This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect, websites attacking

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The Malwarebytes software is continually blocking malicious websites even when a web browser is not opened. Sometimes I will click on a link in Google and get to a page that is blocked by my firewall.

I am running Windows XP service pack 3.

Below is my Hijackthis log

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:16:08 AM, on 3/1/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArchestrA\aaLogger.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Canary Labs\Historian\CLIHistorian.exe
C:\Program Files\Canary Labs\Historian\CLIHistorianMonitor.exe
C:\WINDOWS\system32\cusrvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Rockwell\EventServer.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe
C:\Program Files\Common Files\ArchestrA\NTServApp.exe
C:\Program Files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe
C:\Program Files\Rockwell Software\FactoryTalk Activation\flexsvr.exe
C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Common Files\Rockwell\NmspHost.exe
C:\Program Files\Common Files\Rockwell\RdcyHost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe
C:\Program Files\Rockwell Software\RSSql\rssql_cfg_server.exe
C:\Program Files\Rockwell Software\RSSql\rssql_comp_storer.exe
C:\Program Files\Common Files\Rockwell\RsvcHost.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\ArchestrA\slssvc.exe
C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\StacSV.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe
C:\Program Files\RealVNC\WinVNC\winvnc.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Schneider Electric\Vijeo-Designer\Vijeo-Frame\XBTZG935\XBTZG935svr.exe
C:\XLReporter\XLReporter.exe
C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe
C:\Program Files\Common Files\Rockwell\RnaDirServer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Rockwell\RNADirMultiplexor.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\dpmw32.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Program Files\NCH Swift Sound\Verbose\verbose.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Canary Labs\Shared\TrayIcon.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\blacy\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2801948
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.interstatebatteries.com/cs_esto…x?ZipCode=46750
R3 - URLSearchHook: (no name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
R3 - URLSearchHook: (no name) - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - (no file)
O1 - Hosts: 128.1.0.100 Server6.usmnet.com Server6
O1 - Hosts: 128.1.0.52 DFX5000ia.usmnet.com DFX5000ia # Epson Office
O1 - Hosts: 128.1.0.68 HP2100ia.usmnet.com HP2100ia # Engineering/QC
O1 - Hosts: 128.2.0.15 usmnet.usmnet.com USMNET
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\DellTPad\Apoint.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] "C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe"
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\system32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [UsbCipHelper] C:\Program Files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [Verbose] "C:\Program Files\NCH Swift Sound\Verbose\verbose.exe" -logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Canary Labs TrayIcon] C:\Program Files\Canary Labs\Shared\TrayIcon.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Mobile User VPN.lnk = C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office11\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office11\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1243368827155
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://rockwellautomation.webex.com/client…ort/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArchestrA Logger (aaLogger) - Invensys Systems, Inc. - C:\Program Files\Common Files\ArchestrA\aaLogger.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Canary Labs Enterprise Historian - Canary Labs, Inc. - C:\Program Files\Canary Labs\Historian\CLIHistorian.exe
O23 - Service: Canary Labs Error Log Server - Canary Labs, Inc. - C:\Program Files\Canary Labs\Shared\ErrorLogServer.exe
O23 - Service: Canary Labs HDA Server - Canary Labs, Inc. - C:\Program Files\Canary Labs\Historian\HDAServer.exe
O23 - Service: Canary Labs Enterprise Historian Monitor (Canary_Labs_Historian_Monitor) - Canary Labs, Inc. - C:\Program Files\Canary Labs\Historian\CLIHistorianMonitor.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: dnWhoDisp - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSLINX\dnwhodisp.exe
O23 - Service: Rockwell Event Multiplexer (EventClientMultiplexer) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe
O23 - Service: Rockwell Event Server (EventServer) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\EventServer.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FactoryTalk Activation Service - Macrovision Corporation - C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FS Service Control - Invensys Systems, Inc. - C:\Program Files\Common Files\ArchestrA\NTServApp.exe
O23 - Service: FactoryTalk Activation Helper (FTActivationBoost) - Rockwell Automation Inc. - C:\Program Files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Harmony - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSCommon\RSOBSERV.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IreIKE) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Rockwell Namespace Services (NmspHost) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\NmspHost.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Rockwell Redundancy Services (RdcyHost) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RdcyHost.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: FactoryTalk Diagnostics Local Reader (RNADiagnosticsService) - Rockwell Automation Inc. - C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe
O23 - Service: FactoryTalk Diagnostics CE Receiver (RNADiagReceiver) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RNADiagReceiver.exe
O23 - Service: Rockwell Directory Server (RNADirectory) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RnaDirServer.exe
O23 - Service: Rockwell Directory Multiplexer (RNADirMultiplexor) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RNADirMultiplexor.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: RSLinx Classic (RSLinx) - Rockwell Automation, Inc. - C:\PROGRA~1\ROCKWE~1\RSLinx\RSLINX.EXE
O23 - Service: FactoryTalk Transaction Manager Configuration Server (rssql_cfg_server) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_cfg_server.exe
O23 - Service: FactoryTalk Transaction Manager Compression Server (rssql_comp_storer) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_comp_storer.exe
O23 - Service: FactoryTalk Transaction Manager DDE Connector (rssql_ddecoll) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_ddecoll.exe
O23 - Service: FactoryTalk Transaction Manager RSlinx Connector (rssql_lnxcoll) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_lnxcoll.exe
O23 - Service: FactoryTalk Transaction Manager COM+ Enterprise Connector (rssql_mts_storer) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_mts_storer.exe
O23 - Service: FactoryTalk Transaction Manager OCI Enterprise Connector (rssql_oci_storer) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_oci_storer.exe
O23 - Service: FactoryTalk Transaction Manager OLE-DB Enterprise Connector (rssql_oledb_storer) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_oledb_storer.exe
O23 - Service: FactoryTalk Transaction Manager OPC Connector (rssql_opccoll) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_opccoll.exe
O23 - Service: FactoryTalk Transaction Manager FactoryTalk Connector (rssql_rnacoll) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_rnacoll.exe
O23 - Service: FactoryTalk Transaction Manager RSView Connector (rssql_rsvcoll) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_rsvcoll.exe
O23 - Service: FactoryTalk Transaction Manager ODBC Enterprise Connector (rssql_storer) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_storer.exe
O23 - Service: FactoryTalk Transaction Manager Transaction Manager Service (rssql_tb) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_trnmgr.exe
O23 - Service: FactoryTalk Transaction Manager Transaction and Control Manager (rssql_tmctrl) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSSql\rssql_tmctrl.exe
O23 - Service: Rockwell Application Services (RsvcHost) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RsvcHost.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Wonderware SuiteLink (slssvc) - Invensys Systems, Inc. - C:\Program Files\Common Files\ArchestrA\slssvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\StacSV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: UA Local Discovery Server - OPC Foundation - C:\Program Files\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe
O23 - Service: VNC Server (winvnc) - RealVNC Ltd. - C:\Program Files\RealVNC\WinVNC\winvnc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Wonderware NetDDE Helper (WWNetDDE) - Invensys Systems, Inc. - C:\Program Files\Common Files\ArchestrA\wwnetdde.exe
O23 - Service: XBTZG935 USB Link Cable - Schneider Electric Inc. - C:\Program Files\Schneider Electric\Vijeo-Designer\Vijeo-Frame\XBTZG935\XBTZG935svr.exe
O23 - Service: XLReporter - Unknown owner - C:\XLReporter\XLReporter.exe

–
End of file - 19293 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)











  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
This is the first program scan from TDSSKiller 2011/03/02 07:31:56.0187 5688 TDSS rootkit removing tool 2.4.20.0 Mar 2 2011 10:44:30 2011/03/02 07:31:57.0234 5688 ================================================================================ 2011/03/02 07:31:57.0234 5688 SystemInfo: 2011/03/02 07:31:57.0234 5688 2011/03/02 07:31:57.0234 5688 OS Version: 5.1.2600 ServicePack: 3.0 2011/03/02 07:31:57.0234 5688 Product type: Workstation 2011/03/02 07:31:57.0234 5688 ComputerName: BLACYXP 2011/03/02 07:31:57.0234 5688 UserName: BLacy 2011/03/02 07:31:57.0234 5688 Windows directory: C:\WINDOWS 2011/03/02 07:31:57.0234 5688 System windows directory: C:\WINDOWS 2011/03/02 07:31:57.0234 5688 Processor architecture: Intel x86 2011/03/02 07:31:57.0234 5688 Number of processors: 2 2011/03/02 07:31:57.0234 5688 Page size: 0x1000 2011/03/02 07:31:57.0234 5688 Boot type: Normal boot 2011/03/02 07:31:57.0234 5688 ================================================================================ 2011/03/02 07:31:58.0859 5688 Initialize success 2011/03/02 07:32:00.0500 5500 ================================================================================ 2011/03/02 07:32:00.0500 5500 Scan started 2011/03/02 07:32:00.0500 5500 Mode: Manual; 2011/03/02 07:32:00.0500 5500 ================================================================================ 2011/03/02 07:32:04.0781 5500 abpcd (b3082855c806f43c5207cf15da7f6069) C:\WINDOWS\system32\DRIVERS\abpcd.sys 2011/03/02 07:32:04.0875 5500 abpicw2k (d31c3d556b9309c56ce2c098fb910d54) C:\WINDOWS\system32\DRIVERS\abpicw2k.sys 2011/03/02 07:32:05.0078 5500 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/03/02 07:32:05.0171 5500 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/03/02 07:32:05.0421 5500 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/03/02 07:32:05.0593 5500 AegisP (023867b6606fbabcdd52e089c4a507da) C:\WINDOWS\system32\DRIVERS\AegisP.sys 2011/03/02 07:32:05.0718 5500 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 2011/03/02 07:32:06.0062 5500 ApfiltrService (350f19eb5fe4ec37a2414df56cde1aa8) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys 2011/03/02 07:32:06.0218 5500 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2011/03/02 07:32:06.0468 5500 Aspi32 (ed8cee58c1e4c5893f5b2fd686a272bf) C:\WINDOWS\system32\drivers\Aspi32.sys 2011/03/02 07:32:06.0640 5500 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/03/02 07:32:06.0718 5500 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/03/02 07:32:07.0000 5500 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/03/02 07:32:07.0406 5500 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/03/02 07:32:07.0562 5500 b57w2k (f96038aa1ec4013a93d2420fc689d1e9) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 2011/03/02 07:32:07.0718 5500 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/03/02 07:32:07.0828 5500 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/03/02 07:32:08.0000 5500 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/03/02 07:32:08.0140 5500 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/03/02 07:32:08.0234 5500 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/03/02 07:32:08.0421 5500 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys 2011/03/02 07:32:08.0625 5500 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 2011/03/02 07:32:08.0765 5500 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 2011/03/02 07:32:08.0890 5500 Crypto (c56a413535292d9e43c563bbf946cbc1) C:\WINDOWS\system32\drivers\Crypto.sys 2011/03/02 07:32:09.0078 5500 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/03/02 07:32:09.0265 5500 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/03/02 07:32:09.0546 5500 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/03/02 07:32:09.0687 5500 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/03/02 07:32:09.0734 5500 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/03/02 07:32:09.0828 5500 DNE (c86fbf607445bf693450d84b775f168c) C:\WINDOWS\system32\DRIVERS\dne2000.sys 2011/03/02 07:32:09.0890 5500 DniVap (88ea1b2acdd0536661d67fdd2f030dd2) C:\WINDOWS\system32\DRIVERS\vap.sys 2011/03/02 07:32:10.0078 5500 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/03/02 07:32:10.0515 5500 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 2011/03/02 07:32:10.0687 5500 EraserUtilDrvI10 (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI10.sys 2011/03/02 07:32:10.0953 5500 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/03/02 07:32:11.0093 5500 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 2011/03/02 07:32:11.0187 5500 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/03/02 07:32:11.0359 5500 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 2011/03/02 07:32:11.0515 5500 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/03/02 07:32:11.0625 5500 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/03/02 07:32:11.0765 5500 FTDIBUS (7c17235845d5ae3fb33ead47b5881521) C:\WINDOWS\system32\drivers\ftdibus.sys 2011/03/02 07:32:11.0906 5500 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/03/02 07:32:12.0062 5500 FTSER2K (23220a4709cc5785f9633ba71416145c) C:\WINDOWS\system32\drivers\ftser2k.sys 2011/03/02 07:32:12.0265 5500 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/03/02 07:32:12.0421 5500 guardian2 (7031a936832967a93b0e5d5f1c76745a) C:\WINDOWS\system32\Drivers\oz776.sys 2011/03/02 07:32:12.0578 5500 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/03/02 07:32:12.0671 5500 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/03/02 07:32:12.0843 5500 HSFHWAZL (b1526810210980bed9d22315946c919d) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 2011/03/02 07:32:13.0078 5500 HSF_DPV (ddbd528e60f5961c142a490dc4ea7780) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 2011/03/02 07:32:13.0609 5500 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/03/02 07:32:13.0828 5500 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/03/02 07:32:15.0093 5500 ialm (200cca76cd0e0f7eec78fa56c29b4d67) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 2011/03/02 07:32:16.0906 5500 iastor (2358c53f30cb9dcd1d3843c4e2f299b2) C:\WINDOWS\system32\DRIVERS\iaStor.sys 2011/03/02 07:32:17.0156 5500 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/03/02 07:32:17.0359 5500 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/03/02 07:32:17.0453 5500 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/03/02 07:32:17.0546 5500 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/03/02 07:32:17.0734 5500 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/03/02 07:32:17.0828 5500 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/03/02 07:32:17.0937 5500 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/03/02 07:32:18.0109 5500 IPSECDRV (e101e53684f0f3da7558e0c2dbee2a6f) C:\WINDOWS\system32\Drivers\IPSECDRV.sys 2011/03/02 07:32:18.0234 5500 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/03/02 07:32:18.0312 5500 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/03/02 07:32:18.0453 5500 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/03/02 07:32:18.0562 5500 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/03/02 07:32:18.0671 5500 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/03/02 07:32:18.0750 5500 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/03/02 07:32:18.0937 5500 MBAMProtector (67b48a903430c6d4fb58cbaca1866601) C:\WINDOWS\system32\drivers\mbam.sys 2011/03/02 07:32:19.0046 5500 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 2011/03/02 07:32:19.0156 5500 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/03/02 07:32:19.0265 5500 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/03/02 07:32:19.0375 5500 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/03/02 07:32:19.0531 5500 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/03/02 07:32:19.0640 5500 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/03/02 07:32:19.0984 5500 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/03/02 07:32:20.0265 5500 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/03/02 07:32:20.0703 5500 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/03/02 07:32:20.0906 5500 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/03/02 07:32:21.0031 5500 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/03/02 07:32:21.0125 5500 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/03/02 07:32:21.0375 5500 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/03/02 07:32:21.0468 5500 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/03/02 07:32:21.0796 5500 NAVENG (c8ef74e4d8105b1d02d58ea4734cf616) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20110203.003\naveng.sys 2011/03/02 07:32:22.0000 5500 NAVEX15 (94b3164055d821a62944d9fe84036470) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20110203.003\navex15.sys 2011/03/02 07:32:22.0281 5500 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/03/02 07:32:22.0546 5500 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/03/02 07:32:22.0671 5500 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/03/02 07:32:22.0937 5500 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/03/02 07:32:23.0109 5500 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/03/02 07:32:23.0312 5500 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/03/02 07:32:23.0562 5500 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/03/02 07:32:24.0375 5500 NETw4x32 (88100ebdd10309fbd445ef8e42452eae) C:\WINDOWS\system32\DRIVERS\NETw4x32.sys 2011/03/02 07:32:25.0484 5500 NetwareWorkstation (32b244ea0263a2c77e40f5176abf4517) C:\WINDOWS\system32\NetWare\nwfs.sys 2011/03/02 07:32:25.0843 5500 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2011/03/02 07:32:25.0953 5500 NICM (e0b77595330935a8635d1c5092abf8c9) C:\WINDOWS\system32\drivers\nicm.sys 2011/03/02 07:32:26.0187 5500 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys 2011/03/02 07:32:26.0500 5500 NPF (d21fee8db254ba762656878168ac1db6) C:\WINDOWS\system32\drivers\npf.sys 2011/03/02 07:32:26.0718 5500 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/03/02 07:32:27.0000 5500 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/03/02 07:32:27.0312 5500 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/03/02 07:32:27.0546 5500 NWDHCP (a425f9345686e5d91c1e06877566738a) C:\WINDOWS\system32\NetWare\nwdhcp.sys 2011/03/02 07:32:27.0875 5500 NWDNS (b5c1d2e70f8641b550d4a55ce0cdfaa6) C:\WINDOWS\system32\NetWare\nwdns.sys 2011/03/02 07:32:28.0265 5500 NWFILTER (76bea8cd2b8192c9820295c0255f9e9b) C:\WINDOWS\system32\NetWare\nwfilter.sys 2011/03/02 07:32:28.0656 5500 NWHOST (ec805c89a1eeb04bf31a7160134ce4cd) C:\WINDOWS\system32\NetWare\NWHOST.sys 2011/03/02 07:32:29.0203 5500 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/03/02 07:32:29.0796 5500 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/03/02 07:32:31.0015 5500 NWSAP (2726a6792bbb080ff345ed9a8111360f) C:\WINDOWS\system32\NetWare\NWSAP.sys 2011/03/02 07:32:31.0546 5500 NWSIPX32 (fc3ec4f621efbcaea61ca4f752f9ff17) C:\WINDOWS\system32\NetWare\nwsipx32.sys 2011/03/02 07:32:31.0687 5500 NWSLP (192251dc5fb87ed7b4b1d4b6f2d06a34) C:\WINDOWS\system32\NetWare\nwslp.sys 2011/03/02 07:32:31.0765 5500 NWSNS (451ee45b1e7705678001598e14229e20) C:\WINDOWS\system32\NetWare\NWSNS.sys 2011/03/02 07:32:31.0906 5500 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2011/03/02 07:32:31.0984 5500 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/03/02 07:32:32.0078 5500 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/03/02 07:32:32.0218 5500 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/03/02 07:32:32.0328 5500 PccWdm (861263b7e14d6324948a21b96387dc1c) C:\WINDOWS\system32\DRIVERS\PccWdm.sys 2011/03/02 07:32:32.0437 5500 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/03/02 07:32:32.0515 5500 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/03/02 07:32:32.0562 5500 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 2011/03/02 07:32:32.0937 5500 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/03/02 07:32:33.0031 5500 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/03/02 07:32:33.0140 5500 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/03/02 07:32:33.0250 5500 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/03/02 07:32:33.0609 5500 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/03/02 07:32:33.0718 5500 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/03/02 07:32:33.0843 5500 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/03/02 07:32:33.0906 5500 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/03/02 07:32:34.0078 5500 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/03/02 07:32:34.0187 5500 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/03/02 07:32:34.0343 5500 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/03/02 07:32:34.0500 5500 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/03/02 07:32:34.0593 5500 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/03/02 07:32:34.0750 5500 RESMGR (457b73b6e4334ccb705ba73d884004ac) C:\WINDOWS\system32\NetWare\resmgr.sys 2011/03/02 07:32:34.0937 5500 RsiKtControl (2af65117091a47732f0997330e3daae6) C:\WINDOWS\system32\RSIKT.SYS 2011/03/02 07:32:35.0218 5500 RSSERIAL (b089419975668e2a701178032d652a24) C:\WINDOWS\SYSTEM32\RSSERIAL.SYS 2011/03/02 07:32:35.0484 5500 s24trans (c26a053e4db47f6cdd8653c83aaf22ee) C:\WINDOWS\system32\DRIVERS\s24trans.sys 2011/03/02 07:32:35.0781 5500 SAVRT (a00d5aa4748a1002590f08aa00fc660d) C:\Program Files\Symantec AntiVirus\savrt.sys 2011/03/02 07:32:36.0390 5500 SAVRTPEL (1e805005583be1c1568a3fce259c81e3) C:\Program Files\Symantec AntiVirus\Savrtpel.sys 2011/03/02 07:32:37.0546 5500 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/03/02 07:32:38.0531 5500 Sentinel (4b926f60ccce0c410591c66446675496) C:\WINDOWS\System32\Drivers\SENTINEL.SYS 2011/03/02 07:32:39.0421 5500 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/03/02 07:32:39.0890 5500 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/03/02 07:32:40.0328 5500 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/03/02 07:32:41.0296 5500 SPBBCDrv (c30fa11923892a4dbd1c747db8492e8f) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 2011/03/02 07:32:42.0234 5500 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/03/02 07:32:42.0750 5500 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/03/02 07:32:43.0515 5500 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/03/02 07:32:44.0984 5500 SRVLOC (e3cf62705b3571d9d170f2e5edf258c0) C:\WINDOWS\system32\NetWare\srvloc.sys 2011/03/02 07:32:45.0703 5500 SSIPDDP (6db0676e502995c59053683817c94286) C:\WINDOWS\system32\DRIVERS\SSIPDDP.SYS 2011/03/02 07:32:46.0187 5500 StarOpen (f92254b0bcfcd10caac7bccc7cb7f467) C:\WINDOWS\system32\drivers\StarOpen.sys 2011/03/02 07:32:47.0328 5500 STHDA (951801dfb54d86f611f0af47825476f9) C:\WINDOWS\system32\drivers\sthda.sys 2011/03/02 07:32:50.0531 5500 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/03/02 07:32:51.0093 5500 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/03/02 07:32:52.0125 5500 SymEvent (b3f8b9eab2ebe205c0fe053fba951d8c) C:\Program Files\Symantec\SYMEVENT.SYS 2011/03/02 07:32:52.0390 5500 SYMREDRV (7c73b65f1bdfab9052a5076c0ca622de) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS 2011/03/02 07:32:52.0578 5500 SYMTDI (b4562798891dca27ed67ca07acbadbd9) C:\WINDOWS\System32\Drivers\SYMTDI.SYS 2011/03/02 07:32:52.0781 5500 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/03/02 07:32:53.0046 5500 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/03/02 07:32:53.0171 5500 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/03/02 07:32:53.0281 5500 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/03/02 07:32:53.0343 5500 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/03/02 07:32:53.0500 5500 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/03/02 07:32:53.0703 5500 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/03/02 07:32:53.0812 5500 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/03/02 07:32:53.0921 5500 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/03/02 07:32:54.0031 5500 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/03/02 07:32:54.0140 5500 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/03/02 07:32:54.0218 5500 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/03/02 07:32:54.0312 5500 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/03/02 07:32:54.0437 5500 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/03/02 07:32:54.0593 5500 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/03/02 07:32:54.0812 5500 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 2011/03/02 07:32:55.0000 5500 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/03/02 07:32:55.0265 5500 winachsf (96aff1738271755a39b52eef7e35f98f) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 2011/03/02 07:32:55.0703 5500 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 2011/03/02 07:32:55.0859 5500 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/03/02 07:32:55.0921 5500 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/03/02 07:32:56.0062 5500 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0) 2011/03/02 07:32:56.0093 5500 ================================================================================ 2011/03/02 07:32:56.0093 5500 Scan finished 2011/03/02 07:32:56.0093 5500 ================================================================================ 2011/03/02 07:32:56.0109 5936 Detected object count: 1 2011/03/02 07:33:07.0281 5936 \HardDisk0 - will be cured after reboot 2011/03/02 07:33:07.0281 5936 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure 2011/03/02 07:33:11.0656 4948 Deinitialize success
OLT.txt

