This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Problem after using Combofix

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

dhirajmaskara, Now I'd like you to drag your copy of ComboFix to the recycle bin and download a fresh copy. Then double-click it to run. Hopefully it will run to completion and provide a full log.
heres the log
_____________

ComboFix 09-09-03.02 - dhiraj 4-Sep-2009 8:37.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1526.1050 [GMT 5.5:30]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Symantec Client Firewall *disabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\program files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\docs\gs_clnt.pdf
c:\program files\Symantec Client Security\Symantec AntiVirus\DoScan.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\DoScanTVT.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\DWHWizrd.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\dwLdPntScan.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\GenMar.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\I2ldvp3.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\IMail.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\LDVPREG.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\LuaWrap.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\LuHstEdt.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\Navap32.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\NAVAPI32.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\NAVLU.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\NAVNTUTL.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\nlnhook.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\nLNVP.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\nnewdefs.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\notesext.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\OEHeur.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\OEMConfigWizard.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\patch25d.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\PATCH32I.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\PLATFORM.DAT
c:\program files\Symantec Client Security\Symantec AntiVirus\qscomm32.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\QsInfo.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\qspak32.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\ReadMeForDoScanTVT.txt
c:\program files\Symantec Client Security\Symantec AntiVirus\Rec2.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\SAVCProd.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\SavEmail.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\savhelp.chm
c:\program files\Symantec Client Security\Symantec AntiVirus\savmain.chm
c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\savrt.cat
c:\program files\Symantec Client Security\Symantec AntiVirus\savrt.dat
c:\program files\Symantec Client Security\Symantec AntiVirus\savrt.inf
c:\program files\Symantec Client Security\Symantec AntiVirus\savrt.sys
c:\program files\Symantec Client Security\Symantec AntiVirus\SAVRT\0943NAV~.TMP
c:\program files\Symantec Client Security\Symantec AntiVirus\SavRT32.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\savrtpel.cat
c:\program files\Symantec Client Security\Symantec AntiVirus\savrtpel.inf
c:\program files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys
c:\program files\Symantec Client Security\Symantec AntiVirus\savsess.txt
c:\program files\Symantec Client Security\Symantec AntiVirus\SCANCFG.DAT
c:\program files\Symantec Client Security\Symantec AntiVirus\SCANDLVR.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SCANDRES.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SDPCK32I.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\SDSNAPSX.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\SDSND32I.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SDSOK32I.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SDSTP32I.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SMSTR32I.DLL
c:\program files\Symantec Client Security\Symantec AntiVirus\SRTLEXCL.DAT
c:\program files\Symantec Client Security\Symantec AntiVirus\SRTSEXCL.DAT
c:\program files\Symantec Client Security\Symantec AntiVirus\SymProtectStorage.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\SystemSnapshotRules.bin
c:\program files\Symantec Client Security\Symantec AntiVirus\VPC32.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\VPDN_LU.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\vpmsece3.dll
c:\program files\Symantec Client Security\Symantec AntiVirus\VPTray.exe
c:\windows\system32\019A.dat
c:\windows\system32\drivers\ecbqyvrxmxvxtuij.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SavRoam


((((((((((((((((((((((((( Files Created from 2009-08-04 to 2009-09-04 )))))))))))))))))))))))))))))))
.

