winnt\system32\drivers\safeboot.sys [9/11/2008 11:40 AM 30267]
R0 SBAlg;SBAlg;c:\winnt\system32\drivers\sbalg.sys [9/11/2008 11:40 AM 44848]
R1 RsvLock;RsvLock;c:\winnt\system32\drivers\rsvlock.sys [9/11/2008 11:40 AM 4752]
R1 SBFlop;SBFlop;c:\winnt\system32\drivers\sbflop.sys [9/11/2008 11:40 AM 6096]
R1 SbPrcCtl;SbPrcCtl;c:\winnt\system32\drivers\sbprcctl.sys [9/11/2008 11:40 AM 14864]
R2 agnwifi;AT&T Wi-Fi Support Driver;c:\winnt\system32\drivers\agnwifi.sys [9/11/2008 9:57 AM 19328]
R2 MsDtsServer;SQL Server Integration Services;c:\program files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe [10/14/2005 3:45 AM 199384]
R2 msftesql$ACURA;SQL Server FullText Search (ACURA);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe [8/26/2005 4:00 PM 92880]
R2 MSOLAP$ACURA;SQL Server Analysis Services (ACURA);c:\program files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe [10/14/2005 3:46 AM 14557912]
R2 MSSQL$ACURA;SQL Server (ACURA);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [10/14/2005 3:51 AM 28768528]
R2 PowManSvc;Power Management Service;c:\winnt\system32\PowManSvc.exe [9/11/2008 10:00 AM 40960]
R2 SafeBootConfigurationManager;SafeBoot Configuration Manager;c:\program files\SafeBoot\sbmgrnt.exe [9/11/2008 11:40 AM 49212]
R2 Security maintenance service;Security maintenance service;c:\winnt\system32\SecMaint.exe [9/11/2008 10:00 AM 90112]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/26/2009 9:15 AM 101936]
S2 SQLAgent$ACURA;SQL Server Agent (ACURA);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE [10/14/2005 3:51 AM 318680]
S3 IgniteService;IgniteService;d:\program files\BETV\7398437\Program\IgniteService.exe [9/11/2008 10:00 AM 81920]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [3/14/2007 7:48 PM 116416]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808]
.
Contents of the 'Scheduled Tasks' folder
2009-06-02 c:\winnt\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1202660629-682003330-281317.job
- d:\documents and settings\shokher.gortik\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-02 18:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bearingpoint.com/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = hxxp://inside.corp.bearingpoint.com;
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\winnt\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: bearingpoint.com
Trusted Zone: cisco.com\meetings
Trusted Zone: localhost
Trusted Zone: plateau.com
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Web-Based Email Tools - hxxp://email02.secureserver.net/Download.CAB
DPF: {427BD09A-B354-4AF3-89CC-7EB3B315554B} - hxxp://odohrwebnew.od.nih.gov/bizflow/controls/hwau.cab
DPF: {B20D9D6A-0DEC-4d76-9BEF-175896006B4A}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-02 17:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\msftesql$ACURA]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:ACURA"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ccEvtMgr]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SAVRT]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SNDSrvc]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SYMTDI]
"ImagePath"="-"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1308)
c:\program files\SafeBoot\SBGINA.DLL
c:\program files\SafeBoot\SBIPC.DLL
.
Completion time: 2009-06-02 17:28
ComboFix-quarantined-files.txt 2009-06-02 21:28
ComboFix2.txt 2009-06-02 13:38
ComboFix3.txt 2009-06-01 13:58
ComboFix4.txt 2009-05-31 04:11
Pre-Run: 1,143,459,840 bytes free
Post-Run: 1,126,043,648 bytes free
245
———————————————————————————————————————————————————————————-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:55:13 AM, on 6/2/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\SafeBoot\SBMGRNT.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\PowManSvc.exe
C:\WINNT\system32\SecMaint.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\WINNT\system32\StacSV.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\WINNT\TEMP\bwgo0002fa63.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINNT\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
D:\DOCUME~1\SHEKHA~1.GOR\LOCALS~1\Temp\bwgo000350b1.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
D:\Documents and Settings\shokher.gortik\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\DOCUME~1\SHEKHA~1.GOR\LOCALS~1\Temp\bwgo00039b66.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINNT\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\shokher.gortik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\shokher.gortik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\shokher.gortik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bearingpoint.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://inside.corp.bearingpoint.com;
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NPSMan] C:\WINNT\system32\NPSMan.exe
O4 - HKLM\..\Run: [BearingPoint TV] "D:\Program Files\BETV\7398437\Program\BearingPoint TV.exe" -startup
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SBMGRNT.EXE] C:\PROGRA~1\SafeBoot\SBMGRNT.EXE -WinLogon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\shokher.gortik\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - Global Startup: BearingPoint TV.lnk = D:\Program Files\BETV\7398437\Program\BearingPoint TV.exe
O4 - Global Startup: VPN Client.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINNT\system32\GPhotos.scr/200
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file:About:Blank
O15 - Trusted Zone: *.bearingpoint.com (HKLM)
O15 - Trusted Zone: http://meetings.cisco.com (HKLM)
O15 - Trusted Zone: *.plateau.com (HKLM)
O16 - DPF: Web-Based Email Tools - http://email02.secureserver.net/Download.CAB
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.andhrajyothy.com/wfplayer/tdserver.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {427BD09A-B354-4AF3-89CC-7EB3B315554B} (HWAUCtrl Class) - http://odohrwebnew.od.nih.gov/bizflow/controls/hwau.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/50.10/uploader2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {B20D9D6A-0DEC-4d76-9BEF-175896006B4A} (RptViewerAX Class) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://be.webex.com/client/T25L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = corp.kpmgconsulting.com
O17 - HKLM\Software\..\Telephony: DomainName = corp.kpmgconsulting.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = corp.kpmgconsulting.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = corp.bearingpoint.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = corp.kpmgconsulting.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = corp.bearingpoint.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = corp.kpmgconsulting.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = corp.bearingpoint.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.bearingpoint.com
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IgniteService - Unknown owner - D:\Program Files\BETV\7398437\Program\IgniteService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Power Management Service (PowManSvc) - NPS software - C:\WINNT\system32\PowManSvc.exe
O23 - Service: SafeBoot Configuration Manager (SafeBootConfigurationManager) - Control Break International - C:\Program Files\SafeBoot\SBMGRNT.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Security maintenance service - BearingPoint - Global - C:\WINNT\system32\SecMaint.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINNT\system32\StacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
–
End of file - 12898 bytes