OTL logfile created on: 3/2/2011 8:29:54 AM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\blacy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 4092 5600 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 28.61 Gb Free Space | 38.39% Space Free | Partition Type: NTFS
Drive E: | 1397.26 Gb Total Space | 1320.50 Gb Free Space | 94.51% Space Free | Partition Type: NTFS
Drive F: | 22.43 Gb Total Space | 2.04 Gb Free Space | 9.09% Space Free | Partition Type: NWFS

Computer Name: BLACYXP | User Name: BLacy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\blacy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Canary Labs\Historian\CLIHistorian.exe (Canary Labs, Inc.)
PRC - C:\Program Files\Canary Labs\Historian\CLIHistorianMonitor.exe (Canary Labs, Inc.)
PRC - C:\Program Files\Canary Labs\Shared\TrayIcon.exe (Canary Labs, Inc.)
PRC - C:\Program Files\Schneider Electric\Vijeo-Designer\Vijeo-Frame\XBTZG935\XBTZG935svr.exe (Schneider Electric Inc.)
PRC - C:\XLReporter\XLReporter.exe ()
PRC - C:\Program Files\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe (OPC Foundation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\NCH Swift Sound\Verbose\verbose.exe (NCH Software)
PRC - C:\Program Files\Common Files\ArchestrA\NTServApp.exe (Invensys Systems, Inc.)
PRC - C:\Program Files\Common Files\ArchestrA\aaLogger.exe (Invensys Systems, Inc.)
PRC - C:\Program Files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe (Rockwell Automation Inc.)
PRC - C:\Program Files\Common Files\ArchestrA\slssvc.exe (Invensys Systems, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\RsvcHost.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe (Rockwell Automation Inc.)
PRC - C:\Program Files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe (Rockwell Automation, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Rockwell Software\RSSql\rssql_comp_storer.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Rockwell Software\RSSql\rssql_cfg_server.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\RdcyHost.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\NmspHost.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\RNADirMultiplexor.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\RnaDirServer.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\EventServer.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Rockwell Software\FactoryTalk Activation\flexsvr.exe ()
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe (SafeNet)
PRC - C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe (SafeNet)
PRC - C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe (SafeNet)
PRC - C:\Program Files\lotus\notes\ntmulti.exe (IBM Corp)
PRC - C:\WINDOWS\system32\cusrvc.exe (Novell, Inc.)
PRC - C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe (Macrovision Corporation)
PRC - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\RealVNC\WinVNC\winvnc.exe (RealVNC Ltd.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
PRC - C:\WINDOWS\system32\nwtray.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\dpmw32.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\blacy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\hccutils.dll (Intel Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (Canary Labs Enterprise Historian) – C:\Program Files\Canary Labs\Historian\CLIHistorian.exe (Canary Labs, Inc.)
SRV - (Canary Labs HDA Server) – C:\Program Files\Canary Labs\Historian\HDAServer.exe (Canary Labs, Inc.)
SRV - (Canary Labs Error Log Server) – C:\Program Files\Canary Labs\Shared\ErrorLogServer.exe (Canary Labs, Inc.)
SRV - (Canary_Labs_Historian_Monitor) – C:\Program Files\Canary Labs\Historian\CLIHistorianMonitor.exe (Canary Labs, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (XBTZG935 USB Link Cable) – C:\Program Files\Schneider Electric\Vijeo-Designer\Vijeo-Frame\XBTZG935\XBTZG935svr.exe (Schneider Electric Inc.)
SRV - (XLReporter) – C:\XLReporter\XLReporter.exe ()
SRV - (UA Local Discovery Server) – C:\Program Files\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe (OPC Foundation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (OpcEnum) – C:\WINDOWS\system32\OpcEnum.exe (OPC Foundation)
SRV - (WWNetDDE) – C:\Program Files\Common Files\ArchestrA\wwnetdde.exe (Invensys Systems, Inc.)
SRV - (FS Service Control) – C:\Program Files\Common Files\ArchestrA\NTServApp.exe (Invensys Systems, Inc.)
SRV - (aaLogger) – C:\Program Files\Common Files\ArchestrA\aaLogger.exe (Invensys Systems, Inc.)
SRV - (FTActivationBoost) – C:\Program Files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe (Rockwell Automation Inc.)
SRV - (slssvc) – C:\Program Files\Common Files\ArchestrA\slssvc.exe (Invensys Systems, Inc.)
SRV - (RSLinx) – C:\Program Files\Rockwell Software\RSLinx\RSLINX.EXE (Rockwell Automation, Inc.)
SRV - (RsvcHost) – C:\Program Files\Common Files\Rockwell\RsvcHost.exe (Rockwell Automation, Inc.)
SRV - (RNADiagReceiver) – C:\Program Files\Common Files\Rockwell\RNADiagReceiver.exe (Rockwell Automation, Inc.)
SRV - (RNADiagnosticsService) – C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe (Rockwell Automation Inc.)
SRV - (dnWhoDisp) – C:\Program Files\Rockwell Software\RSLinx\dnwhodisp.exe (Rockwell Automation, Inc.)
SRV - (Harmony) – C:\Program Files\Rockwell Software\RSCommon\RSOBSERV.EXE (Rockwell Automation, Inc.)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel Corporation)
SRV - (rssql_rnacoll) – C:\Program Files\Rockwell Software\RSSql\rssql_rnacoll.exe (Rockwell Automation, Inc.)
SRV - (rssql_opccoll) – C:\Program Files\Rockwell Software\RSSql\rssql_opccoll.exe (Rockwell Automation, Inc.)
SRV - (rssql_lnxcoll) – C:\Program Files\Rockwell Software\RSSql\rssql_lnxcoll.exe (Rockwell Automation, Inc.)
SRV - (rssql_rsvcoll) – C:\Program Files\Rockwell Software\RSSql\rssql_rsvcoll.exe (Rockwell Automation, Inc.)
SRV - (rssql_ddecoll) – C:\Program Files\Rockwell Software\RSSql\rssql_ddecoll.exe (Rockwell Automation, Inc.)
SRV - (rssql_comp_storer) – C:\Program Files\Rockwell Software\RSSql\rssql_comp_storer.exe (Rockwell Automation, Inc.)
SRV - (rssql_mts_storer) – C:\Program Files\Rockwell Software\RSSql\rssql_mts_storer.exe (Rockwell Automation, Inc.)
SRV - (rssql_oledb_storer) – C:\Program Files\Rockwell Software\RSSql\rssql_oledb_storer.exe (Rockwell Automation, Inc.)
SRV - (rssql_oci_storer) – C:\Program Files\Rockwell Software\RSSql\rssql_oci_storer.exe (Rockwell Automation, Inc.)
SRV - (rssql_storer) – C:\Program Files\Rockwell Software\RSSql\rssql_storer.exe (Rockwell Automation, Inc.)
SRV - (rssql_tmctrl) – C:\Program Files\Rockwell Software\RSSql\rssql_tmctrl.exe (Rockwell Automation, Inc.)
SRV - (rssql_tb) – C:\Program Files\Rockwell Software\RSSql\rssql_trnmgr.exe (Rockwell Automation, Inc.)
SRV - (rssql_cfg_server) – C:\Program Files\Rockwell Software\RSSql\rssql_cfg_server.exe (Rockwell Automation, Inc.)
SRV - (RdcyHost) – C:\Program Files\Common Files\Rockwell\RdcyHost.exe (Rockwell Automation, Inc.)
SRV - (NmspHost) – C:\Program Files\Common Files\Rockwell\NmspHost.exe (Rockwell Automation, Inc.)
SRV - (RNADirMultiplexor) – C:\Program Files\Common Files\Rockwell\RNADirMultiplexor.exe (Rockwell Automation, Inc.)
SRV - (RNADirectory) – C:\Program Files\Common Files\Rockwell\RnaDirServer.exe (Rockwell Automation, Inc.)
SRV - (EventClientMultiplexer) – C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe (Rockwell Automation, Inc.)
SRV - (EventServer) – C:\Program Files\Common Files\Rockwell\EventServer.exe (Rockwell Automation, Inc.)
SRV - (AdobeActiveFileMonitor6.0) – C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
SRV - (STacSV) – C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (IPSECMON) – C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe (SafeNet)
SRV - (IreIKE) – C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe (SafeNet)
SRV - (Multi-user Cleanup Service) – C:\Program Files\lotus\notes\ntmulti.exe (IBM Corp)
SRV - (cusrvc) – C:\WINDOWS\system32\cusrvc.exe (Novell, Inc.)
SRV - (FactoryTalk Activation Service) – C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe (Macrovision Corporation)
SRV - (winvnc) – C:\Program Files\RealVNC\WinVNC\winvnc.exe (RealVNC Ltd.)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110203.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110203.003\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (FTDIBUS) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (FTSER2K) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (abpicw2k) – C:\WINDOWS\system32\drivers\abpicw2k.sys (Rockwell Software, Inc.)
DRV - (RSSERIAL) – C:\WINDOWS\SYSTEM32\RSSERIAL.SYS (Rockwell Software Inc.)
DRV - (RsiKtControl) – C:\WINDOWS\system32\RSIKT.SYS (Rockwell Software Inc.)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (NETw4x32) Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (guardian2) – C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (Sentinel) – C:\WINDOWS\System32\Drivers\SENTINEL.SYS (SafeNet, Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (abpcd) – C:\WINDOWS\system32\drivers\abpcd.sys (Rockwell Automation)
DRV - (IPSECDRV) – C:\WINDOWS\system32\drivers\IpSecDrv.sys (SafeNet)
DRV - (Crypto) – C:\WINDOWS\System32\drivers\Crypto.sig ()
DRV - (NetwareWorkstation) – C:\WINDOWS\system32\NetWare\nwfs.sys (Novell, Inc.)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (NWFILTER) – C:\WINDOWS\system32\NetWare\nwfilter.sys (Novell, Inc.)
DRV - (NWDHCP) – C:\WINDOWS\system32\NetWare\nwdhcp.sys ()
DRV - (NICM) – C:\WINDOWS\system32\drivers\nicm.sys (Novell, Inc.)
DRV - (NWDNS) – C:\WINDOWS\system32\NetWare\nwdns.sys ()
DRV - (NWSLP) – C:\WINDOWS\system32\NetWare\nwslp.sys ()
DRV - (SRVLOC) – C:\WINDOWS\system32\NetWare\srvloc.sys (Novell, Inc.)
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (NWSAP) – C:\WINDOWS\system32\NetWare\nwsap.sys ()
DRV - (NWSNS) – C:\WINDOWS\system32\NetWare\nwsns.sys ()
DRV - (NWSIPX32) – C:\WINDOWS\system32\NetWare\nwsipx32.sys (Novell, Inc.)
DRV - (NWHOST) – C:\WINDOWS\system32\NetWare\nwhost.sys ()
DRV - (RESMGR) – C:\WINDOWS\system32\NetWare\resmgr.sys (Novell, Inc.)
DRV - (DniVap) SafeNet WAN Miniport (VA) – C:\WINDOWS\system32\drivers\vap.sys (Deterministic Networks Inc.)
DRV - (PccWdm) – C:\WINDOWS\system32\drivers\PccWdm.sys (Rockwell Software, Inc)
DRV - (SSIPDDP) – C:\WINDOWS\system32\drivers\SSIPDDP.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2801948
IE - HKCU\..\URLSearchHook: {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "NCH EN Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {37483b40-c254-4a72-bda4-22ee90182c1e}:[removed]
FF - prefs.js..extensions.enabledItems: {ada4b710-8346-4b82-8199-5de2b400a6ae}:1.9.9.2
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&q="

FF - HKLM\software\mozilla\Mozilla Firefox 3.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/25 10:28:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/25 10:00:45 | 000,000,000 | —D | M]

[2009/06/09 11:24:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\blacy\Application Data\Mozilla\Extensions
[2011/02/25 10:48:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\extensions
[2010/04/28 07:04:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/13 13:26:36 | 000,000,000 | —D | M] (NCH EN Community Toolbar) – C:\Documents and Settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\extensions\{37483b40-c254-4a72-bda4-22ee90182c1e}
[2011/02/07 18:52:38 | 000,000,000 | —D | M] (ReminderFox) – C:\Documents and Settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2010/12/13 13:26:36 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\extensions\[removed]
[2011/02/25 10:48:26 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/08/17 14:56:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/17 14:56:22 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/08/25 12:02:50 | 000,027,976 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
[2009/08/28 08:08:42 | 000,126,360 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
[2008/06/02 13:59:02 | 000,051,200 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\FTDWSER.DLL
[2009/08/28 08:08:58 | 000,098,712 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2009/08/25 12:01:25 | 000,060,824 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2010/08/17 14:56:20 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2008/06/02 13:04:44 | 000,163,840 | —- | M] (InfoPrint Solutions Company) – C:\Program Files\Mozilla Firefox\plugins\NPOAFP32.DLL

O1 HOSTS File: ([2011/01/24 16:49:19 | 000,002,559 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 192.168.115.8 IsoUnx01.Iso IsoUnx01 ServerX01
O1 - Hosts: 192.168.115.9 IsoUnx02.Iso IsoUnx02 ServerX02
O1 - Hosts: 192.168.115.10 IsoUnx03.Iso IsoUnx03 ServerX03
O1 - Hosts: 192.168.115.11 IsoUnx04.Iso IsoUnx04 ServerX04
O1 - Hosts: 192.168.115.12 IsoUnx05.Iso IsoUnx05 ServerX05
O1 - Hosts: 192.168.115.13 IsoUnx06.Iso IsoUnx06 ServerX06
O1 - Hosts: 192.168.115.14 IsoUnx07.Iso IsoUnx07 ServerX07
O1 - Hosts: 192.168.115.15 IsoUnx08.Iso IsoUnx08 ServerX08
O1 - Hosts: 128.1.0.100 Server6.usmnet.com Server6
O1 - Hosts: 192.168.112.101 Server6b.usmnet.com Server6b
O1 - Hosts: 192.168.112.77 Quality1.usmnet.com Quality1
O1 - Hosts: 192.168.112.103 Notes2.usmnet.com Notes2
O1 - Hosts: 192.168.112.43 HP2015ia.usmnet.com HP2015ia # Cafco Office
O1 - Hosts: 192.168.112.44 HP2015ib.usmnet.com HP2015ib # Supervisior's Office
O1 - Hosts: 192.168.112.45 HP2015ic.usmnet.com HP2015ic # Warehouse
O1 - Hosts: 192.168.112.49 HP2015id.usmnet.com HP2015id # Maintenance Office
O1 - Hosts: 192.168.112.46 HP4250ia.usmnet.com HP4250ia # Office
O1 - Hosts: 192.168.112.47 HP4250ib.usmnet.com HP4250ib # ** No Printer Yet **
O1 - Hosts: 192.168.112.78 Oki391ia.usmnet.com Oki391ia P4500ia # Cafco Office - Printex P4000 - Supposed to be an OKI!
O1 - Hosts: 192.168.112.51 Oki391ib.usmnet.com Oki391ib # - Supposed to be an OKI!
O1 - Hosts: 192.168.112.53 Oki391iC.usmnet.com Oki391ic L2491ia # Warehouse - Lexmark 2491- Supposed to be an OKI!
O1 - Hosts: 192.168.112.26 HP130ia.usmnet.com HP130ia # Engineering Plotter
O1 - Hosts: 192.168.112.48 HP3390ia.usmnet.com HP3390ia # Multifunction FAX
O1 - Hosts: 128.1.0.52 DFX5000ia.usmnet.com DFX5000ia # Epson Office
O1 - Hosts: 4 more lines…
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Canary Labs TrayIcon] C:\Program Files\Canary Labs\Shared\TrayIcon.exe (Canary Labs, Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NDPS] C:\WINDOWS\system32\dpmw32.exe ()
O4 - HKLM..\Run: [NWTRAY] C:\WINDOWS\System32\nwtray.exe (Novell, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [UsbCipHelper] C:\Program Files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe (Rockwell Automation, Inc.)
O4 - HKLM..\Run: [Verbose] C:\Program Files\NCH Swift Sound\Verbose\verbose.exe (NCH Software)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WinVNC] C:\Program Files\RealVNC\WinVNC\winvnc.exe (RealVNC Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Mobile User VPN.lnk = C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe (SafeNet)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: CompatibleRUPSecurity = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\NetWare\nwws2nds.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\system32\NetWare\nwws2sap.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\WINDOWS\system32\NetWare\nwws2slp.dll (Novell, Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1243368827155 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://rockwellautomation.webex.com/client…ort/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.112.77 [removed] [removed] 192.168.112.102
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (NWGINA.DLL) - C:\WINDOWS\System32\nwgina.dll (Novell, INC.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\WRNotifier: DllName - WRLogonNTF.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\blacy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\blacy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (nwv1_0) - C:\WINDOWS\System32\nwv1_0.dll (Novell, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/04 15:58:21 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/02 10:45:38 | 001,374,808 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\blacy\Desktop\TDSSKiller.exe
[2011/03/02 08:28:05 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\blacy\Desktop\OTL(2).exe
[2011/03/02 08:27:48 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\blacy\Desktop\OTL.exe
[2011/02/25 04:30:10 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Malwarebytes
[2011/02/23 15:01:41 | 000,000,000 | —D | C] – C:\Documents and Settings\blacy\Application Data\Malwarebytes
[2011/02/22 11:14:53 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/22 11:14:52 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/22 11:14:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/22 11:14:51 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/18 16:47:56 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2011/02/18 16:47:56 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2011/02/18 16:47:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop
[2011/02/18 16:47:38 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2011/02/16 10:16:59 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/02/16 10:16:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/02/16 10:16:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/02/16 10:16:52 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/02/15 14:11:00 | 000,000,000 | —D | C] – C:\Program Files\Citrix
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/02 10:45:38 | 001,374,808 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\blacy\Desktop\TDSSKiller.exe
[2011/03/02 08:28:05 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\blacy\Desktop\OTL(2).exe
[2011/03/02 08:27:59 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\blacy\Desktop\OTL.exe
[2011/03/02 07:59:02 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/02 07:36:59 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/02 07:36:57 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/02 07:35:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/28 10:19:47 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/28 09:53:28 | 000,126,559 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Stanhope Oneline.dwg
[2011/02/28 09:39:54 | 000,126,559 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Stanhope Oneline.bak
[2011/02/25 10:00:51 | 000,001,620 | —- | M] () – C:\Documents and Settings\blacy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/25 10:00:51 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/24 09:56:48 | 000,568,591 | —- | M] () – C:\Documents and Settings\blacy\Desktop\srap11.pdf
[2011/02/24 09:56:18 | 000,243,770 | —- | M] () – C:\Documents and Settings\blacy\Desktop\2011rfpp2grant.pdf
[2011/02/23 15:26:25 | 000,115,858 | —- | M] () – C:\Documents and Settings\blacy\Desktop\IPConfig.jpg
[2011/02/15 14:10:24 | 000,072,080 | —- | M] () – C:\Documents and Settings\blacy\g2mdlhlpx.exe
[2011/02/14 15:27:33 | 000,000,113 | —- | M] () – C:\WINDOWS\notesnsd.ini
[2011/02/09 13:57:01 | 000,036,171 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Stanhope Main DP.dwg
[2011/02/09 11:20:23 | 000,046,765 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Stanhope Site Plan.dwg
[2011/02/04 11:14:42 | 000,667,648 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Motors_be.mdb
[2011/02/04 07:15:48 | 000,457,228 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/04 07:15:48 | 000,078,034 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/01 13:32:37 | 001,436,741 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Storm.jpg
[2011/02/01 09:45:23 | 000,029,696 | —- | M] () – C:\Documents and Settings\blacy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/25 10:00:51 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/24 09:56:48 | 000,568,591 | —- | C] () – C:\Documents and Settings\blacy\Desktop\srap11.pdf
[2011/02/24 09:56:18 | 000,243,770 | —- | C] () – C:\Documents and Settings\blacy\Desktop\2011rfpp2grant.pdf
[2011/02/23 15:26:22 | 000,115,858 | —- | C] () – C:\Documents and Settings\blacy\Desktop\IPConfig.jpg
[2011/02/22 11:00:04 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/15 14:10:23 | 000,072,080 | —- | C] () – C:\Documents and Settings\blacy\g2mdlhlpx.exe
[2011/02/08 13:26:05 | 000,046,765 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Stanhope Site Plan.dwg
[2011/02/04 15:24:44 | 000,667,648 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Motors_be.mdb
[2011/02/04 09:43:24 | 000,036,171 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Stanhope Main DP.dwg
[2011/02/04 09:29:13 | 000,126,559 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Stanhope Oneline.dwg
[2011/02/04 09:29:13 | 000,126,559 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Stanhope Oneline.bak
[2011/02/01 13:32:34 | 001,436,741 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Storm.jpg
[2011/01/27 08:13:05 | 000,000,659 | —- | C] () – C:\WINDOWS\Setupwizard.ini
[2011/01/24 17:53:17 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\nsldap32v50.dll
[2011/01/24 09:33:16 | 000,000,049 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2011/01/21 14:28:03 | 000,179,528 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/06 08:11:31 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/01/03 13:24:18 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\Rtf2Html.dll
[2011/01/03 13:24:14 | 000,229,451 | —- | C] () – C:\WINDOWS\System32\kbhookdll.dll
[2011/01/03 13:24:14 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\Eztw32.dll
[2011/01/03 13:24:14 | 000,029,696 | —- | C] () – C:\WINDOWS\System32\rpiGlobalHook.dll
[2011/01/03 13:23:50 | 000,031,232 | —- | C] () – C:\WINDOWS\System32\Bcfont32.dll
[2011/01/03 13:23:49 | 000,015,840 | —- | C] () – C:\WINDOWS\System32\Machnm1.exe
[2011/01/03 13:23:49 | 000,007,432 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2011/01/03 13:23:47 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\ptouchif2.dll
[2011/01/03 13:23:47 | 000,030,208 | —- | C] () – C:\WINDOWS\System32\ptouchif1.dll
[2011/01/03 13:23:42 | 001,515,640 | —- | C] () – C:\WINDOWS\System32\SetPrinterDimensions.dll
[2010/08/10 13:16:04 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\redmonnt.dll
[2010/07/25 20:18:15 | 000,454,656 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2010/03/02 11:04:58 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2010/02/24 08:56:42 | 000,055,296 | —- | C] () – C:\WINDOWS\System32\drivers\SSIPDDP.SYS
[2010/02/24 08:56:42 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\SSIVDDP.DLL
[2010/02/24 08:56:42 | 000,000,745 | —- | C] () – C:\WINDOWS\System32\drivers\SSIDDDP.SYS
[2009/11/11 14:14:29 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2009/11/11 14:12:34 | 000,002,607 | —- | C] () – C:\WINDOWS\hyperlog.ini
[2009/09/11 09:24:59 | 000,000,000 | —- | C] () – C:\WINDOWS\licview.INI
[2009/09/11 09:06:08 | 000,000,000 | —- | C] () – C:\WINDOWS\aaLicView.INI
[2009/08/31 07:17:42 | 000,000,113 | —- | C] () – C:\WINDOWS\notesnsd.ini
[2009/08/19 08:39:19 | 000,000,030 | —- | C] () – C:\WINDOWS\FTDWNSPI.INI
[2009/08/18 13:46:45 | 000,000,000 | —- | C] () – C:\WINDOWS\rssql.INI
[2009/08/09 08:32:09 | 000,000,084 | —- | C] () – C:\WINDOWS\WININIT.INI
[2009/08/09 08:32:08 | 000,000,000 | —- | C] () – C:\WINDOWS\WinDnet.ini
[2009/06/25 08:58:36 | 000,032,256 | —- | C] () – C:\WINDOWS\System32\_UNODBC.dll
[2009/06/03 11:48:52 | 000,000,128 | —- | C] () – C:\Documents and Settings\blacy\Local Settings\Application Data\fusioncache.dat
[2009/06/01 15:50:37 | 000,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[2009/05/28 14:30:27 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\HPPAPR01.DLL
[2009/05/28 14:30:27 | 000,000,508 | —- | C] () – C:\WINDOWS\System32\HPPAPR01.DAT
[2009/05/28 13:05:41 | 000,000,032 | —- | C] () – C:\WINDOWS\EvMoveCF.INI
[2009/05/28 10:29:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/05/28 10:07:25 | 000,029,696 | —- | C] () – C:\Documents and Settings\blacy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/28 09:57:54 | 000,002,279 | —- | C] () – C:\WINDOWS\EDS.ini
[2009/05/28 09:54:55 | 000,000,128 | —- | C] () – C:\WINDOWS\rocksoft.ini
[2009/05/26 15:10:17 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2008/07/25 09:08:34 | 000,036,408 | —- | C] () – C:\WINDOWS\System32\LINXVDD.DLL
[2008/07/05 17:19:52 | 000,007,449 | —- | C] () – C:\WINDOWS\System32\drivers\SDDHP.BIN
[2008/07/05 17:19:52 | 000,006,400 | —- | C] () – C:\WINDOWS\System32\drivers\slcnewkt.bin
[2008/07/05 17:19:52 | 000,005,433 | —- | C] () – C:\WINDOWS\System32\drivers\SDDH.BIN
[2008/07/05 17:19:50 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\drivers\KTC.BIN
[2008/07/05 17:19:50 | 000,015,664 | —- | C] () – C:\WINDOWS\System32\drivers\PCMK485.BIN
[2008/07/05 17:19:50 | 000,015,557 | —- | C] () – C:\WINDOWS\System32\drivers\KTX485.BIN
[2008/07/05 17:19:50 | 000,009,282 | —- | C] () – C:\WINDOWS\System32\drivers\PCMKPCL.BIN
[2008/07/05 17:19:50 | 000,009,139 | —- | C] () – C:\WINDOWS\System32\drivers\KTXPCL.BIN
[2008/07/05 17:19:50 | 000,007,575 | —- | C] () – C:\WINDOWS\System32\drivers\KLPCL.BIN
[2008/07/05 17:19:50 | 000,001,825 | —- | C] () – C:\WINDOWS\System32\drivers\KT2ST2.BIN
[2008/07/05 17:19:50 | 000,001,824 | —- | C] () – C:\WINDOWS\System32\drivers\PCMKST3.BIN
[2008/07/05 17:19:50 | 000,001,824 | —- | C] () – C:\WINDOWS\System32\drivers\KLST2.BIN
[2008/07/05 17:19:50 | 000,001,801 | —- | C] () – C:\WINDOWS\System32\drivers\KT2ST1.BIN
[2008/07/05 17:19:50 | 000,001,800 | —- | C] () – C:\WINDOWS\System32\drivers\PCMKST1.BIN
[2008/07/05 17:19:50 | 000,001,800 | —- | C] () – C:\WINDOWS\System32\drivers\KTXST1.BIN
[2008/07/05 17:19:50 | 000,001,800 | —- | C] () – C:\WINDOWS\System32\drivers\KLST1.BIN
[2008/07/05 17:19:50 | 000,000,301 | —- | C] () – C:\WINDOWS\System32\drivers\PCMKST0.BIN
[2008/07/05 17:19:50 | 000,000,301 | —- | C] () – C:\WINDOWS\System32\drivers\KTXST0.BIN
[2008/07/05 17:19:50 | 000,000,248 | —- | C] () – C:\WINDOWS\System32\drivers\KLST0.BIN
[2008/07/05 17:19:50 | 000,000,177 | —- | C] () – C:\WINDOWS\System32\drivers\KT2ST0.BIN
[2008/07/05 17:19:50 | 000,000,011 | —- | C] () – C:\WINDOWS\System32\drivers\PCMKST2.BIN
[2008/05/12 19:32:52 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\StrStorage.dll
[2008/04/09 15:31:54 | 000,000,011 | —- | C] () – C:\WINDOWS\NetWare.INI
[2008/04/04 16:24:37 | 000,135,221 | —- | C] () – C:\WINDOWS\System32\nmasncp.dll
[2008/04/04 16:24:37 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\unclient.exe
[2008/04/04 16:24:36 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\GAMSWrap.dll
[2008/04/04 16:24:36 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\NMASReg.exe
[2008/04/04 16:24:36 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\NMASWrap.dll
[2008/04/04 16:18:44 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\AegisI5Installer.exe
[2008/04/04 16:16:05 | 000,684,032 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2008/04/04 16:16:05 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2008/04/04 16:10:56 | 000,910,304 | —- | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2008/04/04 16:10:56 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4831.dll
[2008/04/04 16:10:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\setupw2k.dll
[2008/04/04 16:10:18 | 000,015,898 | —- | C] () – C:\WINDOWS\System32\vlmsup.exe
[2008/04/04 16:10:18 | 000,001,740 | —- | C] () – C:\WINDOWS\System32\vipx.exe
[2008/04/04 16:10:16 | 000,241,746 | —- | C] () – C:\WINDOWS\System32\nwshlxnt.dll
[2008/04/04 16:10:11 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\lgncon32.dll
[2008/04/04 16:10:11 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\lgncxw32.dll
[2008/04/04 16:10:10 | 000,045,119 | —- | C] () – C:\WINDOWS\System32\dprpcw32.dll
[2008/04/04 16:10:10 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\dpmw32.exe
[2008/04/04 16:10:10 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\dplgnw32.dll
[2008/04/04 16:10:08 | 000,012,736 | —- | C] () – C:\WINDOWS\System32\cmdinfo.exe
[2008/04/04 16:10:00 | 000,002,757 | —- | C] () – C:\WINDOWS\System32\rdrstats.ini
[2008/04/04 16:09:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\prtwin32.dll
[2008/04/04 16:09:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\nwpsrv32.dll
[2008/04/04 16:09:37 | 000,219,136 | —- | C] () – C:\WINDOWS\System32\lgnwnt32.dll
[2008/04/04 16:09:30 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\nwslog32.dll
[2008/04/04 16:01:05 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/04/04 15:55:51 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/04/04 15:37:40 | 000,001,215 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/04/04 10:51:40 | 000,004,346 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/04/04 10:50:38 | 000,340,240 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/02 13:24:02 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2005/03/21 18:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 18:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 05:00:00 | 000,457,228 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 05:00:00 | 000,078,034 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/04/12 12:54:44 | 000,001,116 | —- | C] () – C:\WINDOWS\rsplugs.ini
[1998/12/07 15:11:22 | 000,227,840 | —- | C] () – C:\WINDOWS\System32\lmgr325a.dll
[1997/07/10 23:00:00 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\WRKGADM.EXE
[1997/07/10 23:00:00 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/10 23:00:00 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/10 23:00:00 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL

========== LOP Check ==========

[2009/09/11 08:54:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ArchestrA
[2009/10/07 08:58:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2011/01/26 13:26:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canary Labs
[2011/01/06 08:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2009/06/09 12:49:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2010/02/22 14:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Font Downloader
[2009/09/11 08:52:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InTouchDemos
[2010/07/26 06:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/12/20 13:25:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/01/26 13:55:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OPC Foundation
[2009/08/17 14:28:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rockwell
[2009/05/28 09:58:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rockwell Automation
[2009/09/24 09:32:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
[2010/11/24 10:21:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Software Toolbox
[2009/08/25 11:33:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WFCU
[2009/09/11 08:52:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wonderware
[2010/02/22 14:49:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{50D3FBE1-AD16-4F59-9326-86404D6B1B1F}
[2009/10/07 08:58:48 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Autodesk
[2010/08/10 13:26:15 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Babylon
[2011/01/18 12:05:22 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\BitZipper
[2011/01/06 08:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Canneverbe Limited
[2010/07/25 20:20:25 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\MyHeritage
[2010/12/20 13:25:03 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\NCH Swift Sound
[2010/08/19 08:53:16 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\OpenOffice.org
[2010/03/02 11:15:39 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\pdfforge
[2009/08/27 10:50:32 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Rockwell Software
[2010/09/22 14:07:34 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Schneider Electric
[2010/03/02 11:15:40 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Search Settings
[2010/11/24 10:20:51 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Software Toolbox
[2010/04/16 14:47:05 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Uniblue
[2010/12/20 14:00:39 | 000,000,282 | —- | M] () – C:\WINDOWS\Tasks\wavepadShakeIcon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/05/28 13:37:18 | 000,000,260 | RHS- | M] () – C:\386SWAP.PAR
[2009/06/09 12:49:24 | 000,000,000 | —- | M] () – C:\AdobeDebug.txt
[2008/04/04 15:58:21 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/03 09:23:35 | 000,015,464 | —- | M] () – C:\bar.emf
[2008/04/04 15:54:06 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/04/04 15:58:21 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/02/16 09:23:18 | 000,000,008 | —- | M] () – C:\default.txt
[2009/05/22 10:12:12 | 000,339,099 | —- | M] () – C:\evmovecf.zip
[2009/05/28 13:37:18 | 000,000,468 | RHS- | M] () – C:\EVRSI.SYS
[2008/04/04 15:39:14 | 000,005,127 | -H– | M] () – C:\ffastun.ffa
[2008/04/04 15:39:14 | 000,106,496 | -H– | M] () – C:\ffastun.ffl
[2008/04/04 15:39:14 | 000,176,128 | -H– | M] () – C:\ffastun.ffo
[2008/04/04 15:39:14 | 000,503,808 | -H– | M] () – C:\ffastun0.ffx
[2010/12/02 13:12:42 | 000,000,002 | —- | M] () – C:\ftdwinvw.log
[2008/04/04 15:58:21 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/04/04 15:58:21 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/09/11 08:34:45 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/02 07:35:00 | 4290,772,992 | -HS- | M] () – C:\pagefile.sys
[2010/02/24 13:56:58 | 000,000,397 | —- | M] () – C:\plot.log
[2011/03/02 07:33:11 | 000,046,816 | —- | M] () – C:\TDSSKiller.2.4.20.0_02.03.2011_07.31.56_log.txt
[2010/02/05 14:57:46 | 000,046,080 | -HS- | M] () – C:\Thumbs.db
[2009/05/27 10:28:08 | 027,262,976 | —- | M] () – C:\VIRTPART.DAT
[2011/01/24 18:02:04 | 000,004,704 | -H– | M] () – C:\_NavCClt.Log

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/04/04 15:58:10 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2004/12/05 23:09:50 | 000,062,976 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\HPZPP38Y.DLL
[2006/07/24 09:15:26 | 000,066,048 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\HPZPP4AY.DLL
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[1997/07/10 23:00:00 | 000,000,002 | —- | M] () – C:\Documents and Settings\blacy\Application Data\Microsoft\ArtGalry.cag

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/04/04 10:49:45 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/04/04 10:49:45 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/04/04 10:49:45 | 000,909,312 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/09/11 08:38:53 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/09/11 08:47:56 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\blacy\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/05/26 15:39:32 | 000,000,079 | —- | M] () – C:\Documents and Settings\blacy\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/03/02 08:28:05 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\blacy\Desktop\OTL(2).exe
[2011/03/02 08:27:59 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\blacy\Desktop\OTL.exe
[2011/03/02 10:45:38 | 001,374,808 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\blacy\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >
[2011/02/15 14:10:24 | 000,072,080 | —- | M] () – C:\Documents and Settings\blacy\g2mdlhlpx.exe
[2010/09/10 08:02:46 | 001,062,984 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Documents and Settings\blacy\gotomypc_540.exe

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/09/11 08:47:56 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\blacy\Favorites\Desktop.ini
[2009/05/19 09:46:46 | 000,000,480 | —- | M] () – C:\Documents and Settings\blacy\Favorites\NCH Software Download.lnk

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/03/02 07:39:50 | 000,098,304 | —- | M] () – C:\Documents and Settings\blacy\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-21 12:40:08

========== Files - Unicode (All) ==========
[2010/02/08 11:10:56 | 000,000,000 | —D | M](C:\Documents and Settings\blacy\Favorites\?£sorted Bookmarks) – C:\Documents and Settings\blacy\Favorites\狈£sorted Bookmarks

< End of report >
Extras.txt

OTL Extras logfile created on: 3/2/2011 8:29:54 AM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\blacy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 4092 5600 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 28.61 Gb Free Space | 38.39% Space Free | Partition Type: NTFS
Drive E: | 1397.26 Gb Total Space | 1320.50 Gb Free Space | 94.51% Space Free | Partition Type: NTFS
Drive F: | 22.43 Gb Total Space | 2.04 Gb Free Space | 9.09% Space Free | Partition Type: NWFS

Computer Name: BLACYXP | User Name: BLacy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"135:TCP" = 135:TCP:*:Enabled:Port 135 TCP
"400:TCP" = 400:TCP:*:Enabled:Port 400 TCP
"401:TCP" = 401:TCP:*:Enabled:Port 401 TCP
"402:TCP" = 402:TCP:*:Enabled:Port 402 TCP
"102:TCP" = 102:TCP:*:Enabled:DAS SI 102
"502:TCP" = 502:TCP:*:Enabled:Modicon 502
"1434:UDP" = 1434:UDP:*:Enabled:SQL Server Browser 1434
"1433:TCP" = 1433:TCP:*:Enabled:SQL TCP 1433
"2221:TCP" = 2221:TCP:*:Enabled:DAS ABTCP 2221
"2222:TCP" = 2222:TCP:*:Enabled:DAS ABTCP 2222
"2223:TCP" = 2223:TCP:*:Enabled:DAS ABTCP 2223
"5413:TCP" = 5413:TCP:*:Enabled:Port 5413
"80:TCP" = 80:TCP:*:Enabled:SuiteVoyager 80
"9001:TCP" = 9001:TCP:*:Enabled:vista 9001
"9002:TCP" = 9002:TCP:*:Enabled:EnvMngr 9002
"9003:TCP" = 9003:TCP:*:Enabled:MsgMngr 9003
"9004:TCP" = 9004:TCP:*:Enabled:SecMngr 9004
"9006:TCP" = 9006:TCP:*:Enabled:RedMngr 9006
"9007:TCP" = 9007:TCP:*:Enabled:UnilinkMngr 9007
"9008:TCP" = 9008:TCP:*:Enabled:BatchMngr 9008
"9011:TCP" = 9011:TCP:*:Enabled:LogMngr 9011
"9012:TCP" = 9012:TCP:*:Enabled:InfoMngr 9012
"9013:UDP" = 9013:UDP:*:Enabled:RedMngrX 9013
"9014:UDP" = 9014:UDP:*:Enabled:RedMngrX2 9014
"9015:TCP" = 9015:TCP:*:Enabled:HistQMngrvista 9015
"9016:TCP" = 9016:TCP:*:Enabled:HistQReader 9016
"44818:TCP" = 44818:TCP:*:Enabled:Logix 44818
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"135:TCP" = 135:TCP:*:Enabled:Port 135 TCP
"400:TCP" = 400:TCP:*:Enabled:Port 400 TCP
"401:TCP" = 401:TCP:*:Enabled:Port 401 TCP
"402:TCP" = 402:TCP:*:Enabled:Port 402 TCP
"102:TCP" = 102:TCP:*:Enabled:DAS SI 102
"502:TCP" = 502:TCP:*:Enabled:Modicon 502
"1434:UDP" = 1434:UDP:*:Enabled:SQL Server Browser 1434
"1433:TCP" = 1433:TCP:*:Enabled:SQL TCP 1433
"2221:TCP" = 2221:TCP:*:Enabled:DAS ABTCP 2221
"2222:TCP" = 2222:TCP:*:Enabled:DAS ABTCP 2222
"2223:TCP" = 2223:TCP:*:Enabled:DAS ABTCP 2223
"5413:TCP" = 5413:TCP:*:Enabled:Port 5413
"80:TCP" = 80:TCP:*:Enabled:SuiteVoyager 80
"9001:TCP" = 9001:TCP:*:Enabled:vista 9001
"9002:TCP" = 9002:TCP:*:Enabled:EnvMngr 9002
"9003:TCP" = 9003:TCP:*:Enabled:MsgMngr 9003
"9004:TCP" = 9004:TCP:*:Enabled:SecMngr 9004
"9006:TCP" = 9006:TCP:*:Enabled:RedMngr 9006
"9007:TCP" = 9007:TCP:*:Enabled:UnilinkMngr 9007
"9008:TCP" = 9008:TCP:*:Enabled:BatchMngr 9008
"9011:TCP" = 9011:TCP:*:Enabled:LogMngr 9011
"9012:TCP" = 9012:TCP:*:Enabled:InfoMngr 9012
"9013:UDP" = 9013:UDP:*:Enabled:RedMngrX 9013
"9014:UDP" = 9014:UDP:*:Enabled:RedMngrX2 9014
"9015:TCP" = 9015:TCP:*:Enabled:HistQMngrvista 9015
"9016:TCP" = 9016:TCP:*:Enabled:HistQReader 9016
"44818:TCP" = 44818:TCP:*:Enabled:Logix 44818
"4840:TCP" = 4840:TCP:*:Enabled:UA Local Discovery Server (OPC.TCP 4840)
"52601:TCP" = 52601:TCP:*:Enabled:UA Local Discovery Server (HTTP 52601)
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe" = C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe:*:Enabled:EventClientMultiplexer.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\RsvcHost.exe" = C:\Program Files\Common Files\Rockwell\RsvcHost.exe:*:Enabled:RsvcHost.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\RdcyHost.exe" = C:\Program Files\Common Files\Rockwell\RdcyHost.exe:*:Enabled:RdcyHost.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\NmspHost.exe" = C:\Program Files\Common Files\Rockwell\NmspHost.exe:*:Enabled:NmspHost.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\RnaDirServer.exe" = C:\Program Files\Common Files\Rockwell\RnaDirServer.exe:*:Enabled:RnaDirServer.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\EventServer.exe" = C:\Program Files\Common Files\Rockwell\EventServer.exe:*:Enabled:EventServer.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\DaClient.exe" = C:\Program Files\Common Files\Rockwell\DaClient.exe:*:Enabled:DaClient.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\RNADiagReceiver.exe" = C:\Program Files\Common Files\Rockwell\RNADiagReceiver.exe:*:Enabled:RnaDiagReceiver.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe" = C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe:*:Enabled:RnaDiagnosticsSrv.exe – (Rockwell Automation Inc.)
"C:\Program Files\Common Files\Rockwell\VStudio.exe" = C:\Program Files\Common Files\Rockwell\VStudio.exe:*:Enabled:VStudio.exe – (Rockwell Automation, Inc.)
"C:\WINDOWS\system32\OpcEnum.exe" = C:\WINDOWS\system32\OpcEnum.exe:*:Enabled:OPCEnum.exe – (OPC Foundation)
"C:\Program Files\Rockwell Software\RSCommon\rssql_xml.exe" = C:\Program Files\Rockwell Software\RSCommon\rssql_xml.exe:*:Enabled:RSSQL_XML.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql.exe" = C:\Program Files\Rockwell Software\RSSql\rssql.exe:*:Enabled:rssql.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_tmctrl.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_tmctrl.exe:*:Enabled:rssql_tmctrl.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_trnmgr.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_trnmgr.exe:*:Enabled:rssql_trnmgr.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_cfg_server.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_cfg_server.exe:*:Enabled:rssql_cfg_server.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_comp_storer.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_comp_storer.exe:*:Enabled:rssql_comp_storer.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_lnxcoll.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_lnxcoll.exe:*:Enabled:rssql_lnxcoll.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_rnacoll.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_rnacoll.exe:*:Enabled:rssql_rnacoll.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_rsvcoll.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_rsvcoll.exe:*:Enabled:rssql_rsvcoll.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_opccoll.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_opccoll.exe:*:Enabled:rssql_opccoll.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_trx_csv.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_trx_csv.exe:*:Enabled:rssql_trx_csv.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe" = C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe:*:Enabled:lmgrd.exe – (Macrovision Corporation)
"C:\Program Files\Rockwell Software\FactoryTalk Activation\flexsvr.exe" = C:\Program Files\Rockwell Software\FactoryTalk Activation\flexsvr.exe:*:Enabled:flexsvr.exe – ()
"C:\Program Files\Common Files\ArchestrA\aaLogger.exe" = C:\Program Files\Common Files\ArchestrA\aaLogger.exe:*:Enabled:aaLogger.exe – (Invensys Systems, Inc.)
"C:\Program Files\Common Files\ArchestrA\slssvc.exe" = C:\Program Files\Common Files\ArchestrA\slssvc.exe:*:Enabled:Slssvc.exe – (Invensys Systems, Inc.)
"C:\Program Files\Wonderware\InTouch\wm.exe" = C:\Program Files\Wonderware\InTouch\wm.exe:*:Enabled:wm.exe – (Invensys Systems, Inc.)
"C:\Program Files\Wonderware\InTouch\view.exe" = C:\Program Files\Wonderware\InTouch\view.exe:*:Enabled:view.exe – (Invensys Systems, Inc.)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:mmc.exe – (Microsoft Corporation)
"C:\Program Files\Common Files\ArchestrA\DASAgent.exe" = C:\Program Files\Common Files\ArchestrA\DASAgent.exe:*:Enabled:DASAgent.exe
"C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe" = C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe:*:Enabled:IreIke – (SafeNet)
"C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe" = C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog – (SafeNet)
"C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe" = C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp – (SafeNet)
"C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe" = C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager – (SafeNet)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\WatchGuard\Mobile User VPN\CertMgr.exe" = C:\Program Files\WatchGuard\Mobile User VPN\CertMgr.exe:*:Enabled:Certificate Manager – (SafeNet)
"C:\Program Files\WatchGuard\Mobile User VPN\MuvpnConnect.exe" = C:\Program Files\WatchGuard\Mobile User VPN\MuvpnConnect.exe:*:Enabled:Connect – (WatchGuard Technologies, Inc.)
"C:\Program Files\WatchGuard\Mobile User VPN\spdedit.exe" = C:\Program Files\WatchGuard\Mobile User VPN\spdedit.exe:*:Enabled:Security Policy Editor – (SafeNet)
"C:\Program Files\RealVNC\WinVNC\winvnc.exe" = C:\Program Files\RealVNC\WinVNC\winvnc.exe:*:Enabled:winvnc – (RealVNC Ltd.)
"C:\WINDOWS\system32\dpmw32.exe" = C:\WINDOWS\system32\dpmw32.exe:*:Enabled:dpmw32 – ()
"C:\Program Files\Rockwell Software\RSLogix 5000\ENU\v17\Bin\RS5000.Exe" = C:\Program Files\Rockwell Software\RSLogix 5000\ENU\v17\Bin\RS5000.Exe:*:Enabled:RSLogix 5000 v17.00.00 (CPR 9 SR 1) – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSLogix 5000\ENU\v16\Bin\RS5000.Exe" = C:\Program Files\Rockwell Software\RSLogix 5000\ENU\v16\Bin\RS5000.Exe:*:Enabled:RSLogix 5000 v16.03.00 (CPR 9) – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe" = C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe:*:Enabled:EventClientMultiplexer.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\RsvcHost.exe" = C:\Program Files\Common Files\Rockwell\RsvcHost.exe:*:Enabled:RsvcHost.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\RdcyHost.exe" = C:\Program Files\Common Files\Rockwell\RdcyHost.exe:*:Enabled:RdcyHost.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\NmspHost.exe" = C:\Program Files\Common Files\Rockwell\NmspHost.exe:*:Enabled:NmspHost.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\RnaDirServer.exe" = C:\Program Files\Common Files\Rockwell\RnaDirServer.exe:*:Enabled:RnaDirServer.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\EventServer.exe" = C:\Program Files\Common Files\Rockwell\EventServer.exe:*:Enabled:EventServer.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\DaClient.exe" = C:\Program Files\Common Files\Rockwell\DaClient.exe:*:Enabled:DaClient.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\RNADiagReceiver.exe" = C:\Program Files\Common Files\Rockwell\RNADiagReceiver.exe:*:Enabled:RnaDiagReceiver.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe" = C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe:*:Enabled:RnaDiagnosticsSrv.exe – (Rockwell Automation Inc.)
"C:\Program Files\Common Files\Rockwell\VStudio.exe" = C:\Program Files\Common Files\Rockwell\VStudio.exe:*:Enabled:VStudio.exe – (Rockwell Automation, Inc.)
"C:\WINDOWS\system32\OpcEnum.exe" = C:\WINDOWS\system32\OpcEnum.exe:*:Enabled:OPCEnum.exe – (OPC Foundation)
"C:\Program Files\Rockwell Software\RSCommon\rssql_xml.exe" = C:\Program Files\Rockwell Software\RSCommon\rssql_xml.exe:*:Enabled:RSSQL_XML.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql.exe" = C:\Program Files\Rockwell Software\RSSql\rssql.exe:*:Enabled:rssql.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_tmctrl.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_tmctrl.exe:*:Enabled:rssql_tmctrl.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_trnmgr.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_trnmgr.exe:*:Enabled:rssql_trnmgr.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_cfg_server.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_cfg_server.exe:*:Enabled:rssql_cfg_server.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_comp_storer.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_comp_storer.exe:*:Enabled:rssql_comp_storer.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_lnxcoll.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_lnxcoll.exe:*:Enabled:rssql_lnxcoll.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_rnacoll.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_rnacoll.exe:*:Enabled:rssql_rnacoll.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_rsvcoll.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_rsvcoll.exe:*:Enabled:rssql_rsvcoll.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_opccoll.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_opccoll.exe:*:Enabled:rssql_opccoll.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSSql\rssql_trx_csv.exe" = C:\Program Files\Rockwell Software\RSSql\rssql_trx_csv.exe:*:Enabled:rssql_trx_csv.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\RSLinx\RSLINX.EXE" = C:\Program Files\Rockwell Software\RSLinx\RSLINX.EXE:*:Enabled:RSLinx.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\OPCTools\OPCTest\opctest.exe" = C:\Program Files\Rockwell Software\OPCTools\OPCTest\opctest.exe:*:Enabled:OPCTest.exe – (Rockwell Automation, Inc.)
"C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe" = C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe:*:Enabled:lmgrd.exe – (Macrovision Corporation)
"C:\Program Files\Rockwell Software\FactoryTalk Activation\flexsvr.exe" = C:\Program Files\Rockwell Software\FactoryTalk Activation\flexsvr.exe:*:Enabled:flexsvr.exe – ()
"C:\Program Files\Common Files\ArchestrA\aaLogger.exe" = C:\Program Files\Common Files\ArchestrA\aaLogger.exe:*:Enabled:aaLogger.exe – (Invensys Systems, Inc.)
"C:\Program Files\Common Files\ArchestrA\slssvc.exe" = C:\Program Files\Common Files\ArchestrA\slssvc.exe:*:Enabled:Slssvc.exe – (Invensys Systems, Inc.)
"C:\Program Files\Wonderware\InTouch\wm.exe" = C:\Program Files\Wonderware\InTouch\wm.exe:*:Enabled:wm.exe – (Invensys Systems, Inc.)
"C:\Program Files\Wonderware\InTouch\view.exe" = C:\Program Files\Wonderware\InTouch\view.exe:*:Enabled:view.exe – (Invensys Systems, Inc.)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:mmc.exe – (Microsoft Corporation)
"C:\Program Files\Common Files\ArchestrA\DASAgent.exe" = C:\Program Files\Common Files\ArchestrA\DASAgent.exe:*:Enabled:DASAgent.exe
"C:\Program Files\Hewlett-Packard\HP Designjet System Maintenance\hp_dj_sme.exe" = C:\Program Files\Hewlett-Packard\HP Designjet System Maintenance\hp_dj_sme.exe:*:Enabled:hp designjet system maintenance engine – (Hewlett Packard)
"C:\Program Files\Schneider Electric\Vijeo-Designer\Vijeo-Runtime\Public\Bin\Koohi.exe" = C:\Program Files\Schneider Electric\Vijeo-Designer\Vijeo-Runtime\Public\Bin\Koohi.exe:*:Enabled:HMI Runtime – ()
"C:\Documents and Settings\blacy\My Documents\Downloads\pdf_converter.exe" = C:\Documents and Settings\blacy\My Documents\Downloads\pdf_converter.exe:*:Enabled:PDF Creator
"C:\Program Files\Canary Labs\Historian\HistorianAdmin.exe" = C:\Program Files\Canary Labs\Historian\HistorianAdmin.exe:*:Enabled:Canary Enterprise Historian Administrator – (Canary Labs, Inc.)
"C:\Program Files\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe" = C:\Program Files\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe:*:Enabled:UA Local Discovery Server – (OPC Foundation)
"C:\Program Files\Canary Labs\Logger\LoggerAdmin.exe" = C:\Program Files\Canary Labs\Logger\LoggerAdmin.exe:*:Enabled:Canary Logger Administrator – (Canary Labs, Inc.)
"C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe" = C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe:*:Enabled:IreIke – (SafeNet)
"C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe" = C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog – (SafeNet)
"C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe" = C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp – (SafeNet)
"C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe" = C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager – (SafeNet)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{026AC6A2-54CE-4E69-9925-1EFDB4E321C5}" = RSLogix 500 English 8.10.00 (CPR 9)
"{04040DE8-AEC1-4DD2-839B-818DF7038DA2}" = RSLogix 5000 Module Profile Setup Utility
"{05FA026B-8010-477D-82A2-4FA8B7900870}" = Rockwell Automation 1769 Analog Module Profiles
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{08383572-FC4B-4930-B256-AB94229DF10E}" = RSLogix 5000 Module Profile Core
"{097F8229-8ECD-4DD3-A648-1FD67BDAF562}" = InfoPrint AFP Viewer Plug-In
"{0CAB6A1C-3423-4EA0-8871-9CCA3672602B}" = FlukeView ScopeMeter 4
"{0D847E60-13F6-4266-8D66-B5C7ACF2EBE4}" = Rockwell Automation 1734 Analog Module Profiles
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{10050017-D5FD-11DA-A128-000C29473C90}" = RSLogix 5000 Start Page Media v17.00.05
"{13C4C1BC-6362-40DE-9CB3-48E1AC8A8CC7}" = Rockwell Automation 1732 Discrete Module Profiles
"{14F4B291-1684-4AB9-95C3-2B66260E515D}" = Rockwell Automation 1738 ASCII Module Profiles
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{17736C93-2694-488B-9F8A-0CA46E952FDD}" = Wonderware InTouch
"{1848099B-A3A7-4B54-B756-B3AEAF6BBDEA}" = Vijeo Designer 5.1
"{1CBE3804-20DF-48DA-B048-895C206E80A5}" = Microsoft SQL Server VSS Writer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20010017-D5FD-11DA-A128-000C29473C90}" = RSLogix 5000 Online Books v17.00.00
"{21F5098D-0C9E-4637-AD49-F037F6275990}" = NMAS Client Components (2.3)
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{248A5B8A-942E-4C67-96AF-ED41BACA800E}" = Rockwell Automation 1734 ASCII Module Profiles
"{252E0852-EB89-11D3-986E-0040051609CB}" = INTUNE
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{28D309DC-4EDD-49B4-A7CB-6B5C0E075B34}" = TerraGo Toolbar
"{30010017-EC33-11D6-A408-F6139379CBFB}" = RSLogix 5000 v17.00.00 (CPR 9 SR 1)
"{30010316-EC33-11D6-A408-F6139379CBFB}" = RSLogix 5000 v16.03.00 (CPR 9)
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{325EE2FD-DB48-4A9A-9459-1C6CCA2D284E}" = PicoSoft 6
"{34540622-805E-4CC7-98CF-65A43E99CF4D}" = RSLinx Classic 2.54.00 CPR 9 SR 1
"{3459512F-9223-4DCA-B555-CF00EDAF1B9C}" = Rockwell Automation 1769 Discrete Module Profiles
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{357187EE-8B25-467D-A567-88C735932174}" = Rockwell Automation 1734 Discrete Module Profiles
"{36A7B196-8D70-48A5-8FF3-7B836273FD4C}" = Rockwell Windows Firewall Configuration Utility 1.00.03
"{39363D4F-BF1C-447C-8014-F7966A9975D9}" = Rockwell Automation 1734 Specialty Module Profiles
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{4866D596-CE65-4F7D-B98C-A28F8E9E13E5}" = Rockwell Automation 1756 CNet Comms Module Profiles
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C74828C-0D2A-416A-959B-C19CC441F167}" = CLICK Programming Software Version 1.10
"{4E8B84D4-778C-4DE6-8CBC-2586D438D295}" = Rockwell Automation USB CIP Driver Package
"{501D1B01-DE00-42D6-8513-FA30A0825561}" = OPC UA Local Discovery Server 1.01.316.0
"{50A9694C-49F5-48E2-9E28-D45AEE88CA31}" = Rockwell Automation Drives PowerFlex 4 Module Profiles
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{55D9E026-DCB0-46FF-B60A-68B972228CF6}" = Autodesk Design Review 2010
"{56D614BA-A250-4C3E-8F79-43B3BC611D21}" = Parker Isysnet ASCII Module Profile
"{5783F2D7-4009-0409-0002-0060B0CE6BBA}" = AutoCAD LT 2006 - English
"{5791B7D3-8B34-4218-9750-6A8E45D0AD32}" = pdfforge Toolbar v1.1.2
"{57EF8F37-4213-498E-A6D0-79DC2D96CA45}" = Rockwell Automation 1738 Discrete Module Profiles 2
"{5977421B-2072-4DA7-9A18-90AF4BB24268}" = Rockwell Automation 1769 Controller Module Profiles
"{5B5B3D92-A765-4AD5-9752-30BA2C71C314}" = Lotus Notes 6.5.1
"{5B860FC6-C088-4D53-9A1D-10BBE33BE045}" = Rockwell Automation Generic Safety Module Profiles
"{5D4DB6E7-E61B-4A9A-BCDD-0808251DE3C1}" = HP ICC Profiles
"{60C6C5B8-6D81-4849-800F-0400C7FA1C70}" = Rockwell Automation 1738 Discrete Module Profiles 3
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{692179FB-984B-465A-BC4F-3875D2D53F32}" = RSNetWorx for DeviceNet 9.00.00 (CPR 9 SR 1)
"{6B4D6AEB-EA83-47F6-B17A-82DD9CD7F383}" = Rockwell Automation Drives PowerFlex 7 Module Profiles
"{6B977FCD-28E0-47C6-8056-E5FF477D898E}" = Parker Isysnet Discrete Module Profiles 2
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78921186-FCF5-4832-8FD1-088339BE6FAE}" = Rockwell Automation 1738 Analog Module Profiles
"{7CB1A5C6-0EF4-4E6D-92CA-D96ADED5F2A4}" = Rockwell Automation 1769 Specialty Module Profiles
"{7D3C6066-4659-4A2E-8D8E-EE93E206FF99}" = Rockwell Automation 1756 HART Module Profiles
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{80FA8F02-B48D-4208-89F1-AA1100C960B5}" = Rockwell Automation 1769 Boolean Module Profiles
"{829CD169-E692-48E8-9BDE-A3E8D8B65538}" = mSCfg
"{8372A29B-CE1C-4419-B479-8493027B41AA}" = Rockwell Automation 1769 ASCII Module Profiles
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8391EA99-A1EF-4EF3-97EE-BE966DBA3411}" = Rockwell Automation 1791DS Discrete Module Profiles
"{864F7779-997D-4FCC-A66B-84CD6DD57FF7}" = FactoryTalk Services Platform 2.10 (CPR 9)
"{893727BF-9C7C-483F-9E69-D8314DB21186}" = Parker Isysnet Discrete Module Profiles
"{898483E3-11FC-4D0A-ADCA-D1C9ADBA6C62}" = Hirschmann HiDiscovery 2.0
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-001C-0409-0000-0000000FF1CE}" = Microsoft Office Access Runtime (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISPRO_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_VISPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{9207A8EC-3B2D-4A4A-8BF7-957FC19BB3DE}" = Zebra Setup Utilities
"{927DB57A-2A2A-4DC5-9E07-234C9F285F03}" = Parker Isysnet Discrete Module Profiles 3
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{96327C3C-96BE-4C7A-A6F7-A71635E5949A}" = Microsoft SQL Server 2005 Backward compatibility
"{96FD5AB7-3B09-46C1-87B7-7727E1DC171F}" = Rockwell Automation Drives SCANport Module Profiles
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CF2221C-5546-47EF-A5BD-39AAB391EFB3}" = Rockwell Automation Drives PowerFlex 7 2 Module Profiles
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A1C775C8-CBD3-49B0-A72C-4C751378B2F4}" = RSLogix 5000 Setup Installer
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A32A6393-37DA-4E44-BB9F-C4F384F89EB9}" = HP System maintenance for HP Designjet 30 130 series
"{A393179D-478D-40C7-A6A2-90B9F34C2341}" = Rockwell Automation 1738 Discrete Module Profiles
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A6F82CD1-E338-4D47-B6DA-907040B7624A}" = Rockwell Automation 1734 Discrete Module Profiles 2
"{A8AEBFB4-846A-4DE7-BF8A-8E7246D3FC0F}" = Canary Enterprise Historian
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB8E12B5-0B0E-47F9-83A7-89F40B39DBF1}" = Rockwell Automation 1756 ENet Comms Module Profiles
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{B0ECEDEB-92C4-11D8-BD8E-00105A24FEA8}" = Mobile User VPN
"{B3EC9ADF-DAB1-4A7F-B05B-1158555C30DB}" = FactoryTalk Activation Server 3.02 (CPR 9 SR 2)
"{B6954CD8-348F-42A0-AB28-A24621163F17}" = InfoPrint AFP Viewer Plug-In
"{B9ED7828-4CB8-4873-95F5-64525C9229BE}" = Rockwell Automation 1769 Analog Module Profiles
"{BF251EAF-8697-4E89-BF09-C998F97BBC40}" = Microsoft SQL Server Native Client
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1EFEE0F-87EB-481A-A8F4-903069F12236}" = Parker Isysnet Analog Module Profiles
"{C3341CF6-EC1D-405C-A33F-272576C3C7B4}" = FactoryTalk Transaction Manager 9.00.00 (CPR 9)
"{C336A3DB-FA32-42BE-97D0-FFD42D807FD6}" = Oz776 SCR Driver V1.1.4.2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D02CEF5F-56D4-432C-B4BB-25B8AF6BC1EB}" = RSLogix 5000 System Updates
"{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}" = Broadcom Gigabit Integrated Controller
"{DE6BBFB2-B81E-4FBD-825F-EAC90F54D311}" = Rockwell Automation 1769 Embedded Module Profiles
"{E5E6E687-1033-BA7E-6000-000000000001}" = Adobe Acrobat Elements 6.0
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EC330663-0202-11DD-95FF-0800200C9A66}" = HP Web Registration
"{EDFE2142-CFB3-44AB-A961-DE85F6408A28}" = Sentinel Protection Installer 7.3.2
"{F02DBC5D-33E3-45E9-B0F8-B7745229ED1C}" = NICI (Shared) U.S./Worldwide (128 bit) (2.6.4-5)
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F54AC413-D2C6-4A24-B324-370C223C6250}" = Adobe Photoshop Elements 6.0
"{F5B20EF6-80AE-4D77-BEBF-AF63CEFA5DD0}" = ControlFLASH
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FA79AEE5-9FA1-4A6F-B66F-18AF565E1061}" = Rockwell Automation 1738 Specialty Module Profiles
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 6" = Adobe Photoshop Elements 6.0
"Adolix Split and Merge PDF_is1" = Adolix Split and Merge PDF v2.0
"Autodesk Design Review 2010" = Autodesk Design Review 2010
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"BitZipper_is1" = BitZipper 2010
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"EZSeries TouchPanel" = EZSeries TouchPanel 5.6
"FaciliWorks 8 Desktop" = FaciliWorks 8 Desktop
"HAP (HyperWare Automation Program)" = HAP (HyperWare Automation Program)
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Designjet 30-130 Printer Series" = HP Designjet 30-130 Printer Series
"ie8" = Windows Internet Explorer 8
"InstallShield_{C336A3DB-FA32-42BE-97D0-FFD42D807FD6}" = Oz776 SCR Driver V1.1.4.2
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0)" = Mozilla Firefox (3.0)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NETGEAR Print Server Utility" = NETGEAR Print Server Utility
"Novell Client for Windows" = Novell Client for Windows
"Office8.0" = Microsoft Office 97, Professional Edition
"PanelBuilder32" = PanelBuilder32
"PM Calculator" = PM Calculator
"ProInst" = Intel® PROSet/Wireless Software
"RSHWare" = Rockwell Software Hardware Maintenance Tool
"Total Access Memo 2007 Runtime" = Total Access Memo 2007 Runtime
"Verbose" = Verbose Text to Speech
"VISPRO" = Microsoft Office Visio Professional 2007
"WavePad" = WavePad Sound Editor
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPcapInst" = WinPcap 3.1
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XBTZG935" = USB Link Cable (XBTZG935)
"Zebra Font Downloader_is1" = Zebra Font Downloader
"Zebra Setup Utilities" = Zebra Setup Utilities

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.5.0.457

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/22/2011 1:10:04 PM | Computer Name = BLACYXP | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{3B579FA2-C712-4331-955E-4EB6A46630D1}\RP496\A0066183.exe by:
Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 2/22/2011 1:10:13 PM | Computer Name = BLACYXP | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{3B579FA2-C712-4331-955E-4EB6A46630D1}\RP496\A0066184.dll by:
Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully.

Error - 2/22/2011 1:10:13 PM | Computer Name = BLACYXP | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Bloodhound.MalPE in File: C:\System Volume Information\_restore{3B579FA2-C712-4331-955E-4EB6A46630D1}\RP496\A0066184.dll
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 2/22/2011 1:10:13 PM | Computer Name = BLACYXP | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Bloodhound.MalPE in File: C:\System Volume
Information\_restore{3B579FA2-C712-4331-955E-4EB6A46630D1}\RP496\A0066184.dll by:
Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 2/24/2011 1:39:31 PM | Computer Name = BLACYXP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 2/24/2011 1:39:32 PM | Computer Name = BLACYXP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 2/25/2011 11:31:18 AM | Computer Name = BLACYXP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 2/25/2011 11:31:18 AM | Computer Name = BLACYXP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 3/2/2011 8:32:38 AM | Computer Name = BLACYXP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 3/2/2011 8:32:39 AM | Computer Name = BLACYXP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

[ FTDiag Events ]
Error - 2/14/2011 10:10:27 AM | Computer Name = BLACYXP | Source = FactoryTalkDiagnostics | ID = 33489897
Description = Logged Date: 14:10:27 Monday, February 14, 2011 Location: BLACYXP
Provider: RSNetWorx for DeviceNet Username: BLACYXP\BLacy Verbosity: 0 CHAS:5005:
Address 30: [Slot 00] Communication Error(0xC) 'Error response received: [0x0407].
Connection lost.', SCIA(0x10, 0x7D, 0x1, 0x8

Error - 2/14/2011 10:10:29 AM | Computer Name = BLACYXP | Source = FactoryTalkDiagnostics | ID = 33489897
Description = Logged Date: 14:10:29 Monday, February 14, 2011 Location: BLACYXP
Provider: RSNetWorx for DeviceNet Username: BLACYXP\BLacy Verbosity: 0 CHAS:5005:
Address 30: [Slot 01] Communication Error(0xC) 'Error response received: [0x0407].
Connection lost.', SCIA(0x10, 0x7D, 0x2, 0x8

Error - 2/14/2011 10:10:31 AM | Computer Name = BLACYXP | Source = FactoryTalkDiagnostics | ID = 33489897
Description = Logged Date: 14:10:31 Monday, February 14, 2011 Location: BLACYXP
Provider: RSNetWorx for DeviceNet Username: BLACYXP\BLacy Verbosity: 0 CHAS:5005:
Address 30: [Slot 02] Communication Error(0xC) 'Error response received: [0x0407].
Connection lost.', SCIA(0x10, 0x7D, 0x3, 0x8

Error - 2/14/2011 10:10:33 AM | Computer Name = BLACYXP | Source = FactoryTalkDiagnostics | ID = 33489897
Description = Logged Date: 14:10:33 Monday, February 14, 2011 Location: BLACYXP
Provider: RSNetWorx for DeviceNet Username: BLACYXP\BLacy Verbosity: 0 CHAS:5005:
Address 30: [Slot 03] Communication Error(0xC) 'Error response received: [0x0407].
Connection lost.', SCIA(0x10, 0x7D, 0x4, 0x8

Error - 2/14/2011 10:10:35 AM | Computer Name = BLACYXP | Source = FactoryTalkDiagnostics | ID = 33489897
Description = Logged Date: 14:10:35 Monday, February 14, 2011 Location: BLACYXP
Provider: RSNetWorx for DeviceNet Username: BLACYXP\BLacy Verbosity: 0 CHAS:5005:
Address 30: [Slot 04] Communication Error(0xC) 'Error response received: [0x0407].
Connection lost.', SCIA(0x10, 0x7D, 0x5, 0x8

Error - 2/24/2011 10:25:36 AM | Computer Name = BLACYXP | Source = FactoryTalk Directory Multiplexor | ID = 33489897
Description = Logged Date: 14:25:36 Thursday, February 24, 2011 Location: BLACYXP
Provider: FactoryTalk Directory Multiplexor Username: WORKGROUP\BLACYXP$ Verbosity:
0 Failed to load FactoryTalk Directory schema for scope '$Local' from the FactoryTalk
Server. This is likely due to a loss of connectivity between this computer and
the FactoryTalk Server computer. The FactoryTalk Directory schema will be loaded
from the cache on this compute

Error - 2/28/2011 10:21:36 AM | Computer Name = BLACYXP | Source = FactoryTalkDiagnostics | ID = 33489897
Description = Logged Date: 14:21:36 Monday, February 28, 2011 Location: BLACYXP
Provider: RSNetWorx for DeviceNet Username: BLACYXP\BLacy Verbosity: 0 DNET:0013:
The device at address 22 has experienced an identity communications error (8000000A).
Properties faile

Error - 2/28/2011 2:18:07 PM | Computer Name = BLACYXP | Source = FactoryTalkDiagnostics | ID = 33489897
Description = Logged Date: 18:18:07 Monday, February 28, 2011 Location: BLACYXP
Provider: RSNetWorx for DeviceNet Username: BLACYXP\BLacy Verbosity: 0 DNET:0013:
The device at address 22 has experienced an identity communications error (8000000A).
Properties faile

Error - 2/28/2011 2:19:45 PM | Computer Name = BLACYXP | Source = FactoryTalkDiagnostics | ID = 33489897
Description = Logged Date: 18:19:45 Monday, February 28, 2011 Location: BLACYXP
Provider: RSNetWorx for DeviceNet Username: BLACYXP\BLacy Verbosity: 0 DNET:0013:
The device at address 22 has experienced an identity communications error (8000000A).
Properties faile

Error - 2/28/2011 2:23:55 PM | Computer Name = BLACYXP | Source = FactoryTalkDiagnostics | ID = 33489897
Description = Logged Date: 18:23:55 Monday, February 28, 2011 Location: BLACYXP
Provider: RSNetWorx for DeviceNet Username: BLACYXP\BLacy Verbosity: 0 DNET:0013:
The device at address 22 has experienced an identity communications error (8000000A).
Properties faile

[ System Events ]
Error - 2/24/2011 11:44:14 AM | Computer Name = BLACYXP | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2

Error - 2/24/2011 1:37:10 PM | Computer Name = BLACYXP | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2

Error - 2/24/2011 3:47:41 PM | Computer Name = BLACYXP | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2

Error - 2/24/2011 3:57:42 PM | Computer Name = BLACYXP | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2

Error - 2/25/2011 11:28:59 AM | Computer Name = BLACYXP | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2

Error - 2/28/2011 8:30:26 AM | Computer Name = BLACYXP | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2

Error - 2/28/2011 12:29:29 PM | Computer Name = BLACYXP | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2

Error - 3/1/2011 8:06:16 AM | Computer Name = BLACYXP | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2

Error - 3/2/2011 8:09:13 AM | Computer Name = BLACYXP | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2

Error - 3/2/2011 8:35:48 AM | Computer Name = BLACYXP | Source = Service Control Manager | ID = 7000
Description = The DS1410D service failed to start due to the following error: %%2


< End of report >
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Combofix log


ComboFix 11-03-01.03 - BLacy 03/03/2011 7:51.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1034 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\blacy\g2mdlhlpx.exe
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\INSTALL.LOG
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
C:\Thumbs.db
c:\windows\system32\drivers\npf.sys
c:\windows\system32\kbhookdll.dll
c:\windows\system32\open.ico
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\xlreporter\XLReporter.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_NPF
——-\Legacy_XLReporter
——-\Service_XLReporter


((((((((((((((((((((((((( Files Created from 2011-02-03 to 2011-03-03 )))))))))))))))))))))))))))))))
.

2011-02-25 09:30 . 2011-02-25 09:30 ——– d—–w- c:\documents and settings\LocalService\Application Data\Malwarebytes
2011-02-23 20:01 . 2011-02-23 20:01 ——– d—–w- c:\documents and settings\blacy\Application Data\Malwarebytes
2011-02-22 16:14 . 2011-02-22 16:14 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-02-22 16:14 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-22 16:14 . 2011-02-22 16:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-02-22 16:14 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-22 16:14 . 2011-02-22 16:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-22 15:42 . 2011-02-22 15:42 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2011-02-22 15:42 . 2011-02-22 15:42 ——– d—–w- c:\documents and settings\Administrator\Application Data\Search Settings
2011-02-22 15:42 . 2011-02-22 15:42 ——– d—–w- c:\documents and settings\Administrator\Application Data\pdfforge
2011-02-22 15:42 . 2011-02-22 15:42 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\ConduitEngine
2011-02-22 15:41 . 2011-02-22 15:41 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Temp
2011-02-18 21:56 . 2011-02-18 21:57 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2011-02-18 21:24 . 2011-02-18 21:24 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-02-16 15:16 . 2011-02-16 15:16 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-02-15 19:11 . 2011-02-15 19:11 ——– d—–w- c:\program files\Citrix

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-09 12:13 . 2010-12-09 12:13 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2009-08-25 17:02 . 2009-08-25 17:02 27976 —-a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2009-08-28 13:08 . 2009-08-28 13:08 126360 —-a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-06-02 18:59 . 2009-08-19 13:39 51200 —-a-w- c:\program files\mozilla firefox\plugins\FTDWSER.DLL
2009-08-28 13:08 . 2009-08-28 13:09 98712 —-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2008-06-02 18:59 . 2009-08-19 13:39 51200 —-a-w- c:\program files\internet explorer\plugins\FTDWSER.DLL
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 —-a-w- c:\program files\ConduitEngine\ConduitEngine.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-16 138008]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"NDPS"="c:\windows\system32\dpmw32.exe" [2000-01-21 28672]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 28672]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2005-04-17 85184]
"WinVNC"="c:\program files\RealVNC\WinVNC\winvnc.exe" [2002-11-27 335872]
"UsbCipHelper"="c:\program files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe" [2008-05-27 434176]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-11 67488]
"Verbose"="c:\program files\NCH Swift Sound\Verbose\verbose.exe" [2009-06-10 577540]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Canary Labs TrayIcon"="c:\program files\Canary Labs\Shared\TrayIcon.exe" [2010-12-13 121856]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-7-30 217195]
Mobile User VPN.lnk - c:\program files\WatchGuard\Mobile User VPN\SafeCfg.exe [2011-1-24 65588]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-4-4 106560]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WatchGuard\\Mobile User VPN\\CertMgr.exe"=
"c:\\Program Files\\WatchGuard\\Mobile User VPN\\MuvpnConnect.exe"=
"c:\\Program Files\\WatchGuard\\Mobile User VPN\\spdedit.exe"=
"c:\\Program Files\\RealVNC\\WinVNC\\winvnc.exe"=
"c:\\WINDOWS\\system32\\dpmw32.exe"=
"c:\\Program Files\\Rockwell Software\\RSLogix 5000\\ENU\\v17\\Bin\\RS5000.Exe"=
"c:\\Program Files\\Rockwell Software\\RSLogix 5000\\ENU\\v16\\Bin\\RS5000.Exe"=
"c:\\Program Files\\Common Files\\Rockwell\\EventClientMultiplexer.exe"=
"c:\\Program Files\\Common Files\\Rockwell\\RsvcHost.exe"=
"c:\\Program Files\\Common Files\\Rockwell\\RdcyHost.exe"=
"c:\\Program Files\\Common Files\\Rockwell\\NmspHost.exe"=
"c:\\Program Files\\Common Files\\Rockwell\\RnaDirServer.exe"=
"c:\\Program Files\\Common Files\\Rockwell\\EventServer.exe"=
"c:\\Program Files\\Common Files\\Rockwell\\DaClient.exe"=
"c:\\Program Files\\Common Files\\Rockwell\\RNADiagReceiver.exe"=
"c:\\Program Files\\Common Files\\Rockwell\\RNADiagnosticsSrv.exe"=
"c:\\Program Files\\Common Files\\Rockwell\\VStudio.exe"=
"c:\\WINDOWS\\system32\\OpcEnum.exe"=
"c:\\Program Files\\Rockwell Software\\RSCommon\\rssql_xml.exe"=
"c:\\Program Files\\Rockwell Software\\RSSql\\rssql.exe"=
"c:\\Program Files\\Rockwell Software\\RSSql\\rssql_tmctrl.exe"=
"c:\\Program Files\\Rockwell Software\\RSSql\\rssql_trnmgr.exe"=
"c:\\Program Files\\Rockwell Software\\RSSql\\rssql_cfg_server.exe"=
"c:\\Program Files\\Rockwell Software\\RSSql\\rssql_comp_storer.exe"=
"c:\\Program Files\\Rockwell Software\\RSSql\\rssql_lnxcoll.exe"=
"c:\\Program Files\\Rockwell Software\\RSSql\\rssql_rnacoll.exe"=
"c:\\Program Files\\Rockwell Software\\RSSql\\rssql_rsvcoll.exe"=
"c:\\Program Files\\Rockwell Software\\RSSql\\rssql_opccoll.exe"=
"c:\\Program Files\\Rockwell Software\\RSSql\\rssql_trx_csv.exe"=
"c:\\Program Files\\Rockwell Software\\RSLinx\\RSLINX.EXE"=
"c:\\Program Files\\Rockwell Software\\OPCTools\\OPCTest\\opctest.exe"=
"c:\\Program Files\\Rockwell Software\\FactoryTalk Activation\\lmgrd.exe"=
"c:\\Program Files\\Rockwell Software\\FactoryTalk Activation\\flexsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\ArchestrA\\aaLogger.exe"=
"c:\\Program Files\\Common Files\\ArchestrA\\slssvc.exe"=
"c:\\Program Files\\Wonderware\\InTouch\\wm.exe"=
"c:\\Program Files\\Wonderware\\InTouch\\view.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\system32\\dllhost.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Designjet System Maintenance\\hp_dj_sme.exe"=
"c:\\Program Files\\Schneider Electric\\Vijeo-Designer\\Vijeo-Runtime\\Public\\Bin\\Koohi.exe"=
"c:\\Program Files\\Canary Labs\\Historian\\HistorianAdmin.exe"=
"c:\\Program Files\\Common Files\\OPC Foundation\\UA\\v1.0\\Bin\\Opc.Ua.DiscoveryServer.exe"=
"c:\\Program Files\\Canary Labs\\Logger\\LoggerAdmin.exe"=
"c:\\Program Files\\WatchGuard\\Mobile User VPN\\IreIKE.exe"=
"c:\program files\WatchGuard\Mobile User VPN\ViewLog.exe"= c:\program files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog
"c:\program files\WatchGuard\Mobile User VPN\CmonApp.exe"= c:\program files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp
"c:\program files\WatchGuard\Mobile User VPN\vpn.exe"= c:\program files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"445:TCP"= 445:TCP:@xpsp2res.dll,-22005
"135:TCP"= 135:TCP:Port 135 TCP
"400:TCP"= 400:TCP:Port 400 TCP
"401:TCP"= 401:TCP:Port 401 TCP
"402:TCP"= 402:TCP:Port 402 TCP
"102:TCP"= 102:TCP:DAS SI 102
"502:TCP"= 502:TCP:Modicon 502
"1434:UDP"= 1434:UDP:SQL Server Browser 1434
"1433:TCP"= 1433:TCP:SQL TCP 1433
"2221:TCP"= 2221:TCP:DAS ABTCP 2221
"2222:TCP"= 2222:TCP:DAS ABTCP 2222
"2223:TCP"= 2223:TCP:DAS ABTCP 2223
"5413:TCP"= 5413:TCP:Port 5413
"9001:TCP"= 9001:TCP:vista 9001
"9002:TCP"= 9002:TCP:EnvMngr 9002
"9003:TCP"= 9003:TCP:MsgMngr 9003
"9004:TCP"= 9004:TCP:SecMngr 9004
"9006:TCP"= 9006:TCP:RedMngr 9006
"9007:TCP"= 9007:TCP:UnilinkMngr 9007
"9008:TCP"= 9008:TCP:BatchMngr 9008
"9011:TCP"= 9011:TCP:LogMngr 9011
"9012:TCP"= 9012:TCP:InfoMngr 9012
"9013:UDP"= 9013:UDP:RedMngrX 9013
"9014:UDP"= 9014:UDP:RedMngrX2 9014
"9015:TCP"= 9015:TCP:HistQMngrvista 9015
"9016:TCP"= 9016:TCP:HistQReader 9016
"44818:TCP"= 44818:TCP:Logix 44818
"4840:TCP"= 4840:TCP:UA Local Discovery Server (OPC.TCP 4840)
"52601:TCP"= 52601:TCP:UA Local Discovery Server (HTTP 52601)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 Canary Labs Enterprise Historian;Canary Labs Enterprise Historian;c:\program files\Canary Labs\Historian\CLIHistorian.exe [12/13/2010 10:57 AM 3122688]
R2 Canary_Labs_Historian_Monitor;Canary Labs Enterprise Historian Monitor;c:\program files\Canary Labs\Historian\CLIHistorianMonitor.exe [12/13/2010 10:51 AM 10752]
R2 Crypto;Crypto;c:\windows\system32\drivers\Crypto.sys [1/24/2011 5:53 PM 521786]
R2 FactoryTalk Activation Service;FactoryTalk Activation Service;c:\program files\Rockwell Software\FactoryTalk Activation\lmgrd.exe [11/17/2003 6:50 PM 659456]
R2 FTActivationBoost;FactoryTalk Activation Helper;c:\program files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe [9/29/2008 1:49 PM 66848]
R2 IPSECDRV;SafeNet IPSec Plugin;c:\windows\system32\drivers\IpSecDrv.sys [1/24/2011 5:53 PM 119864]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2/22/2011 11:14 AM 304464]
R2 NmspHost;Rockwell Namespace Services;c:\program files\Common Files\Rockwell\NmspHost.exe [9/17/2007 11:57 PM 212992]
R2 RdcyHost;Rockwell Redundancy Services;c:\program files\Common Files\Rockwell\RdcyHost.exe [9/17/2007 11:57 PM 212992]
R2 rssql_cfg_server;FactoryTalk Transaction Manager Configuration Server;c:\program files\Rockwell Software\RSSql\rssql_cfg_server.exe [9/25/2007 6:46 PM 229444]
R2 rssql_comp_storer;FactoryTalk Transaction Manager Compression Server;c:\program files\Rockwell Software\RSSql\rssql_comp_storer.exe [9/25/2007 6:48 PM 114757]
R2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [4/17/2005 11:30 AM 124608]
R2 SSIPDDP;SSIPDDP Parallel port device driver;c:\windows\system32\drivers\SSIPDDP.SYS [2/24/2010 8:56 AM 55296]
R2 UA Local Discovery Server;UA Local Discovery Server;c:\program files\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe [5/31/2010 6:26 PM 28160]
R2 XBTZG935 USB Link Cable;XBTZG935 USB Link Cable;c:\program files\Schneider Electric\Vijeo-Designer\Vijeo-Frame\XBTZG935\XBTZG935svr.exe [8/24/2010 7:25 PM 90112]
R3 abpcd;Allen-Bradley 1784-PCD 32-Bit Driver;c:\windows\system32\drivers\abpcd.sys [8/27/2004 11:19 AM 71336]
R3 DniVap;SafeNet WAN Miniport (VA);c:\windows\system32\drivers\vap.sys [1/24/2011 5:53 PM 36188]
R3 EraserUtilDrvI10;EraserUtilDrvI10;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI10.sys [3/2/2011 2:11 PM 102448]
R3 EventServer;Rockwell Event Server;c:\program files\Common Files\Rockwell\EventServer.exe [9/17/2007 10:36 PM 217088]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2/22/2011 11:14 AM 20952]
S1 abpicw2k;AB PIC/AIC+ Driver;c:\windows\system32\drivers\abpicw2k.sys [7/25/2008 9:10 AM 119016]
S1 VirtualBackplane;A-B Virtual Backplane;c:\windows\system32\Drivers\VirtualBackplane.sys –> c:\windows\system32\Drivers\VirtualBackplane.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/29/2009 7:20 AM 133104]
S3 Canary Labs Error Log Server;Canary Labs Error Log Server;c:\program files\Canary Labs\Shared\ErrorLogServer.exe [12/13/2010 10:52 AM 164864]
S3 Canary Labs HDA Server;Canary Labs HDA Server;c:\program files\Canary Labs\Historian\HDAServer.exe [12/13/2010 10:53 AM 344576]
S3 EraserUtilDrv10741;EraserUtilDrv10741;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10741.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10741.sys [?]
S3 PccWdm;%PccWdm.DeviceDesc%;c:\windows\system32\drivers\PccWdm.sys [11/15/2001 6:28 AM 57572]
S3 RsiKtControl;RsiKtControl;c:\windows\system32\RSIKT.SYS [7/5/2008 5:19 PM 39067]
S3 RSSERIAL;RSLinx Classic Serial Driver;c:\windows\system32\rsserial.sys [7/5/2008 5:19 PM 155440]
S3 rssql_ddecoll;FactoryTalk Transaction Manager DDE Connector;c:\program files\Rockwell Software\RSSql\rssql_ddecoll.exe [9/25/2007 6:48 PM 118849]
S3 rssql_lnxcoll;FactoryTalk Transaction Manager RSlinx Connector;c:\program files\Rockwell Software\RSSql\rssql_lnxcoll.exe [9/25/2007 6:48 PM 315457]
S3 rssql_mts_storer;FactoryTalk Transaction Manager COM+ Enterprise Connector;c:\program files\Rockwell Software\RSSql\rssql_mts_storer.exe [9/25/2007 6:48 PM 65604]
S3 rssql_oci_storer;FactoryTalk Transaction Manager OCI Enterprise Connector ;c:\program files\Rockwell Software\RSSql\rssql_oci_storer.exe [9/25/2007 6:47 PM 73796]
S3 rssql_oledb_storer;FactoryTalk Transaction Manager OLE-DB Enterprise Connector ;c:\program files\Rockwell Software\RSSql\rssql_oledb_storer.exe [9/25/2007 6:47 PM 65606]
S3 rssql_opccoll;FactoryTalk Transaction Manager OPC Connector;c:\program files\Rockwell Software\RSSql\rssql_opccoll.exe [9/25/2007 6:48 PM 315457]
S3 rssql_rnacoll;FactoryTalk Transaction Manager FactoryTalk Connector;c:\program files\Rockwell Software\RSSql\rssql_rnacoll.exe [9/25/2007 6:49 PM 315457]
S3 rssql_rsvcoll;FactoryTalk Transaction Manager RSView Connector;c:\program files\Rockwell Software\RSSql\rssql_rsvcoll.exe [9/25/2007 6:48 PM 307265]
S3 rssql_storer;FactoryTalk Transaction Manager ODBC Enterprise Connector;c:\program files\Rockwell Software\RSSql\rssql_storer.exe [9/25/2007 6:47 PM 69696]
S3 rssql_tb;FactoryTalk Transaction Manager Transaction Manager Service;c:\program files\Rockwell Software\RSSql\rssql_trnmgr.exe [9/25/2007 6:47 PM 155712]
S3 rssql_tmctrl;FactoryTalk Transaction Manager Transaction and Control Manager ;c:\program files\Rockwell Software\RSSql\rssql_tmctrl.exe [9/25/2007 6:47 PM 176192]
.
Contents of the 'Scheduled Tasks' folder

2011-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-29 12:19]

2011-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-29 12:19]

2010-12-20 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2010-12-13 18:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2801948
uInternet Connection Wizard,ShellNext = hxxp://www.interstatebatteries.com/cs_estore/DealerLocator/Default.aspx?ZipCode=46750
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office11\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: ReminderFox: {ada4b710-8346-4b82-8199-5de2b400a6ae} - %profile%\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed]
FF - Ext: NCH EN Community Toolbar: {37483b40-c254-4a72-bda4-22ee90182c1e} - %profile%\extensions\{37483b40-c254-4a72-bda4-22ee90182c1e}
.
.
——- File Associations ——-
.
.scr=AutoCADLTScriptFile
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
URLSearchHooks-{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - (no file)
WebBrowser-{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file)
WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - (no file)
AddRemove-WinPcapInst - c:\program files\WinPcap\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-03 08:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
UsbCipHelper = c:\program files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe???????????Nj?w??????@???D?????&??|P?E????|????????????A??|????P?E?????????4???????????????????>?@?????T???@????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
@DACL=(02 0010)
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@DACL=(02 0010)
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1496)
c:\windows\system32\NRDWIN32.dll
c:\windows\system32\AXNMAS~1.OCX
c:\windows\system32\AXNMAS~2.OCX

- - - - - - - > 'Explorer.exe'(4568)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\NLS\ENGLISH\NWSHLXNR.DLL
c:\windows\system32\NLS\ENGLISH\NOVNPNTR.DLL
c:\windows\system32\netprovcredman.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\WatchGuard\Mobile User VPN\IreIKE.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Common Files\ArchestrA\aaLogger.exe
c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
c:\windows\system32\cusrvc.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Common Files\ArchestrA\NTServApp.exe
c:\program files\Rockwell Software\FactoryTalk Activation\flexsvr.exe
c:\program files\WatchGuard\Mobile User VPN\IPSecMon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\lotus\notes\ntmulti.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Common Files\Rockwell\RNADiagnosticsSrv.exe
c:\program files\Common Files\Rockwell\RsvcHost.exe
c:\program files\Common Files\ArchestrA\slssvc.exe
c:\program files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\StacSV.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\Intel\Wireless\Bin\WLKeeper.exe
c:\program files\Common Files\Rockwell\EventClientMultiplexer.exe
c:\program files\Common Files\Rockwell\RnaDirServer.exe
c:\program files\Common Files\Rockwell\RNADirMultiplexor.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\NWTRAY.EXE
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2011-03-03 08:15:39 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-03 13:15

Pre-Run: 30,284,967,936 bytes free
Post-Run: 31,372,005,376 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - D326AD4FEE507F8B424E76D65F3E8F1D
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.






Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
When I tried to look for updates, Malwarebytes began downloading the file, but toward the end of the download the following error occurred. An error has occurred. Please report this error code too our support team. MBAM_ERROR-UPDATING (403,0,HTTPStatusCode) I tried several times.
Here is the Malwarebytes scan log. I still couldn't get it to update, but I ran the scan anyway. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5873 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 3/3/2011 9:41:36 AM mbam-log-2011-03-03 (09-41-36).txt Scan type: Quick scan Objects scanned: 181037 Time elapsed: 7 minute(s), 4 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Eset Scan Log file ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6425 # api_version=3.0.2 # EOSSerial=0545ef957f7f504bb45ec9008d7874d2 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-03-03 05:34:15 # local_time=2011-03-03 12:34:15 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=182596 # found=5 # cleaned=5 # scan_time=5418 C:\System Volume Information\_restore{3B579FA2-C712-4331-955E-4EB6A46630D1}\RP454\A0059530.exe Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3B579FA2-C712-4331-955E-4EB6A46630D1}\RP454\A0059531.exe a variant of Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{3B579FA2-C712-4331-955E-4EB6A46630D1}\RP475\A0061651.exe a variant of Win32/RegistryBooster application (deleted - quarantined) 00000000000000000000000000000000 C E:\052410\Downloads\registrybooster.exe a variant of Win32/RegistryBooster application (deleted - quarantined) 00000000000000000000000000000000 C E:\122310\Downloads\registrybooster.exe a variant of Win32/RegistryBooster application (deleted - quarantined) 00000000000000000000000000000000 C
OTL Log

OTL logfile created on: 3/4/2011 7:20:49 AM - Run 2
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\blacy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 4092 5600 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 29.12 Gb Free Space | 39.07% Space Free | Partition Type: NTFS
Drive E: | 1397.26 Gb Total Space | 1320.50 Gb Free Space | 94.51% Space Free | Partition Type: NTFS

Computer Name: BLACYXP | User Name: BLacy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\blacy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Canary Labs\Historian\CLIHistorian.exe (Canary Labs, Inc.)
PRC - C:\Program Files\Canary Labs\Historian\CLIHistorianMonitor.exe (Canary Labs, Inc.)
PRC - C:\Program Files\Canary Labs\Shared\TrayIcon.exe (Canary Labs, Inc.)
PRC - C:\Program Files\Schneider Electric\Vijeo-Designer\Vijeo-Frame\XBTZG935\XBTZG935svr.exe (Schneider Electric Inc.)
PRC - C:\Program Files\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe (OPC Foundation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\NCH Swift Sound\Verbose\verbose.exe (NCH Software)
PRC - C:\Program Files\Common Files\ArchestrA\NTServApp.exe (Invensys Systems, Inc.)
PRC - C:\Program Files\Common Files\ArchestrA\aaLogger.exe (Invensys Systems, Inc.)
PRC - C:\Program Files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe (Rockwell Automation Inc.)
PRC - C:\Program Files\Common Files\ArchestrA\slssvc.exe (Invensys Systems, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\RsvcHost.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe (Rockwell Automation Inc.)
PRC - C:\Program Files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe (Rockwell Automation, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Rockwell Software\RSSql\rssql_comp_storer.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Rockwell Software\RSSql\rssql_cfg_server.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\RdcyHost.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\NmspHost.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\RNADirMultiplexor.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\RnaDirServer.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Common Files\Rockwell\EventServer.exe (Rockwell Automation, Inc.)
PRC - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Rockwell Software\FactoryTalk Activation\flexsvr.exe ()
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DoScan.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe (SafeNet)
PRC - C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe (SafeNet)
PRC - C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe (SafeNet)
PRC - C:\Program Files\lotus\notes\ntmulti.exe (IBM Corp)
PRC - C:\WINDOWS\system32\cusrvc.exe (Novell, Inc.)
PRC - C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe (Macrovision Corporation)
PRC - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\RealVNC\WinVNC\winvnc.exe (RealVNC Ltd.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
PRC - C:\WINDOWS\system32\nwtray.exe (Novell, Inc.)
PRC - C:\WINDOWS\system32\dpmw32.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\blacy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – File not found
SRV - (HidServ) – File not found
SRV - (Canary Labs Enterprise Historian) – C:\Program Files\Canary Labs\Historian\CLIHistorian.exe (Canary Labs, Inc.)
SRV - (Canary Labs HDA Server) – C:\Program Files\Canary Labs\Historian\HDAServer.exe (Canary Labs, Inc.)
SRV - (Canary Labs Error Log Server) – C:\Program Files\Canary Labs\Shared\ErrorLogServer.exe (Canary Labs, Inc.)
SRV - (Canary_Labs_Historian_Monitor) – C:\Program Files\Canary Labs\Historian\CLIHistorianMonitor.exe (Canary Labs, Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (XBTZG935 USB Link Cable) – C:\Program Files\Schneider Electric\Vijeo-Designer\Vijeo-Frame\XBTZG935\XBTZG935svr.exe (Schneider Electric Inc.)
SRV - (UA Local Discovery Server) – C:\Program Files\Common Files\OPC Foundation\UA\v1.0\Bin\Opc.Ua.DiscoveryServer.exe (OPC Foundation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (OpcEnum) – C:\WINDOWS\system32\OpcEnum.exe (OPC Foundation)
SRV - (WWNetDDE) – C:\Program Files\Common Files\ArchestrA\wwnetdde.exe (Invensys Systems, Inc.)
SRV - (FS Service Control) – C:\Program Files\Common Files\ArchestrA\NTServApp.exe (Invensys Systems, Inc.)
SRV - (aaLogger) – C:\Program Files\Common Files\ArchestrA\aaLogger.exe (Invensys Systems, Inc.)
SRV - (FTActivationBoost) – C:\Program Files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe (Rockwell Automation Inc.)
SRV - (slssvc) – C:\Program Files\Common Files\ArchestrA\slssvc.exe (Invensys Systems, Inc.)
SRV - (RSLinx) – C:\Program Files\Rockwell Software\RSLinx\RSLINX.EXE (Rockwell Automation, Inc.)
SRV - (RsvcHost) – C:\Program Files\Common Files\Rockwell\RsvcHost.exe (Rockwell Automation, Inc.)
SRV - (RNADiagReceiver) – C:\Program Files\Common Files\Rockwell\RNADiagReceiver.exe (Rockwell Automation, Inc.)
SRV - (RNADiagnosticsService) – C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe (Rockwell Automation Inc.)
SRV - (dnWhoDisp) – C:\Program Files\Rockwell Software\RSLinx\dnwhodisp.exe (Rockwell Automation, Inc.)
SRV - (Harmony) – C:\Program Files\Rockwell Software\RSCommon\RSOBSERV.EXE (Rockwell Automation, Inc.)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel Corporation)
SRV - (rssql_rnacoll) – C:\Program Files\Rockwell Software\RSSql\rssql_rnacoll.exe (Rockwell Automation, Inc.)
SRV - (rssql_opccoll) – C:\Program Files\Rockwell Software\RSSql\rssql_opccoll.exe (Rockwell Automation, Inc.)
SRV - (rssql_lnxcoll) – C:\Program Files\Rockwell Software\RSSql\rssql_lnxcoll.exe (Rockwell Automation, Inc.)
SRV - (rssql_rsvcoll) – C:\Program Files\Rockwell Software\RSSql\rssql_rsvcoll.exe (Rockwell Automation, Inc.)
SRV - (rssql_ddecoll) – C:\Program Files\Rockwell Software\RSSql\rssql_ddecoll.exe (Rockwell Automation, Inc.)
SRV - (rssql_comp_storer) – C:\Program Files\Rockwell Software\RSSql\rssql_comp_storer.exe (Rockwell Automation, Inc.)
SRV - (rssql_mts_storer) – C:\Program Files\Rockwell Software\RSSql\rssql_mts_storer.exe (Rockwell Automation, Inc.)
SRV - (rssql_oledb_storer) – C:\Program Files\Rockwell Software\RSSql\rssql_oledb_storer.exe (Rockwell Automation, Inc.)
SRV - (rssql_oci_storer) – C:\Program Files\Rockwell Software\RSSql\rssql_oci_storer.exe (Rockwell Automation, Inc.)
SRV - (rssql_storer) – C:\Program Files\Rockwell Software\RSSql\rssql_storer.exe (Rockwell Automation, Inc.)
SRV - (rssql_tmctrl) – C:\Program Files\Rockwell Software\RSSql\rssql_tmctrl.exe (Rockwell Automation, Inc.)
SRV - (rssql_tb) – C:\Program Files\Rockwell Software\RSSql\rssql_trnmgr.exe (Rockwell Automation, Inc.)
SRV - (rssql_cfg_server) – C:\Program Files\Rockwell Software\RSSql\rssql_cfg_server.exe (Rockwell Automation, Inc.)
SRV - (RdcyHost) – C:\Program Files\Common Files\Rockwell\RdcyHost.exe (Rockwell Automation, Inc.)
SRV - (NmspHost) – C:\Program Files\Common Files\Rockwell\NmspHost.exe (Rockwell Automation, Inc.)
SRV - (RNADirMultiplexor) – C:\Program Files\Common Files\Rockwell\RNADirMultiplexor.exe (Rockwell Automation, Inc.)
SRV - (RNADirectory) – C:\Program Files\Common Files\Rockwell\RnaDirServer.exe (Rockwell Automation, Inc.)
SRV - (EventClientMultiplexer) – C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe (Rockwell Automation, Inc.)
SRV - (EventServer) – C:\Program Files\Common Files\Rockwell\EventServer.exe (Rockwell Automation, Inc.)
SRV - (AdobeActiveFileMonitor6.0) – C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
SRV - (STacSV) – C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (IPSECMON) – C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe (SafeNet)
SRV - (IreIKE) – C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe (SafeNet)
SRV - (Multi-user Cleanup Service) – C:\Program Files\lotus\notes\ntmulti.exe (IBM Corp)
SRV - (cusrvc) – C:\WINDOWS\system32\cusrvc.exe (Novell, Inc.)
SRV - (FactoryTalk Activation Service) – C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe (Macrovision Corporation)
SRV - (winvnc) – C:\Program Files\RealVNC\WinVNC\winvnc.exe (RealVNC Ltd.)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110204.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110204.002\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (FTDIBUS) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (FTSER2K) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (abpicw2k) – C:\WINDOWS\system32\drivers\abpicw2k.sys (Rockwell Software, Inc.)
DRV - (RSSERIAL) – C:\WINDOWS\SYSTEM32\RSSERIAL.SYS (Rockwell Software Inc.)
DRV - (RsiKtControl) – C:\WINDOWS\system32\RSIKT.SYS (Rockwell Software Inc.)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (NETw4x32) Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (guardian2) – C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (Sentinel) – C:\WINDOWS\System32\Drivers\SENTINEL.SYS (SafeNet, Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (abpcd) – C:\WINDOWS\system32\drivers\abpcd.sys (Rockwell Automation)
DRV - (IPSECDRV) – C:\WINDOWS\system32\drivers\IpSecDrv.sys (SafeNet)
DRV - (Crypto) – C:\WINDOWS\System32\drivers\Crypto.sig ()
DRV - (NetwareWorkstation) – C:\WINDOWS\system32\NetWare\nwfs.sys (Novell, Inc.)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (NWFILTER) – C:\WINDOWS\system32\NetWare\nwfilter.sys (Novell, Inc.)
DRV - (NWDHCP) – C:\WINDOWS\system32\NetWare\nwdhcp.sys ()
DRV - (NICM) – C:\WINDOWS\system32\drivers\nicm.sys (Novell, Inc.)
DRV - (NWDNS) – C:\WINDOWS\system32\NetWare\nwdns.sys ()
DRV - (NWSLP) – C:\WINDOWS\system32\NetWare\nwslp.sys ()
DRV - (SRVLOC) – C:\WINDOWS\system32\NetWare\srvloc.sys (Novell, Inc.)
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (NWSAP) – C:\WINDOWS\system32\NetWare\nwsap.sys ()
DRV - (NWSNS) – C:\WINDOWS\system32\NetWare\nwsns.sys ()
DRV - (NWSIPX32) – C:\WINDOWS\system32\NetWare\nwsipx32.sys (Novell, Inc.)
DRV - (NWHOST) – C:\WINDOWS\system32\NetWare\nwhost.sys ()
DRV - (RESMGR) – C:\WINDOWS\system32\NetWare\resmgr.sys (Novell, Inc.)
DRV - (DniVap) SafeNet WAN Miniport (VA) – C:\WINDOWS\system32\drivers\vap.sys (Deterministic Networks Inc.)
DRV - (PccWdm) – C:\WINDOWS\system32\drivers\PccWdm.sys (Rockwell Software, Inc)
DRV - (SSIPDDP) – C:\WINDOWS\system32\drivers\SSIPDDP.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2801948
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "NCH EN Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {37483b40-c254-4a72-bda4-22ee90182c1e}:[removed]
FF - prefs.js..extensions.enabledItems: {ada4b710-8346-4b82-8199-5de2b400a6ae}:1.9.9.2
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&q="

FF - HKLM\software\mozilla\Mozilla Firefox 3.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/03 10:07:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/25 10:00:45 | 000,000,000 | —D | M]

[2009/06/09 11:24:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\blacy\Application Data\Mozilla\Extensions
[2011/02/25 10:48:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\extensions
[2010/04/28 07:04:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/13 13:26:36 | 000,000,000 | —D | M] (NCH EN Community Toolbar) – C:\Documents and Settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\extensions\{37483b40-c254-4a72-bda4-22ee90182c1e}
[2011/02/07 18:52:38 | 000,000,000 | —D | M] (ReminderFox) – C:\Documents and Settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2010/12/13 13:26:36 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\blacy\Application Data\Mozilla\Firefox\Profiles\4qx274im.default\extensions\[removed]
[2011/02/25 10:48:26 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/08/17 14:56:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/17 14:56:22 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/08/25 12:02:50 | 000,027,976 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
[2009/08/28 08:08:42 | 000,126,360 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
[2008/06/02 13:59:02 | 000,051,200 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\FTDWSER.DLL
[2009/08/28 08:08:58 | 000,098,712 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2009/08/25 12:01:25 | 000,060,824 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2010/08/17 14:56:20 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2008/06/02 13:04:44 | 000,163,840 | —- | M] (InfoPrint Solutions Company) – C:\Program Files\Mozilla Firefox\plugins\NPOAFP32.DLL

O1 HOSTS File: ([2011/03/03 08:07:35 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Canary Labs TrayIcon] C:\Program Files\Canary Labs\Shared\TrayIcon.exe (Canary Labs, Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NDPS] C:\WINDOWS\system32\dpmw32.exe ()
O4 - HKLM..\Run: [NWTRAY] C:\WINDOWS\System32\nwtray.exe (Novell, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [UsbCipHelper] C:\Program Files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe (Rockwell Automation, Inc.)
O4 - HKLM..\Run: [Verbose] C:\Program Files\NCH Swift Sound\Verbose\verbose.exe (NCH Software)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WinVNC] C:\Program Files\RealVNC\WinVNC\winvnc.exe (RealVNC Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Mobile User VPN.lnk = C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe (SafeNet)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: CompatibleRUPSecurity = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\NetWare\nwws2nds.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\system32\NetWare\nwws2sap.dll (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\WINDOWS\system32\NetWare\nwws2slp.dll (Novell, Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1243368827155 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://rockwellautomation.webex.com/client…ort/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.112.77 [removed] [removed] 192.168.112.102
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (NWGINA.DLL) - C:\WINDOWS\System32\nwgina.dll (Novell, INC.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\WRNotifier: DllName - WRLogonNTF.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\blacy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\blacy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/04 15:58:21 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/03 10:57:41 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/03/03 10:56:33 | 002,322,184 | —- | C] (ESET) – C:\Documents and Settings\blacy\Desktop\esetsmartinstaller_enu.exe
[2011/03/03 07:48:09 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/03/03 07:41:38 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/03/03 07:41:37 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/03/03 07:41:37 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/03/03 07:41:37 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/03/03 07:39:54 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/03/03 07:31:48 | 000,000,000 | —D | C] – C:\Qoobox
[2011/03/02 12:28:46 | 001,068,544 | —- | C] (Coupons.com Incorporated) – C:\Documents and Settings\blacy\Desktop\CouponPrinter.exe
[2011/03/02 10:45:38 | 001,374,808 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\blacy\Desktop\TDSSKiller.exe
[2011/03/02 08:27:48 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\blacy\Desktop\OTL.exe
[2011/02/25 04:30:10 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Malwarebytes
[2011/02/23 15:01:41 | 000,000,000 | —D | C] – C:\Documents and Settings\blacy\Application Data\Malwarebytes
[2011/02/22 11:14:53 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/22 11:14:52 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/22 11:14:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/22 11:14:51 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/18 16:47:56 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2011/02/18 16:47:56 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2011/02/18 16:47:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop
[2011/02/18 16:47:38 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2011/02/16 10:16:59 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/02/16 10:16:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/02/16 10:16:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/02/16 10:16:52 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/02/15 14:11:00 | 000,000,000 | —D | C] – C:\Program Files\Citrix
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/04 07:07:29 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/04 07:07:24 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/04 07:05:46 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/03 15:20:10 | 000,124,607 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Stanhope Oneline.dwg
[2011/03/03 15:15:46 | 000,416,853 | —- | M] () – C:\Documents and Settings\blacy\Desktop\MWB Screenshot.pdf
[2011/03/03 15:13:02 | 000,124,607 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Stanhope Oneline.bak
[2011/03/03 14:59:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/03 13:19:56 | 000,061,326 | —- | M] () – C:\Documents and Settings\blacy\My Documents\KqjceEMZ.pdf.part.pdf
[2011/03/03 10:56:59 | 002,322,184 | —- | M] (ESET) – C:\Documents and Settings\blacy\Desktop\esetsmartinstaller_enu.exe
[2011/03/03 10:00:05 | 000,234,230 | —- | M] () – C:\Documents and Settings\blacy\Desktop\Mace PO.pdf
[2011/03/03 09:24:53 | 000,097,792 | —- | M] () – C:\Documents and Settings\blacy\Desktop\NCP Remittance Coupon.pdf
[2011/03/03 08:07:35 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/03/03 07:48:16 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/03/03 07:27:21 | 004,278,549 | R— | M] () – C:\Documents and Settings\blacy\Desktop\ComboFix.exe
[2011/03/02 12:28:57 | 001,068,544 | —- | M] (Coupons.com Incorporated) – C:\Documents and Settings\blacy\Desktop\CouponPrinter.exe
[2011/03/02 10:45:38 | 001,374,808 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\blacy\Desktop\TDSSKiller.exe
[2011/03/02 10:23:18 | 000,035,840 | —- | M] () – C:\Documents and Settings\blacy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/02 08:27:59 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\blacy\Desktop\OTL.exe
[2011/02/28 10:19:47 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/25 10:00:51 | 000,001,620 | —- | M] () – C:\Documents and Settings\blacy\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/25 10:00:51 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/24 09:56:48 | 000,568,591 | —- | M] () – C:\Documents and Settings\blacy\Desktop\srap11.pdf
[2011/02/24 09:56:18 | 000,243,770 | —- | M] () – C:\Documents and Settings\blacy\Desktop\2011rfpp2grant.pdf
[2011/02/23 15:26:25 | 000,115,858 | —- | M] () – C:\Documents and Settings\blacy\Desktop\IPConfig.jpg
[2011/02/14 15:27:33 | 000,000,113 | —- | M] () – C:\WINDOWS\notesnsd.ini
[2011/02/09 13:57:01 | 000,036,171 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Stanhope Main DP.dwg
[2011/02/09 11:20:23 | 000,046,765 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Stanhope Site Plan.dwg
[2011/02/04 11:14:42 | 000,667,648 | —- | M] () – C:\Documents and Settings\blacy\My Documents\Motors_be.mdb
[2011/02/04 07:15:48 | 000,457,228 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/04 07:15:48 | 000,078,034 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/03 15:15:43 | 000,416,853 | —- | C] () – C:\Documents and Settings\blacy\Desktop\MWB Screenshot.pdf
[2011/03/03 13:19:56 | 000,061,326 | —- | C] () – C:\Documents and Settings\blacy\My Documents\KqjceEMZ.pdf.part.pdf
[2011/03/03 10:00:01 | 000,234,230 | —- | C] () – C:\Documents and Settings\blacy\Desktop\Mace PO.pdf
[2011/03/03 09:24:52 | 000,097,792 | —- | C] () – C:\Documents and Settings\blacy\Desktop\NCP Remittance Coupon.pdf
[2011/03/03 07:48:16 | 000,000,211 | —- | C] () – C:\Boot.bak
[2011/03/03 07:48:13 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/03/03 07:41:38 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/03/03 07:41:37 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/03/03 07:41:37 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/03/03 07:41:37 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/03/03 07:41:37 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/03/03 07:26:11 | 004,278,549 | R— | C] () – C:\Documents and Settings\blacy\Desktop\ComboFix.exe
[2011/02/25 10:00:51 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/24 09:56:48 | 000,568,591 | —- | C] () – C:\Documents and Settings\blacy\Desktop\srap11.pdf
[2011/02/24 09:56:18 | 000,243,770 | —- | C] () – C:\Documents and Settings\blacy\Desktop\2011rfpp2grant.pdf
[2011/02/23 15:26:22 | 000,115,858 | —- | C] () – C:\Documents and Settings\blacy\Desktop\IPConfig.jpg
[2011/02/22 11:00:04 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/08 13:26:05 | 000,046,765 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Stanhope Site Plan.dwg
[2011/02/04 15:24:44 | 000,667,648 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Motors_be.mdb
[2011/02/04 09:43:24 | 000,036,171 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Stanhope Main DP.dwg
[2011/02/04 09:29:13 | 000,124,607 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Stanhope Oneline.dwg
[2011/02/04 09:29:13 | 000,124,607 | —- | C] () – C:\Documents and Settings\blacy\My Documents\Stanhope Oneline.bak
[2011/01/27 08:13:05 | 000,000,659 | —- | C] () – C:\WINDOWS\Setupwizard.ini
[2011/01/24 17:53:17 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\nsldap32v50.dll
[2011/01/24 09:33:16 | 000,000,049 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2011/01/21 14:28:03 | 000,179,528 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/06 08:11:31 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2011/01/03 13:24:18 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\Rtf2Html.dll
[2011/01/03 13:24:14 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\Eztw32.dll
[2011/01/03 13:24:14 | 000,029,696 | —- | C] () – C:\WINDOWS\System32\rpiGlobalHook.dll
[2011/01/03 13:23:50 | 000,031,232 | —- | C] () – C:\WINDOWS\System32\Bcfont32.dll
[2011/01/03 13:23:49 | 000,015,840 | —- | C] () – C:\WINDOWS\System32\Machnm1.exe
[2011/01/03 13:23:49 | 000,007,432 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2011/01/03 13:23:47 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\ptouchif2.dll
[2011/01/03 13:23:47 | 000,030,208 | —- | C] () – C:\WINDOWS\System32\ptouchif1.dll
[2011/01/03 13:23:42 | 001,515,640 | —- | C] () – C:\WINDOWS\System32\SetPrinterDimensions.dll
[2010/08/10 13:16:04 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\redmonnt.dll
[2010/07/25 20:18:15 | 000,454,656 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2010/03/02 11:04:58 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2010/02/24 08:56:42 | 000,055,296 | —- | C] () – C:\WINDOWS\System32\drivers\SSIPDDP.SYS
[2010/02/24 08:56:42 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\SSIVDDP.DLL
[2010/02/24 08:56:42 | 000,000,745 | —- | C] () – C:\WINDOWS\System32\drivers\SSIDDDP.SYS
[2009/11/11 14:14:29 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2009/11/11 14:12:34 | 000,002,607 | —- | C] () – C:\WINDOWS\hyperlog.ini
[2009/09/11 09:24:59 | 000,000,000 | —- | C] () – C:\WINDOWS\licview.INI
[2009/09/11 09:06:08 | 000,000,000 | —- | C] () – C:\WINDOWS\aaLicView.INI
[2009/08/31 07:17:42 | 000,000,113 | —- | C] () – C:\WINDOWS\notesnsd.ini
[2009/08/19 08:39:19 | 000,000,030 | —- | C] () – C:\WINDOWS\FTDWNSPI.INI
[2009/08/18 13:46:45 | 000,000,000 | —- | C] () – C:\WINDOWS\rssql.INI
[2009/08/09 08:32:09 | 000,000,084 | —- | C] () – C:\WINDOWS\WININIT.INI
[2009/08/09 08:32:08 | 000,000,000 | —- | C] () – C:\WINDOWS\WinDnet.ini
[2009/06/25 08:58:36 | 000,032,256 | —- | C] () – C:\WINDOWS\System32\_UNODBC.dll
[2009/06/03 11:48:52 | 000,000,128 | —- | C] () – C:\Documents and Settings\blacy\Local Settings\Application Data\fusioncache.dat
[2009/06/01 15:50:37 | 000,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[2009/05/28 14:30:27 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\HPPAPR01.DLL
[2009/05/28 14:30:27 | 000,000,508 | —- | C] () – C:\WINDOWS\System32\HPPAPR01.DAT
[2009/05/28 13:05:41 | 000,000,032 | —- | C] () – C:\WINDOWS\EvMoveCF.INI
[2009/05/28 10:29:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/05/28 10:07:25 | 000,035,840 | —- | C] () – C:\Documents and Settings\blacy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/28 09:57:54 | 000,002,279 | —- | C] () – C:\WINDOWS\EDS.ini
[2009/05/28 09:54:55 | 000,000,128 | —- | C] () – C:\WINDOWS\rocksoft.ini
[2009/05/26 15:10:17 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2008/07/25 09:08:34 | 000,036,408 | —- | C] () – C:\WINDOWS\System32\LINXVDD.DLL
[2008/07/05 17:19:52 | 000,007,449 | —- | C] () – C:\WINDOWS\System32\drivers\SDDHP.BIN
[2008/07/05 17:19:52 | 000,006,400 | —- | C] () – C:\WINDOWS\System32\drivers\slcnewkt.bin
[2008/07/05 17:19:52 | 000,005,433 | —- | C] () – C:\WINDOWS\System32\drivers\SDDH.BIN
[2008/07/05 17:19:50 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\drivers\KTC.BIN
[2008/07/05 17:19:50 | 000,015,664 | —- | C] () – C:\WINDOWS\System32\drivers\PCMK485.BIN
[2008/07/05 17:19:50 | 000,015,557 | —- | C] () – C:\WINDOWS\System32\drivers\KTX485.BIN
[2008/07/05 17:19:50 | 000,009,282 | —- | C] () – C:\WINDOWS\System32\drivers\PCMKPCL.BIN
[2008/07/05 17:19:50 | 000,009,139 | —- | C] () – C:\WINDOWS\System32\drivers\KTXPCL.BIN
[2008/07/05 17:19:50 | 000,007,575 | —- | C] () – C:\WINDOWS\System32\drivers\KLPCL.BIN
[2008/07/05 17:19:50 | 000,001,825 | —- | C] () – C:\WINDOWS\System32\drivers\KT2ST2.BIN
[2008/07/05 17:19:50 | 000,001,824 | —- | C] () – C:\WINDOWS\System32\drivers\PCMKST3.BIN
[2008/07/05 17:19:50 | 000,001,824 | —- | C] () – C:\WINDOWS\System32\drivers\KLST2.BIN
[2008/07/05 17:19:50 | 000,001,801 | —- | C] () – C:\WINDOWS\System32\drivers\KT2ST1.BIN
[2008/07/05 17:19:50 | 000,001,800 | —- | C] () – C:\WINDOWS\System32\drivers\PCMKST1.BIN
[2008/07/05 17:19:50 | 000,001,800 | —- | C] () – C:\WINDOWS\System32\drivers\KTXST1.BIN
[2008/07/05 17:19:50 | 000,001,800 | —- | C] () – C:\WINDOWS\System32\drivers\KLST1.BIN
[2008/07/05 17:19:50 | 000,000,301 | —- | C] () – C:\WINDOWS\System32\drivers\PCMKST0.BIN
[2008/07/05 17:19:50 | 000,000,301 | —- | C] () – C:\WINDOWS\System32\drivers\KTXST0.BIN
[2008/07/05 17:19:50 | 000,000,248 | —- | C] () – C:\WINDOWS\System32\drivers\KLST0.BIN
[2008/07/05 17:19:50 | 000,000,177 | —- | C] () – C:\WINDOWS\System32\drivers\KT2ST0.BIN
[2008/07/05 17:19:50 | 000,000,011 | —- | C] () – C:\WINDOWS\System32\drivers\PCMKST2.BIN
[2008/05/12 19:32:52 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\StrStorage.dll
[2008/04/09 15:31:54 | 000,000,011 | —- | C] () – C:\WINDOWS\NetWare.INI
[2008/04/04 16:24:37 | 000,135,221 | —- | C] () – C:\WINDOWS\System32\nmasncp.dll
[2008/04/04 16:24:37 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\unclient.exe
[2008/04/04 16:24:36 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\GAMSWrap.dll
[2008/04/04 16:24:36 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\NMASReg.exe
[2008/04/04 16:24:36 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\NMASWrap.dll
[2008/04/04 16:18:44 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\AegisI5Installer.exe
[2008/04/04 16:16:05 | 000,684,032 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2008/04/04 16:16:05 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2008/04/04 16:10:56 | 000,910,304 | —- | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2008/04/04 16:10:56 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4831.dll
[2008/04/04 16:10:18 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\setupw2k.dll
[2008/04/04 16:10:18 | 000,015,898 | —- | C] () – C:\WINDOWS\System32\vlmsup.exe
[2008/04/04 16:10:18 | 000,001,740 | —- | C] () – C:\WINDOWS\System32\vipx.exe
[2008/04/04 16:10:16 | 000,241,746 | —- | C] () – C:\WINDOWS\System32\nwshlxnt.dll
[2008/04/04 16:10:11 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\lgncon32.dll
[2008/04/04 16:10:11 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\lgncxw32.dll
[2008/04/04 16:10:10 | 000,045,119 | —- | C] () – C:\WINDOWS\System32\dprpcw32.dll
[2008/04/04 16:10:10 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\dpmw32.exe
[2008/04/04 16:10:10 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\dplgnw32.dll
[2008/04/04 16:10:08 | 000,012,736 | —- | C] () – C:\WINDOWS\System32\cmdinfo.exe
[2008/04/04 16:10:00 | 000,002,757 | —- | C] () – C:\WINDOWS\System32\rdrstats.ini
[2008/04/04 16:09:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\prtwin32.dll
[2008/04/04 16:09:41 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\nwpsrv32.dll
[2008/04/04 16:09:37 | 000,219,136 | —- | C] () – C:\WINDOWS\System32\lgnwnt32.dll
[2008/04/04 16:09:30 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\nwslog32.dll
[2008/04/04 16:01:05 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/04/04 15:55:51 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/04/04 15:37:40 | 000,001,215 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/04/04 10:51:40 | 000,004,346 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/04/04 10:50:38 | 000,340,240 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/03/21 18:48:05 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 18:48:05 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 05:00:00 | 000,457,228 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 05:00:00 | 000,078,034 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/04/12 12:54:44 | 000,001,116 | —- | C] () – C:\WINDOWS\rsplugs.ini
[1998/12/07 15:11:22 | 000,227,840 | —- | C] () – C:\WINDOWS\System32\lmgr325a.dll
[1997/07/10 23:00:00 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\WRKGADM.EXE
[1997/07/10 23:00:00 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/10 23:00:00 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/10 23:00:00 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL

========== LOP Check ==========

[2009/09/11 08:54:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ArchestrA
[2009/10/07 08:58:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2011/01/26 13:26:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canary Labs
[2011/01/06 08:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2009/06/09 12:49:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2010/02/22 14:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Font Downloader
[2009/09/11 08:52:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InTouchDemos
[2010/07/26 06:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/12/20 13:25:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/01/26 13:55:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OPC Foundation
[2009/08/17 14:28:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rockwell
[2009/05/28 09:58:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rockwell Automation
[2009/09/24 09:32:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
[2010/11/24 10:21:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Software Toolbox
[2009/08/25 11:33:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WFCU
[2009/09/11 08:52:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wonderware
[2010/02/22 14:49:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{50D3FBE1-AD16-4F59-9326-86404D6B1B1F}
[2009/10/07 08:58:48 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Autodesk
[2010/08/10 13:26:15 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Babylon
[2011/01/18 12:05:22 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\BitZipper
[2011/01/06 08:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Canneverbe Limited
[2010/07/25 20:20:25 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\MyHeritage
[2010/12/20 13:25:03 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\NCH Swift Sound
[2010/08/19 08:53:16 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\OpenOffice.org
[2010/03/02 11:15:39 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\pdfforge
[2009/08/27 10:50:32 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Rockwell Software
[2010/09/22 14:07:34 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Schneider Electric
[2010/03/02 11:15:40 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Search Settings
[2010/11/24 10:20:51 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Software Toolbox
[2010/04/16 14:47:05 | 000,000,000 | —D | M] – C:\Documents and Settings\blacy\Application Data\Uniblue
[2010/12/20 14:00:39 | 000,000,282 | —- | M] () – C:\WINDOWS\Tasks\wavepadShakeIcon.job

========== Purity Check ==========



< End of report >
You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.









Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.







[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 24 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 24 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u24 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u24-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.










Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI