This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

antivirus removal

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hey, i had a licenced copy of net protector. i uninstalled it after its license period ws over. but the logo of net protector still appears when i shut down my system. how do i remove it?
Hi aaisha :welcome:



Unfortunately NetProtector is not a legit antivirus program, it's a rogue program:

http://forums.whatthetech.com/index.php?showtopic=113631

In that sense I'm afraid to say that you have paid for malware. I'm sorry about that.



We will have to dig deeper in order to remove the entire infection, and not just the logo at log-out screen.
Please follow these steps:


Step 1 | Please download OTL from one of the following mirrors:

This is THE Mirror

——————————————————————–

  • Save it to your desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it.
  • Double click inside the Custom Scan box at the bottom.
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel".
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop.
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in this topic.
  • You may need two posts to fit them both in.

Step 2 | Please download GMER from one of the following locations and save it to your desktop:

Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

——————————————————————–

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.

Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

[external image: Posted Image]

  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Make sure all options are checked except:
  • IAT/EAT
  • Drives/Partition other than Systemdrive, which is typically C:\
  • Show All (This is important, so do not miss it.)

[external image: Posted Image]
Click the image to enlarge it

  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
– If you encounter any problems, try running GMER in Safe Mode.
hey,
thanks for the reply. i executed the otl.exe. the scan.txt is not available on the given link… the notepad files created after running otl.exe are here:

OTL.txt

OTL logfile created on: 20/07/2011 9:52:38 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\dell\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MM/yyyy

2.96 Gb Total Physical Memory | 2.20 Gb Available Physical Memory | 74.44% Memory free
4.80 Gb Paging File | 4.14 Gb Available in Paging File | 86.38% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 13.08 Gb Free Space | 26.79% Space Free | Partition Type: NTFS
Drive D: | 49.81 Gb Total Space | 22.14 Gb Free Space | 44.45% Space Free | Partition Type: NTFS
Drive E: | 99.73 Gb Total Space | 95.05 Gb Free Space | 95.31% Space Free | Partition Type: NTFS
Drive F: | 99.71 Gb Total Space | 99.42 Gb Free Space | 99.71% Space Free | Partition Type: NTFS

Computer Name: I-127080E3EB544 | User Name: dell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\dell\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
PRC - C:\WINDOWS\system32\WDFMGR.EXE ()
PRC - C:\Program Files\IDT\WDM\STTRAY.EXE (IDT, Inc.)
PRC - c:\Program Files\IDT\XPM09_6047v002\WDM\STACSV.EXE (IDT, Inc.)
PRC - C:\Program Files\Hewlett-Packard\OrderReminder\ORDERREMINDER.EXE (Hewlett-Packard)
PRC - e:\oracle\ora90\BIN\ORACLE.EXE (Oracle Corporation)
PRC - C:\Program Files\DellTPad\HIDFIND.EXE (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\EXPLORER.EXE (Microsoft Corporation)
PRC - C:\Program Files\Huawei\MT841\DSLAGENT.EXE ()
PRC - C:\WINDOWS\system32\CMD.EXE (Microsoft Corporation)
PRC - C:\Program Files\DellTPad\APOINT.EXE (Alps Electric Co., Ltd.)
PRC - E:\oracle\ora90\BIN\AGNTSRVC.EXE (Oracle Corporation)
PRC - E:\oracle\ora90\Apache\Apache\APACHE.EXE ()
PRC - C:\WINDOWS\system32\AESTFLTR.EXE (Andrea Electronics Corporation)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
PRC - C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware Workstation\hqtray.exe (VMware, Inc.)
PRC - C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
PRC - E:\oracle\ora90\Apache\jdk\bin\java.exe ()
PRC - E:\oracle\ora90\BIN\dbsnmp.exe (Oracle Corporation)
PRC - E:\oracle\ora90\BIN\TNSLSNR.EXE ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\dell\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (XAMPP) – File not found
SRV - (gulviaoba) – File not found
SRV - (ApConSvc) – File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_e477fed.dll ()
SRV - (AVP) – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (UMWdf) – C:\WINDOWS\system32\WDFMGR.EXE ()
SRV - (STacSV) – c:\Program Files\IDT\XPM09_6047v002\WDM\STACSV.EXE (IDT, Inc.)
SRV - (OracleServiceTE) – e:\oracle\ora90\bin\ORACLE.EXE (Oracle Corporation)
SRV - (OracleOraHome90Agent) – E:\oracle\ora90\BIN\AGNTSRVC.EXE (Oracle Corporation)
SRV - (OracleOraHome90HTTPServer) – E:\oracle\ora90\Apache\Apache\APACHE.EXE ()
SRV - (wampmysqld) – c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe ()
SRV - (wampapache) – c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe (Apache Software Foundation)
SRV - (dsNcService) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (VMAuthdService) – C:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
SRV - (VMnetDHCP) – C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
SRV - (ufad-ws60) – C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe (VMware, Inc.)
SRV - (vmount2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
SRV - (OracleOraHome90PagingServer) – E:\oracle\ora90/bin/pagntsrv.exe ()
SRV - (OLAPServer) – E:\oracle\ora90\BIN\xsolap.exe (Oracle Corporation)
SRV - (Oracle OLAP Agent) – E:\oracle\ora90\BIN\xsaagent.exe ()
SRV - (OracleOraHome90SNMPPeerMasterAgent) – E:\oracle\ora90\BIN\agntsvc.exe ()
SRV - (OracleOraHome90SNMPPeerEncapsulator) – E:\oracle\ora90\BIN\encsvc.exe ()
SRV - (OracleOraHome90ClientCache) – E:\oracle\ora90\BIN\ONRSD.EXE ()
SRV - (OracleOraHome90TNSListener) – E:\oracle\ora90\BIN\TNSLSNR.exe ()
SRV - (xsSmartAgent) – E:\oracle\ora90\BIN\osagent.exe ()


========== Driver Services (SafeList) ==========

DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (zmdpseuk1) – C:\WINDOWS\system32\drivers\zmdpseuk1.sys ()
DRV - (kl2) – C:\WINDOWS\system32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (KL1) – C:\WINDOWS\system32\DRIVERS\kl1.sys (Kaspersky Lab ZAO)
DRV - (klim5) – C:\WINDOWS\system32\drivers\klim5.sys (Kaspersky Lab ZAO)
DRV - (klmouflt) – C:\WINDOWS\system32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (VBoxNetFlt) – C:\WINDOWS\system32\drivers\VBoxNetFlt.sys (Windows ® Server 2003 DDK provider)
DRV - (VBoxUSBMon) – C:\WINDOWS\system32\drivers\VBoxUSBMon.sys (Sun Microsystems, Inc.)
DRV - (VBoxDrv) – C:\WINDOWS\system32\drivers\VBoxDrv.sys ()
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (OA009Vid) – C:\WINDOWS\system32\drivers\OA009Vid.sys (Creative Technology Ltd.)
DRV - (OA009Ufd) – C:\WINDOWS\system32\drivers\OA009Ufd.sys (Creative Technology Ltd.)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (RSUSBSTOR) – C:\WINDOWS\system32\drivers\RTS5121.sys (Realtek Semiconductor Corp.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (AESTAud) – C:\WINDOWS\system32\drivers\AESTAud.sys (Andrea Electronics Corporation)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (dsNcAdpt) – C:\WINDOWS\system32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (OA009Afx) – C:\WINDOWS\system32\drivers\OA009Afx.sys (Creative Technology Ltd.)
DRV - (vmkbd) – C:\WINDOWS\system32\drivers\VMkbd.sys (VMware, Inc.)
DRV - (hcmon) – C:\WINDOWS\system32\drivers\hcmon.sys (VMware, Inc.)
DRV - (VMnetuserif) – C:\WINDOWS\system32\drivers\vmnetuserif.sys (VMware, Inc.)
DRV - (vmx86) – C:\WINDOWS\system32\drivers\vmx86.sys (VMware, Inc.)
DRV - (vmusb) – C:\WINDOWS\system32\drivers\vmusb.sys (VMware, Inc.)
DRV - (VMnetBridge) – C:\WINDOWS\system32\drivers\vmnetbridge.sys (VMware, Inc.)
DRV - (VMnetAdapter) – C:\WINDOWS\system32\drivers\vmnetadapter.sys (VMware, Inc.)
DRV - (vstor2-ws60) – C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys (VMware, Inc.)
DRV - (vstor2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys (VMware, Inc.)
DRV - (vmm) – C:\WINDOWS\system32\drivers\VMM.sys (Microsoft Corporation)
DRV - (VPCNetS2) – C:\WINDOWS\system32\drivers\VMNetSrv.sys (Microsoft Corporation)
DRV - (VirtualFD) – C:\vfd21-080206\vfd.sys (Ken Kato)
DRV - (USB_RNDIS) – C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://www.google.com/accounts/ServiceLogin?service=mail&passive;=true&rm;=false&continue;=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fhl%3Den%26tab%3Dwm%26ui%3Dhtml%26zy%3Dl&bsv;=llya694le36z&scc;=1
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: [removed]:11.0.1.400
FF - prefs.js..extensions.enabledItems: [removed]:11.0.1.400
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: 0
FF - prefs.js..network.proxy.backup.gopher: ""
FF - prefs.js..network.proxy.backup.gopher_port: 0
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: 0
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: 0
FF - prefs.js..network.proxy.ftp: "192.168.5.253"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "192.168.5.253"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "192.168.5.253"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "192.168.5.253"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "192.168.5.253"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/23 23:30:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/23 23:30:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\THBExt [2011/04/17 19:46:19 | 000,000,000 | —D | M]

[2010/06/12 09:49:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\dell\Application Data\Mozilla\Extensions
[2011/07/20 21:48:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\dell\Application Data\Mozilla\Firefox\Profiles\kaa1iaow.default\extensions
[2010/08/29 10:33:31 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\dell\Application Data\Mozilla\Firefox\Profiles\kaa1iaow.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/07/18 22:02:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/17 19:47:39 | 000,000,000 | —D | M] (Anti-Banner) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/04/17 19:47:37 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files\Mozilla Firefox\extensions\[removed]

O1 HOSTS File: ([2011/03/05 22:05:06 | 000,000,779 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.Brenz.pl
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 173.192.170.88 drghwaweg45j4i6u3q32fg2h.com
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\APOINT.EXE (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\QUICKSET.EXE ()
O4 - HKLM..\Run: [DSLAGENTEXE] C:\Program Files\Huawei\MT841\DSLAGENT.EXE ()
O4 - HKLM..\Run: [hornnsqa] File not found
O4 - HKLM..\Run: [il56nse] File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\ORDERREMINDER.EXE (Hewlett-Packard)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\STTRAY.EXE (IDT, Inc.)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files\VMware\VMware Workstation\hqtray.exe (VMware, Inc.)
O4 - HKLM..\Run: [vmware-tray] C:\Program Files\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [EXPLORER.EXE] C:\WINDOWS\EXPLORER.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\dell\Start Menu\Programs\Startup\wpyfthlk.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: fa8gd = C:\DOCUME~1\dell\LOCALS~1\Temp\d2u5q5h.exe
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 24syw = C:\DOCUME~1\dell\LOCALS~1\Temp\r1tsjvy.exe
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: apps = C:\WINDOWS\fonts\services.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B}
https://sslvpn.persistent.co.in/dana-cached…perSetupSP1.cab (JuniperSetupSP1 Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\mzvkbd3.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\EXPLORER.EXE (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/27 00:38:36 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{509fe4e2-68aa-11e0-b1aa-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{509fe4e2-68aa-11e0-b1aa-005056c00008}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{509fe4e2-68aa-11e0-b1aa-005056c00008}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL GuEgae.EXe
O33 - MountPoints2\{7d6303d3-390b-11df-af4c-a718f802d2da}\Shell - "" = Autorun
O33 - MountPoints2\{7d6303d3-390b-11df-af4c-a718f802d2da}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{7d6303d3-390b-11df-af4c-a718f802d2da}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL system3_.exe
O33 - MountPoints2\{7d6303d3-390b-11df-af4c-a718f802d2da}\Shell\Open\command - "" = system3_.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (nprootkt.exe) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/19 16:26:56 | 000,000,000 | —D | C] – C:\ubuntu
[2011/07/19 15:25:38 | 000,000,000 | —D | C] – C:\Documents and Settings\dell\Desktop\ubuntu 10.4
[2011/07/19 15:20:57 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Documents and Settings\dell\Desktop\OTL.exe
[2011/07/16 20:42:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PowerISO
[2011/07/15 14:31:41 | 000,000,000 | —D | C] – C:\Program Files\PowerISO
[2011/07/15 14:29:45 | 000,000,000 | —D | C] – C:\Ubuntu 10.10
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/20 21:41:00 | 000,400,128 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/20 21:41:00 | 000,061,768 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/20 21:35:07 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/20 21:35:03 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/19 16:32:08 | 000,088,813 | —- | M] () – C:\wubildr
[2011/07/19 16:32:08 | 000,008,192 | —- | M] () – C:\wubildr.mbr
[2011/07/19 16:32:08 | 000,000,238 | RHS- | M] () – C:\boot.ini
[2011/07/19 16:25:43 | 000,000,000 | RHS- | M] () – C:\CONFIG.SYS
[2011/07/19 15:46:33 | 000,000,743 | —- | M] () – C:\Documents and Settings\dell\Desktop\fixme.reg
[2011/07/19 15:21:08 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Documents and Settings\dell\Desktop\OTL.exe
[2011/07/19 15:07:07 | 091,551,771 | —- | M] () – C:\Documents and Settings\dell\Desktop\ubuntu-11.04-desktop-i386.iso.part
[2011/07/17 14:08:44 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/07/17 12:01:05 | 000,000,000 | —- | M] () – C:\Documents and Settings\dell\Desktop\ubuntu-11.04-desktop-i386.iso
[2011/07/16 20:42:20 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2011/07/15 16:05:34 | 000,762,864 | —- | M] () – C:\Documents and Settings\dell\Desktop\flask-docs.pdf
[2011/07/13 20:10:32 | 000,612,789 | —- | M] () – C:\Documents and Settings\dell\Desktop\Learn Python The Hard Way.pdf
[2011/07/13 05:31:02 | 001,878,829 | —- | M] () – C:\PowerISO48.exe
[2011/07/08 20:05:41 | 000,570,937 | —- | M] () – C:\Documents and Settings\dell\Desktop\be col timetable.jpg
[2011/07/07 11:13:15 | 000,073,934 | —- | M] () – C:\Documents and Settings\dell\Desktop\MTech-Phd.pdf
[2011/07/03 17:57:50 | 000,067,053 | —- | M] () – C:\Documents and Settings\dell\Desktop\Form16.pdf
[2011/07/02 13:44:13 | 000,000,111 | —- | M] () – C:\Documents and Settings\dell\default.pls
[2011/07/01 18:52:25 | 000,159,648 | —- | M] () – C:\Documents and Settings\dell\Desktop\COMP2K924.pdf
[2011/06/26 10:39:44 | 000,036,864 | —- | M] () – C:\Documents and Settings\dell\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/19 16:32:08 | 000,088,813 | —- | C] () – C:\wubildr
[2011/07/19 16:32:08 | 000,008,192 | —- | C] () – C:\wubildr.mbr
[2011/07/19 15:46:33 | 000,000,743 | —- | C] () – C:\Documents and Settings\dell\Desktop\fixme.reg
[2011/07/19 10:16:55 | 000,762,864 | —- | C] () – C:\Documents and Settings\dell\Desktop\flask-docs.pdf
[2011/07/17 12:01:05 | 000,000,000 | —- | C] () – C:\Documents and Settings\dell\Desktop\ubuntu-11.04-desktop-i386.iso
[2011/07/17 12:00:51 | 091,551,771 | —- | C] () – C:\Documents and Settings\dell\Desktop\ubuntu-11.04-desktop-i386.iso.part
[2011/07/15 14:31:44 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2011/07/15 14:31:03 | 001,878,829 | —- | C] () – C:\PowerISO48.exe
[2011/07/13 20:10:16 | 000,612,789 | —- | C] () – C:\Documents and Settings\dell\Desktop\Learn Python The Hard Way.pdf
[2011/07/08 20:05:40 | 000,570,937 | —- | C] () – C:\Documents and Settings\dell\Desktop\be col timetable.jpg
[2011/07/07 11:13:15 | 000,073,934 | —- | C] () – C:\Documents and Settings\dell\Desktop\MTech-Phd.pdf
[2011/07/03 17:57:48 | 000,067,053 | —- | C] () – C:\Documents and Settings\dell\Desktop\Form16.pdf
[2011/07/01 18:52:25 | 000,159,648 | —- | C] () – C:\Documents and Settings\dell\Desktop\COMP2K924.pdf
[2011/06/20 09:14:43 | 000,180,624 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2011/04/17 19:47:27 | 000,115,369 | —- | C] () – C:\WINDOWS\System32\drivers\klin.dat
[2011/04/17 19:47:27 | 000,097,859 | —- | C] () – C:\WINDOWS\System32\drivers\klick.dat
[2011/03/05 22:07:01 | 000,000,268 | —- | C] () – C:\WINDOWS\drtuahehjh.ini
[2011/03/05 22:05:37 | 000,000,166 | —- | C] () – C:\WINDOWS\il56nse.ini
[2011/03/05 21:59:59 | 000,078,592 | —- | C] () – C:\WINDOWS\System32\drivers\zmdpseuk1.sys
[2011/03/05 21:59:31 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\NpLogOn.Dll11478
[2011/02/10 09:33:48 | 000,000,314 | —- | C] () – C:\WINDOWS\primopdf.ini
[2010/12/23 17:58:05 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/10/18 00:02:10 | 000,000,000 | —- | C] () – C:\WINDOWS\procui.INI
[2010/07/27 22:00:53 | 000,000,288 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/07/27 21:53:55 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2010/06/12 09:49:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/05/01 19:49:53 | 000,000,192 | —- | C] () – C:\WINDOWS\System32\EDIT.INI
[2010/04/02 20:24:26 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\vshp1020.dll
[2010/04/02 20:24:25 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\zshp1020.exe
[2010/03/30 20:24:25 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\GsiNdi32.dll
[2010/03/30 20:24:22 | 000,017,674 | —- | C] () – C:\WINDOWS\wwdslcfg.ini
[2010/03/30 20:24:19 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\GsiDi32.dll
[2010/03/27 12:56:36 | 000,000,141 | —- | C] () – C:\Documents and Settings\All Users\Application Data\license.ini
[2010/03/27 12:42:52 | 000,000,010 | —- | C] () – C:\WINDOWS\cbid32.dll
[2010/03/27 05:59:25 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/03/27 05:58:18 | 000,270,192 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/27 04:21:01 | 000,100,368 | —- | C] () – C:\WINDOWS\System32\drivers\VBoxDrv.sys
[2010/03/27 01:08:49 | 000,036,864 | —- | C] () – C:\Documents and Settings\dell\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/27 01:04:51 | 000,126,464 | —- | C] () – C:\WINDOWS\System32\ZvExeScn.Dll15724
[2010/03/27 00:46:53 | 002,026,604 | —- | C] () – C:\WINDOWS\System32\igkrng500.bin
[2010/03/27 00:46:52 | 000,442,964 | —- | C] () – C:\WINDOWS\System32\igcompkrng500.bin
[2010/03/27 00:46:52 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4990.dll
[2010/03/27 00:45:43 | 002,318,336 | —- | C] () – C:\WINDOWS\System32\WLTRAY.EXE_
[2010/03/27 00:45:43 | 002,318,336 | —- | C] () – C:\WINDOWS\System32\WLTRAY.EXE
[2010/03/27 00:45:43 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2010/03/27 00:45:42 | 000,753,664 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2010/03/27 00:45:42 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\WLTRYSVC.EXE_
[2010/03/27 00:45:42 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\WLTRYSVC.EXE
[2010/03/27 00:40:43 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/03/27 00:35:50 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/09/09 19:01:40 | 000,027,675 | —- | C] () – C:\WINDOWS\System32\drivers\klopp.dat
[2008/08/15 08:46:30 | 002,854,912 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2006/11/20 14:05:38 | 000,000,833 | —- | C] () – C:\WINDOWS\EParse.ini
[2006/10/05 11:43:02 | 000,020,227 | —- | C] () – C:\WINDOWS\System32\Fixdll.exe
[2006/04/10 19:15:10 | 000,043,064 | —- | C] () – C:\WINDOWS\Regrest.exe
[2005/12/30 17:12:10 | 000,000,167 | —- | C] () – C:\WINDOWS\ZVIgnore.dat
[2004/08/11 01:45:04 | 000,066,560 | —- | C] () – C:\WINDOWS\System32\WDFMGR.EXE_
[2004/08/11 01:45:04 | 000,066,560 | —- | C] () – C:\WINDOWS\System32\WDFMGR.EXE
[2004/08/04 04:37:22 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 04:26:44 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\ieencode.dll
[2004/08/02 17:50:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/07/17 15:06:38 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2001/11/14 13:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/08/31 10:49:44 | 000,000,218 | —- | C] () – C:\WINDOWS\oraodbc.ini
[2001/08/23 16:30:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 16:30:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 16:30:00 | 000,400,128 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 16:30:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 16:30:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 16:30:00 | 000,061,768 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 16:30:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 16:30:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 16:30:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 16:30:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[1998/12/06 16:56:04 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\verinst.exe

========== LOP Check ==========

[2010/12/19 13:01:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/02/18 12:39:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe

========== Purity Check ==========



< End of report >





Extras.txt

OTL Extras logfile created on: 20/07/2011 9:52:38 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\dell\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd/MM/yyyy

2.96 Gb Total Physical Memory | 2.20 Gb Available Physical Memory | 74.44% Memory free
4.80 Gb Paging File | 4.14 Gb Available in Paging File | 86.38% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 13.08 Gb Free Space | 26.79% Space Free | Partition Type: NTFS
Drive D: | 49.81 Gb Total Space | 22.14 Gb Free Space | 44.45% Space Free | Partition Type: NTFS
Drive E: | 99.73 Gb Total Space | 95.05 Gb Free Space | 95.31% Space Free | Partition Type: NTFS
Drive F: | 99.71 Gb Total Space | 99.42 Gb Free Space | 99.71% Space Free | Partition Type: NTFS

Computer Name: I-127080E3EB544 | User Name: dell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] – C:\Program Files\Opera\opera.exe (Opera Software)
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
jsfile – "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" %*
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [ZERO-V] – C:\PROGRA~1\NETPRO~2\zvscan\Runscan.exe %1
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UacDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"2417:TCP" = 2417:TCP:*:Enabled:gbbakly
"1198:TCP" = 1198:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\Huawei\MT841\dslagent.exe" = C:\Program Files\Huawei\MT841\dslagent.exe:*:Enabled:dslagent – ()
"E:\oracle\ora90\BIN\xsaagent.exe" = E:\oracle\ora90\BIN\xsaagent.exe:*:Disabled:xsaagent – ()
"E:\oracle\ora90\Apache\Apache\Apache.exe" = E:\oracle\ora90\Apache\Apache\Apache.exe:*:Disabled:Apache – ()
"C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe" = C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home – (Nero AG)
"E:\xampp\mysql\bin\mysqld.exe" = E:\xampp\mysql\bin\mysqld.exe:*:Disabled:mysqld
"E:\xampp\MercuryMail\mercury.exe" = E:\xampp\MercuryMail\mercury.exe:*:Disabled:Mercury/32 Core Processing Module v4.62
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Firefox – (Mozilla Corporation)
"C:\WINDOWS\fonts\services.exe" = C:\WINDOWS\fonts\services.exe:*:Enabled:services.exe


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{177E1CA1-14CC-4398-AB15-A5746EFE8F22}" = Adobe Flash Builder 4
"{20B3FD5B-A987-406B-A5B5-CDE3CA1EF4E1}" = Adobe Flash Player 10 ActiveX
"{23E5C72C-CC08-4EE0-9CC2-D925B232B331}" = Microsoft MSDN 2005 Express Edition - ENU
"{2687340C-C114-47DC-9F0E-C1BA85FEB001}" = POWERPREP II
"{32A3A4F4-B792-11D6-A78A-00B0D0160000}" = Java™ SE Development Kit 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{59B60A02-7A8B-47EF-850F-D8645B62C4B1}" = Sun xVM VirtualBox
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{656C0E21-331E-11DF-81CE-005056806466}" = Google Earth
"{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73F1BDB7-11E1-11D5-9DC6-00C04F2FC33B}" = Wordflash
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A7CAA24-7B23-410B-A7C3-F994B0944160}" = Microsoft Virtual PC 2007
"{8D49D55D-9837-4E0E-AE3B-05C7BEC5CD1F}" = Opera 10.51
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}" = VMware Workstation
"{AB6F4AB9-AC85-4002-9829-B6EEA55AE3A5}" = Microsoft Visual C++ 2005 Express Edition - ENU
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C79312BD-3E76-4474-A10C-1435D1856A4B}" = Adobe Dreamweaver CS5
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{D10CB652-9332-4242-B7A9-2D61570144F7}" = Realtek Card Reader
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D9B4D7EE-481C-4C36-86AB-A8F7417725FF}" = LightScribe 1.6.43.1
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{F61DD673-0030-4BB2-A382-7E57E97F1033}" = Nero 7 Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Akamai" = Akamai NetSession Interface
"Blender" = Blender (remove only)
"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Creative OA009" = Integrated Webcam Driver (1.01.01.1007)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP-LaserJet 1020 series" = LaserJet 1020 series
"Huawei MT841" = Huawei MT841
"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"Juniper Network Connect 5.5.0" = Juniper Networks Network Connect 5.5.0
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft MSDN 2005 Express Edition - ENU" = Microsoft MSDN 2005 Express Edition - ENU
"Microsoft Visual C++ 2005 Express Edition - ENU" = Microsoft Visual C++ 2005 Express Edition - ENU
"Mozilla Firefox (3.6.18)" = Mozilla Firefox (3.6.18)
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"nbi-glassfish-mod-[removed].0" = GlassFish Server Open Source Edition 3.0.1
"nbi-nb-base-[removed].0" = NetBeans IDE 6.9.1
"OrderReminder HP LaserJet 1020" = OrderReminder HP LaserJet 1020
"Picasa 3" = Picasa 3
"PowerISO" = PowerISO
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"Visual Studio 6.0 Enterprise Edition" = Microsoft Visual Studio 6.0 Enterprise Edition
"VLC media player" = VLC media player 1.0.1
"WampServer 2_is1" = WampServer 2.0
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WebPost" = Microsoft Web Publishing Wizard 1.53
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinRAR archiver" = WinRAR archiver
"Wubi" = Ubuntu

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 06/07/2011 1:49:56 PM | Computer Name = I-127080E3EB544 | Source = EventSystem | ID = 4610
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80040154 from line 44 of d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp.
This may indicate that the COM+ Event System is not properly installed. Please
try reinstalling the COM+ Event Syste

Error - 06/07/2011 1:49:56 PM | Computer Name = I-127080E3EB544 | Source = EventSystem | ID = 4610
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80040154 from line 44 of d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp.
This may indicate that the COM+ Event System is not properly installed. Please
try reinstalling the COM+ Event Syste

Error - 08/07/2011 12:43:26 PM | Computer Name = I-127080E3EB544 | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/07/2011 12:52:50 PM | Computer Name = I-127080E3EB544 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 15/07/2011 10:40:46 AM | Computer Name = I-127080E3EB544 | Source = EventSystem | ID = 4610
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80040154 from line 44 of d:\qxp_slp\com\com1x\src\events\tier1\eventsystemobj.cpp.
This may indicate that the COM+ Event System is not properly installed. Please
try reinstalling the COM+ Event Syste

Error - 16/07/2011 11:06:13 AM | Computer Name = I-127080E3EB544 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 16/07/2011 11:06:13 AM | Computer Name = I-127080E3EB544 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 16/07/2011 11:06:13 AM | Computer Name = I-127080E3EB544 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 19/07/2011 6:10:43 AM | Computer Name = I-127080E3EB544 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.26.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 19/07/2011 2:38:08 PM | Computer Name = I-127080E3EB544 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.26.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 20/07/2011 12:05:09 PM | Computer Name = I-127080E3EB544 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\WINDOWS\system32\WLTRAY.exe.
Reference
error message: The operation completed successfully. .

Error - 20/07/2011 12:05:10 PM | Computer Name = I-127080E3EB544 | Source = SideBySide | ID = 16842810
Description = Syntax error in manifest or policy file "C:\Program Files\Dell\QuickSet\quickset.exe"
on line 0.

Error - 20/07/2011 12:05:10 PM | Computer Name = I-127080E3EB544 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Dell\QuickSet\quickset.exe.
Reference
error message: The operation completed successfully. .

Error - 20/07/2011 12:06:11 PM | Computer Name = I-127080E3EB544 | Source = Service Control Manager | ID = 7000
Description = The Bluetooth LAN Access Server service failed to start due to the
following error: %%1058

Error - 20/07/2011 12:06:11 PM | Computer Name = I-127080E3EB544 | Source = Service Control Manager | ID = 7000
Description = The Microsoft TV/Video Connection service failed to start due to the
following error: %%1058

Error - 20/07/2011 12:06:11 PM | Computer Name = I-127080E3EB544 | Source = Service Control Manager | ID = 7000
Description = The NPAV Application Control service failed to start due to the following
error: %%3

Error - 20/07/2011 12:06:11 PM | Computer Name = I-127080E3EB544 | Source = Service Control Manager | ID = 7023
Description = The zbebyh service terminated with the following error: %%126

Error - 20/07/2011