2009-09-02 17:39 . 2009-09-02 17:48 ——– d—–w- C:\Rooter$
2009-08-29 07:45 . 2009-08-29 07:45 ——– d—–w- c:\documents and settings\dhiraj\Application Data\IObit
2009-08-29 07:45 . 2009-08-29 07:45 ——– d—–w- c:\program files\IObit
2009-08-29 07:30 . 2009-08-29 07:30 0 —-a-w- c:\windows\nsreg.dat
2009-08-29 07:30 . 2009-08-29 07:30 ——– d—–w- c:\documents and settings\dhiraj\Local Settings\Application Data\Mozilla
2009-08-28 17:34 . 2009-08-28 17:34 ——– d—–w- c:\program files\Trend Micro
2009-08-24 05:59 . 2009-08-24 05:59 ——– d—–w- c:\documents and settings\dhiraj\Local Settings\Application Data\pjwjlldf
2009-08-24 05:59 . 2009-08-24 05:59 ——– d—–w- c:\documents and settings\dhiraj\Application Data\pjwjlldf
2009-08-23 06:13 . 2009-08-23 06:13 ——– d—–w- c:\windows\ie8updates
2009-08-22 23:41 . 2009-08-22 23:41 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\pjwjlldf
2009-08-22 23:41 . 2009-08-22 23:41 ——– d—–w- c:\documents and settings\NetworkService\Application Data\pjwjlldf
2009-08-22 10:07 . 2009-08-22 10:07 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Malwarebytes
2009-08-22 10:07 . 2009-08-03 08:06 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 10:07 . 2009-08-22 10:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-22 10:07 . 2009-08-22 10:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 10:07 . 2009-08-03 08:06 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-22 08:31 . 2009-08-22 08:31 ——– d—–w- c:\program files\NIC
2009-08-22 02:21 . 2009-08-22 02:21 ——– d—–w- c:\program files\Aladdin
2009-08-21 04:02 . 2009-08-21 04:02 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-21 03:45 . 2009-08-21 03:45 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-08-21 02:59 . 2009-07-03 17:09 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2009-08-21 02:59 . 2009-07-03 17:09 246272 ——w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-21 02:28 . 2009-08-21 02:28 ——– d—–w- c:\program files\FileSignerPlus
2009-08-20 18:35 . 2009-08-20 18:35 ——– d-sh–w- c:\documents and settings\dhiraj\IECompatCache
2009-08-20 18:34 . 2009-08-20 18:34 ——– d-sh–w- c:\documents and settings\dhiraj\PrivacIE
2009-08-20 18:31 . 2009-08-20 18:31 ——– d-sh–w- c:\documents and settings\dhiraj\IETldCache
2009-08-20 18:09 . 2009-08-20 18:10 ——– dc-h–w- c:\windows\ie8
2009-08-12 17:26 . 2009-08-12 17:26 ——– d—–w- c:\windows\ServicePackFiles
2009-08-12 16:31 . 2009-06-05 07:42 655872 ——w- c:\windows\system32\dllcache\mstscax.dll
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- c:\program files\MSBuild
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- c:\program files\Reference Assemblies
2009-08-12 09:33 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-12 09:33 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-12 09:33 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-12 09:33 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-12 09:33 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-12 09:33 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-12 09:33 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- C:\68d61042816a94014e
2009-08-12 09:32 . 2009-08-12 09:41 ——– d—–w- c:\windows\SxsCaPendDel
2009-08-12 09:29 . 2009-08-12 09:29 ——– d—–w- c:\program files\MSXML 6.0
2009-08-12 08:05 . 2009-08-12 08:05 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Sonic
2009-08-12 08:04 . 2009-08-12 08:04 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Leadertech
2009-08-05 09:11 . 2009-08-05 09:11 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-04 03:13 . 2008-10-22 06:47 1683744 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-09-04 03:13 . 2008-10-22 06:47 71337760 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-04 02:54 . 2007-05-20 02:36 ——– d—–w- c:\program files\Microsoft SQL Server
2009-09-04 02:42 . 2008-06-18 18:45 ——– d—–w- c:\program files\Common Files\Akamai
2009-09-03 18:26 . 2008-02-10 16:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Metacafe
2009-09-03 18:26 . 2009-04-18 04:58 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Metacafe
2009-09-03 18:26 . 2008-02-10 16:00 ——– d—–w- c:\program files\Metacafe
2009-09-03 17:17 . 2008-10-22 06:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-09-03 17:13 . 2008-10-22 06:47 956252 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-03 17:13 . 2008-10-22 06:47 159716 –sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-09-03 07:04 . 2009-09-03 07:04 ——– d—–w- c:\program files\ESET
2009-08-30 06:14 . 2007-05-19 03:03 5427 —-a-w- c:\windows\system32\EGATHDRV.SYS
2009-08-27 09:10 . 2009-04-11 14:29 191352 —-a-w- c:\documents and settings\dhiraj\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 17:49 . 2008-10-15 12:31 ——– d—–w- c:\program files\CCleaner
2009-08-26 01:22 . 2007-05-19 03:03 ——– d—–w- c:\program files\Google
2009-08-25 13:05 . 2007-05-19 06:45 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-08-24 06:21 . 2007-08-19 21:15 ——– d—–w- c:\program files\EphPod
2009-08-24 06:21 . 2007-05-19 02:40 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-12 08:04 . 2007-05-19 02:52 ——– d—–w- c:\program files\Common Files\Sonic Shared
2009-08-05 09:11 . 1980-01-01 07:00 204800 ——w- c:\windows\system32\mswebdvd.dll
2009-08-02 18:47 . 2009-07-31 18:59 ——– d—–w- c:\documents and settings\dhiraj\Application Data\LimeWire
2009-07-29 12:13 . 2009-07-29 12:12 ——– d—–w- c:\documents and settings\dhiraj\Application Data\U3
2009-07-27 19:39 . 2009-07-27 19:39 ——– d—–w- c:\program files\FLV Converter
2009-07-27 18:52 . 2009-07-27 18:52 ——– d—–w- c:\program files\KeepV Converter
2009-07-27 18:36 . 2009-07-13 05:02 ——– d—–w- c:\program files\Cucusoft
2009-07-27 18:35 . 2009-07-27 18:31 ——– d—–w- c:\documents and settings\dhiraj\Application Data\GetRightToGo
2009-07-17 18:55 . 1980-01-01 07:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 18:13 . 1980-01-01 07:00 286208 ——w- c:\windows\system32\wmpdxm.dll
2009-07-09 17:35 . 2009-07-09 17:35 ——– d—–w- c:\program files\Windows Mobile Device Handbook
2009-07-03 17:09 . 1980-01-01 07:00 915456 ——w- c:\windows\system32\wininet.dll
2009-07-01 09:46 . 2009-07-27 18:36 94854 —-a-w- c:\windows\system32\HKCU_GNU.reg
2009-06-25 18:36 . 1980-01-01 07:00 95744 —-a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 1980-01-01 07:00 661504 —-a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 1980-01-01 07:00 517120 —-a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 1980-01-01 07:00 48640 —-a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 1980-01-01 07:00 471552 —-a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 1980-01-01 07:00 47104 —-a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 1980-01-01 07:00 225280 —-a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 1980-01-01 07:00 186880 —-a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 1980-01-01 07:00 177152 —-a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 1980-01-01 07:00 16896 —-a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 1980-01-01 07:00 138240 —-a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 1980-01-01 07:00 123392 —-a-w- c:\windows\system32\mqrtdep.dll
2009-06-25 08:17 . 1980-01-01 07:00 729600 ——w- c:\windows\system32\lsasrv.dll
2009-06-25 08:17 . 1980-01-01 07:00 59392 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:17 . 1980-01-01 07:00 56320 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:17 . 1980-01-01 07:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:17 . 1980-01-01 07:00 168448 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:17 . 1980-01-01 07:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-22 11:49 . 1980-01-01 07:00 19968 —-a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 1980-01-01 07:00 117248 —-a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 1980-01-01 07:00 4608 —-a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 1980-01-01 07:00 91776 —-a-w- c:\windows\system32\drivers\mqac.sys
2009-06-22 11:35 . 1980-01-01 07:00 92544 ——w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:55 . 1980-01-01 07:00 82432 ——w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 1980-01-01 07:00 119808 ——w- c:\windows\system32\t2embed.dll
2009-06-12 11:50 . 1980-01-01 07:00 80896 ——w- c:\windows\system32\tlntsess.exe
2009-06-12 11:50 . 1980-01-01 07:00 76288 ——w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 1980-01-01 07:00 84992 ——w- c:\windows\system32\avifil32.dll
2009-06-10 06:32 . 1980-01-01 07:00 132096 ——w- c:\windows\system32\wkssvc.dll
2009-06-08 08:59 . 2008-01-23 12:37 5194 —-a-w- c:\program files\Exportcerts.txt
2009-06-08 08:59 . 2008-01-23 12:37 34 —-a-w- c:\program files\Exportcerts1.txt
2007-06-02 03:46 . 2007-06-02 03:32 526 ——w- c:\program files\DataCardInfo.ini
2006-02-23 15:01 . 2007-06-02 03:32 0 -c—-w- c:\program files\EW600APICfg.dat
2006-01-11 11:18 . 2007-06-02 03:32 294912 ——w- c:\program files\vWTP.mdb
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-20 39408]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2005-11-07 106496]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Metacafe.lnk - c:\program files\Metacafe\MetacafeAgent.exe [2009-2-18 145736]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2007-5-20 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2005-12-22 01:42 32768 ——w- c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-12-08 21:59 39936 ——w- c:\windows\system32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 06:45 28672 ——w- c:\windows\system32\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-12-01 03:16 24576 ——w- c:\windows\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd csspwntfy

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CONE EXPERT Grey Report.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CONE EXPERT Grey Report.lnk
backup=c:\windows\pss\CONE EXPERT Grey Report.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^REPORTS.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\REPORTS.lnk
backup=c:\windows\pss\REPORTS.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Dhiraj.MAHABIR^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\Dhiraj.MAHABIR\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Dhiraj.MAHABIR^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=c:\documents and settings\Dhiraj.MAHABIR\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^dhiraj^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\dhiraj\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"STCAgent"=2 (0x2)
"btwdins"=2 (0x2)
"ETOKSRV"=2 (0x2)
"DefWatch"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AcPrfMgrSvc"=2 (0x2)
"Autodesk Licensing Service"=3 (0x3)
"SymSecurePort"=2 (0x2)
"Symantec AntiVirus"=2 (0x2)
"SPBBCSvc"=3 (0x3)
"gusvc"=3 (0x3)
"ccPwdSvc"=3 (0x3)
"ccProxy"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4260:TCP"= 4260:TCP:@xpsp2res.dll,-22009

R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [19-May-2007 8:11 AM 85760]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [19-May-2007 8:11 AM 4736]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [19-May-2007 8:34 AM 4442]
R2 Akamai;Akamai;c:\windows\System32\svchost.exe -k Akamai [01-Jan-1980 12:30 PM 14336]
R2 eTSrv;ETOKSRV;c:\program files\Aladdin\eToken\PKIClient\x32\eTSrv.exe [03-Nov-2008 1:29 PM 7168]
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [22-Dec-2005 5:44 AM 12544]
R2 IntelliAdminRC3;IntelliAdminRC3;c:\windows\IntelliAdminRC3\Agent32.exe [03-Feb-2009 1:51 PM 2279904]
R2 PrivateDisk;PrivateDisk;c:\program files\IBM ThinkVantage\SafeGuard PrivateDisk\privatediskm.sys [16-Nov-2005 1:41 AM 46142]
R2 smi2;smi2;c:\program files\SMI2\smi2.sys [22-Dec-2005 5:15 AM 3968]
R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [09-Dec-2005 3:14 AM 3328]
R3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;c:\windows\system32\drivers\ewusbmdm.sys [19-May-2007 12:45 PM 65152]
R3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;c:\windows\system32\drivers\ewusbser.sys [19-May-2007 12:45 PM 65152]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13-Dec-2007 1:28 PM 24592]
S1 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\oxser.sys [23-Mar-2008 8:41 PM 49792]
S3 AKSUP;AKSUP;c:\windows\system32\drivers\aksup.sys [15-Apr-2009 4:01 PM 34472]
S3 BTPCCARD;Bluetooth BCSP Transport for Pc Card;c:\windows\system32\drivers\btpcbcsp.sys [01-Jul-2003 12:30 PM 232444]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\DRIVERS\CSVirtA.sys –> c:\windows\system32\DRIVERS\CSVirtA.sys [?]
S3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys –> c:\windows\system32\drivers\vvftav303.sys [?]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\Drivers\usbVM303.sys –> c:\windows\system32\Drivers\usbVM303.sys [?]
S4 ConeExpertUCOM;ConeExpertUCOM;c:\coexpert\bin\WatchUcom.exe ConeExpertUCOM –> c:\coexpert\bin\WatchUcom.exe ConeExpertUCOM [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-01-25 c:\windows\Tasks\Dhiraj 23102008.job
- c:\windows\system32\ntbackup.exe [1980-01-01 12:00]

2009-09-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-926495626-1003886262-1936394565-1004.job
- c:\documents and settings\Dhiraj.MAHABIR\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-07 02:17]

2008-09-23 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2007-05-19 08:12]

2009-08-09 c:\windows\Tasks\Scheduled backup of T60.job
- c:\windows\system32\ntbackup.exe [1980-01-01 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.rediff.com/
IE: &Download with &DAP - c:\progra~1\DAP\dapextie.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {7A98F4DF-39CA-46EE-94E0-AC5D4D412C79} = 192.168.0.101
TCP: {BA1F53B8-1E72-466F-B978-A9FC622BCD7F} = 192.9.100.1,192.9.100.100
DPF: {23ACBF1D-D7AF-4236-AD8C-CADF14234B78} - hxxp://dgftcom.nic.in/(n)CodeDGFT_new.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} - hxxp://122.160.111.150/WebDiginet.CAB
DPF: {BE90DF74-A983-4BBB-A9C1-F2C90807F548} - hxxp://www.mca.gov.in/DCAPortalWeb/dca/jsp/mydca/pki/AssureSignControl.cab
FF - ProfilePath - c:\documents and settings\dhiraj\Application Data\Mozilla\Firefox\Profiles\2v0krwal.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.rediff.com/|http://economictimes.indiatimes.com/
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-04 08:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\docume~1\dhiraj\LOCALS~1\Temp\Perflib_Perfdata_434.dat 16384 bytes

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\ccEvtMgr]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SAVRT]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SNDSrvc]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SYMTDI]
"ImagePath"="-"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1560)
c:\windows\system32\vrlogon.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\klogon.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\windows\system32\biologon.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\remote.dll
c:\windows\system32\tphklock.dll
c:\program files\ThinkVantage Fingerprint Software\crypto.dll
c:\windows\system32\mobilev.acm
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\windows\system32\igfxdev.dll
c:\windows\system32\notifyf2.dll

- - - - - - - > 'lsass.exe'(1616)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\IBM ThinkVantage\Client Security Solution\csspwntfy.dll
c:\windows\system32\WTSAPI32.dll
c:\program files\IBM ThinkVantage\Client Security Solution\ibmtsp.dll
c:\program files\IBM ThinkVantage\Client Security Solution\tcsrpc.dll
c:\program files\IBM ThinkVantage\Client Security Solution\cssuserdatadispatcher.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
c:\program files\Bonjour\mdnsNSP.dll

- - - - - - - > 'explorer.exe'(6024)
c:\windows\system32\WININET.dll
c:\windows\system32\PROCHLP.DLL
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-09-04 8:46
ComboFix-quarantined-files.txt 2009-09-04 03:16
ComboFix2.txt 2009-08-24 12:11

Pre-Run: 10,554,216,448 bytes free
Post-Run: 10,524,327,936 bytes free

424 — E O F — 2009-08-26 12:17
dhirajmaskara,

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.

Cleanup

  • Double click on OTM to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
thank you cleaning up the system .. but the initial problem is kind of still there .. maybe something to do with settings now .. like i was surfing and one of the websites warned that "cookies" are not enabled .. i'm also having trouble in logging on a govt website for Company Affairs , where in i need to log in to submit some returns .. i have metacafe installed and earlier i was able to download videos from metacafe which not happening now..
dhirajmaskara,

Let's get scan for a little different look at your system.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 22:29:49.56 on 04-Sep-2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1526.1008 [GMT 5.5:30] AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C} FW: Symantec Client Firewall *disabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} ============== Running Processes =============== C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\system32\IPSSVC.EXE C:\WINDOWS\System32\svchost.exe -k Akamai C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files\Aladdin\eToken\PKIClient\x32\eTSrv.exe C:\WINDOWS\IntelliAdminRC3\Agent32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\TPHDEXLG.EXE C:\WINDOWS\system32\TpKmpSVC.exe C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\TpShocks.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\PROGRA~1\MICROS~3\rapimgr.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Microsoft Office\Office10\EXCEL.EXE C:\Documents and Settings\dhiraj\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.rediff.com/ BHO: DAPBHO Class: {0096cc0a-623c-4829-ad9c-19af0dc9d8fe} - c:\program files\dap\DAPIEBar.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_10\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll TB: DAP Bar: {62999427-33fc-4baf-9c9c-bce6bd127f08} - c:\program files\dap\DAPIEBar.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Wolfram Toolbar: {9e709aef-74f7-4da3-a7fc-f3e2d5a8d793} - c:\program files\wolfram research\wolframtoolbar\1.0\WolframBands32.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe" uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [TpShocks] TpShocks.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\metacafe.lnk - c:\program files\metacafe\MetacafeAgent.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe IE: &Download with &DAP - c:\progra~1\dap\dapextie.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {669695BC-A811-4A9D-8CDF-BA8C795F261C} - c:\progra~1\dap\DAP.EXE IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - c:\program files\lenovo\pkgmgr\\PkgMgr.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 7.0\SCIEPlgn.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll Trusted Zone: metacafe.com\www DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} - hxxp://www.bitstream.com/wfplayer/tdserver.cab DPF: {23ACBF1D-D7AF-4236-AD8C-CADF14234B78} - hxxp://dgftcom.nic.in/(n)CodeDGFT_new.CAB DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {6F7864F9-DB33-11D3-8166-0060B0F885E6} - hxxps://onsite.safescrypt.com/services/SafescryptLimitedDGFTOnlineCA/vspta3.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-150-windows-i586.cab DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://floridakeysmedia.tv/axiscam/Codebase/AxisCamControl.ocx DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} - hxxp://122.160.111.150/WebDiginet.CAB DPF: {BE90DF74-A983-4BBB-A9C1-F2C90807F548} - hxxp://www.mca.gov.in/DCAPortalWeb/dca/jsp/mydca/pki/AssureSignControl.cab DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4.2/jinstall-142-win.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-150-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: {7A98F4DF-39CA-46EE-94E0-AC5D4D412C79} = 192.168.0.101 TCP: {BA1F53B8-1E72-466F-B978-A9FC622BCD7F} = 192.9.100.1,192.9.100.100 Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: ACNotify - ACNotify.dll Notify: igfxcui - igfxdev.dll Notify: klogon - c:\windows\system32\klogon.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll Notify: psfus - psqlpwd.dll Notify: tpfnf2 - notifyf2.dll Notify: tphotkey - tphklock.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Notification Packages = scecli psqlpwd csspwntfy ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\dhiraj\applic~1\mozilla\firefox\profiles\2v0krwal.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.rediff.com/|http://economictimes.indiatimes.com/ FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava11.dll FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava12.dll FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava13.dll FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava14.dll FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava32.dll FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJPI150_10.dll FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPOJI610.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2007-10-31 112144] R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [2007-5-19 85760] R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2007-5-19 11520] R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2007-5-19 5248] R1 klif;Klif;c:\windows\system32\drivers\klif.sys [2007-12-28 195344] R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [2007-5-19 4736] R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2007-5-19 4442] R2 Akamai;Akamai;c:\windows\system32\svchost.exe -k Akamai [1980-1-1 14336] R2 eTSrv;ETOKSRV;c:\program files\aladdin\etoken\pkiclient\x32\eTSrv.exe [2008-11-3 7168] R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [2005-12-22 12544] R2 IntelliAdminRC3;IntelliAdminRC3;c:\windows\intelliadminrc3\Agent32.exe [2009-2-3 2279904] R2 PrivateDisk;PrivateDisk;c:\program files\ibm thinkvantage\safeguard privatedisk\privatediskm.sys [2005-11-16 46142] R2 smi2;smi2;c:\program files\smi2\smi2.sys [2005-12-22 3968] R2 smihlp;SMI helper driver;c:\program files\thinkvantage fingerprint software\smihlp.sys [2005-12-9 3328] R3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;c:\windows\system32\drivers\ewusbmdm.sys [2007-5-19 65152] R3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;c:\windows\system32\drivers\ewusbser.sys [2007-5-19 65152] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2007-12-13 24592] S1 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\oxser.sys [2008-3-23 49792] S1 SAVRTPEL;SAVRTPEL;\??\c:\program files\symantec client security\symantec antivirus\savrtpel.sys –> c:\program files\symantec client security\symantec antivirus\Savrtpel.sys [?] S2 AVP;Kaspersky Internet Security 7.0;c:\program files\kaspersky lab\kaspersky internet security 7.0\avp.exe [2008-2-8 227856] S3 AKSUP;AKSUP;c:\windows\system32\drivers\aksup.sys [2009-4-15 34472] S3 BTPCCARD;Bluetooth BCSP Transport for Pc Card;c:\windows\system32\drivers\btpcbcsp.sys [2003-7-1 232444] S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\drivers\csvirta.sys –> c:\windows\system32\drivers\CSVirtA.sys [?] S3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20051205.008\naveng.sys [2007-5-19 77816] S3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20051205.008\navex15.sys [2007-5-19 750424] S3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys –> c:\windows\system32\drivers\vvftav303.sys [?] S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\usbvm303.sys –> c:\windows\system32\drivers\usbVM303.sys [?] S4 ccEvtMgr;Symantec Event Manager;- –> - [?] S4 ccProxy;Symantec Network Proxy;c:\program files\common files\symantec shared\ccProxy.exe [2005-6-2 239216] S4 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-6-2 83568] S4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-6-2 161392] S4 ConeExpertUCOM;ConeExpertUCOM;c:\coexpert\bin\watchucom.exe coneexpertucom –> c:\coexpert\bin\WatchUcom.exe ConeExpertUCOM [?] S4 SAVRT;SAVRT;- –> - [?] S4 Symantec AntiVirus;Symantec AntiVirus;"c:\program files\symantec client security\symantec antivirus\rtvscan.exe" –> c:\program files\symantec client security\symantec antivirus\Rtvscan.exe [?] =============== Created Last 30 ================ 2009-09-03 12:34 –d—– c:\program files\ESET 2009-08-29 13:15 –d—– c:\docume~1\dhiraj\applic~1\IObit 2009-08-29 13:15 –d—– c:\program files\IObit 2009-08-28 23:04 –d—– c:\program files\Trend Micro 2009-08-24 17:39 –d—– c:\windows\system32\dllcache\cache 2009-08-24 17:13 a-dshr– C:\cmdcons 2009-08-24 11:29 –d—– c:\docume~1\dhiraj\applic~1\pjwjlldf 2009-08-23 11:43 –d—– c:\windows\ie8updates 2009-08-22 15:37 –d—– c:\docume~1\dhiraj\applic~1\Malwarebytes 2009-08-22 15:37 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-22 15:37 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-22 15:37 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-22 15:37 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-22 14:01 –d—– c:\program files\NIC 2009-08-22 07:51 –d—– c:\program files\Aladdin 2009-08-21 08:29 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll 2009-08-21 08:29 12,800 ——– c:\windows\system32\dllcache\xpshims.dll 2009-08-21 07:58 –d—– c:\program files\FileSignerPlus 2009-08-21 00:05 –dsh— c:\documents and settings\dhiraj\IECompatCache 2009-08-21 00:04 –dsh— c:\documents and settings\dhiraj\PrivacIE 2009-08-21 00:01 –dsh— c:\documents and settings\dhiraj\IETldCache 2009-08-20 23:39 -cd-h— c:\windows\ie8 2009-08-17 10:57 4,744,641,394 a——- C:\DhirajBackUp160809.rar 2009-08-13 10:08 1,089,601 ——– c:\windows\system32\dllcache\ntprint.cat 2009-08-12 22:56 –d—– c:\windows\ServicePackFiles 2009-08-12 22:43 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx 2009-08-12 22:01 655,872 ——– c:\windows\system32\dllcache\mstscax.dll 2009-08-12 15:03 –d—– c:\windows\system32\XPSViewer 2009-08-12 15:03 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-08-12 15:03 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll 2009-08-12 15:03 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-12 15:03 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-08-12 15:03 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-12 15:03 117,760 ——– c:\windows\system32\prntvpt.dll 2009-08-12 15:03 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-12 15:03 –d—– C:\68d61042816a94014e 2009-08-12 15:02 –d—– c:\windows\SxsCaPendDel 2009-08-12 14:59 –d—– c:\program files\MSXML 6.0 ==================== Find3M ==================== 2009-09-04 22:27 1,693,984 a–sh— c:\windows\system32\drivers\fidbox2.dat 2009-09-04 22:17 71,488,288 a–sh— c:\windows\system32\drivers\fidbox.dat 2009-09-04 09:26 959,036 a–sh— c:\windows\system32\drivers\fidbox.idx 2009-09-04 09:26 161,276 a–sh— c:\windows\system32\drivers\fidbox2.idx 2009-08-30 11:44 5,427 a——- c:\windows\system32\EGATHDRV.SYS 2009-08-19 14:30 192,200 a——- c:\docume~1\dhiraj\applic~1\GDIPFONTCACHEV1.DAT 2009-08-05 14:41 204,800 ——– c:\windows\system32\mswebdvd.dll 2009-08-05 14:41 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll 2009-07-19 18:48 5,937,152 a——- c:\windows\system32\dllcache\mshtml.dll 2009-07-19 18:48 5,937,152 a——- c:\windows\system32\dllcache\cache\mshtml.dll 2009-07-19 18:48 11,067,392 a——- c:\windows\system32\dllcache\ieframe.dll 2009-07-18 00:25 58,880 a——- c:\windows\system32\atl.dll 2009-07-18 00:25 58,880 ——– c:\windows\system32\dllcache\atl.dll 2009-07-13 23:43 10,841,088 ——– c:\windows\system32\dllcache\wmp.dll 2009-07-13 23:43 286,208 ——– c:\windows\system32\wmpdxm.dll 2009-07-13 23:43 286,208 ——– c:\windows\system32\dllcache\wmpdxm.dll 2009-07-10 19:12 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll 2009-07-03 22:39 915,456 a——- c:\windows\system32\dllcache\wininet.dll 2009-07-03 22:39 915,456 a——- c:\windows\system32\dllcache\cache\wininet.dll 2009-07-03 22:39 915,456 ——– c:\windows\system32\wininet.dll 2009-07-03 22:39 1,208,832 a——- c:\windows\system32\dllcache\urlmon.dll 2009-07-03 22:39 206,848 a——- c:\windows\system32\dllcache\occache.dll 2009-07-03 22:39 594,432 a——- c:\windows\system32\dllcache\msfeeds.dll 2009-07-03 22:39 55,296 a——- c:\windows\system32\dllcache\msfeedsbs.dll 2009-07-03 22:39 1,985,536 a——- c:\windows\system32\dllcache\iertutil.dll 2009-07-03 22:39 25,600 a——- c:\windows\system32\dllcache\jsproxy.dll 2009-07-03 22:39 184,320 a——- c:\windows\system32\dllcache\iepeers.dll 2009-07-03 22:39 386,048 a——- c:\windows\system32\dllcache\iedkcs32.dll 2009-07-03 16:31 173,056 a——- c:\windows\system32\dllcache\ie4uinit.exe 2009-07-01 15:16 94,854 a——- c:\windows\system32\HKCU_GNU.reg 2009-06-29 21:42 133,120 ——– c:\windows\system32\dllcache\extmgr.dll 2009-06-29 16:37 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-06-25 13:47 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 13:47 168,448 a——- c:\windows\system32\schannel.dll 2009-06-25 13:47 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 13:47 59,392 a——- c:\windows\system32\wdigest.dll 2009-06-25 13:47 56,320 a——- c:\windows\system32\secur32.dll 2009-06-25 13:47 729,600 ——– c:\windows\system32\lsasrv.dll 2009-06-25 13:47 729,600 ——– c:\windows\system32\dllcache\lsasrv.dll 2009-06-25 13:47 301,568 ——– c:\windows\system32\dllcache\kerberos.dll 2009-06-25 13:47 168,448 ——– c:\windows\system32\dllcache\schannel.dll 2009-06-25 13:47 136,192 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-06-25 13:47 59,392 ——– c:\windows\system32\dllcache\wdigest.dll 2009-06-25 13:47 56,320 ——– c:\windows\system32\dllcache\secur32.dll 2009-06-22 17:19 117,248 a——- c:\windows\system32\mqtgsvc.exe 2009-06-22 17:19 19,968 a——- c:\windows\system32\mqbkup.exe 2009-06-22 17:19 117,248 ——– c:\windows\system32\dllcache\mqtgsvc.exe 2009-06-22 17:19 19,968 ——– c:\windows\system32\dllcache\mqbkup.exe 2009-06-22 17:19 4,608 a——- c:\windows\system32\mqsvc.exe 2009-06-22 17:19 4,608 ——– c:\windows\system32\dllcache\mqsvc.exe 2009-06-22 17:18 91,776 ——– c:\windows\system32\dllcache\mqac.sys 2009-06-22 17:05 92,544 ——– c:\windows\system32\dllcache\ksecdd.sys 2009-06-16 20:25 119,808 ——– c:\windows\system32\t2embed.dll 2009-06-16 20:25 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-06-16 20:25 82,432 ——– c:\windows\system32\fontsub.dll 2009-06-16 20:25 82,432 ——– c:\windows\system32\dllcache\fontsub.dll 2009-06-12 17:20 80,896 ——– c:\windows\system32\tlntsess.exe 2009-06-12 17:20 80,896 ——– c:\windows\system32\dllcache\tlntsess.exe 2009-06-12 17:20 76,288 ——– c:\windows\system32\telnet.exe 2009-06-12 17:20 76,288 ——– c:\windows\system32\dllcache\telnet.exe 2009-06-10 19:51 84,992 ——– c:\windows\system32\dllcache\avifil32.dll 2009-06-10 19:51 84,992 ——– c:\windows\system32\avifil32.dll 2009-06-10 12:02 132,096 ——– c:\windows\system32\wkssvc.dll 2009-06-10 12:02 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll 2009-06-08 14:29 5,194 a——- c:\program files\Exportcerts.txt 2009-06-08 14:29 34 a——- c:\program files\Exportcerts1.txt 2007-06-02 09:16 526 ——– c:\program files\DataCardInfo.ini 2006-02-23 20:31 0 -c—— c:\program files\EW600APICfg.dat 2006-01-11 16:48 294,912 ——– c:\program files\vWTP.mdb ============= FINISH: 22:30:14.68 ===============

Attachments:

dhirajmaskara,

Do you recognize this? Domain = MAHABIR

Your Java is out of date and you have other old versions still on your computer, those old versions are now a security vulnerability:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer - Version 6 update 16
yes .. mahabir is a domain in our network .. i have installed JRE6 u16 .. it shows in the list of installed programs .. i have not restarted the machine , yet what do you recommend next ?
dhirajmaskara, I'm assuming you are trying to browse with Firefox. If I'm correct please try the following: 1. Click the Tools menu. 2. Select Options. 3. Click the Privacy tab. 4. Select the 'Accept cookies from sites' checkbox. 5. Click the OK button. Then see if you can access your websites. If this doesn't work, please try to access them using Internet Explorer and let me know if you get the same results.
i do not use firefox .. in fact i had downloaded it when i was getting problems with IE .. but firefox has been giving the same problems .. i tried after enabling cookies also .. same situation. could you look at all the security settings of IE by some s/ware and then suggest some changes ? i also feel that there something to do with some connection type of the internet .. some port or socket .. since yesterday i was trying to log onto the forum using the normal broadband i use daily but it was just not opening the site .. so finally now i have connected using my data card and disconnected from the network .. only then i have been able to get here and post this.
dhirajmaskara,

Unfortunately I think we have exceeded my knowledge. I'm just not seeing anything else. I suggest that you post in the windows forum and seek guidance from the Tech Team. When you do that, please provide a link there back to this thread so that they can see your logs.

Does this make sense to you?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI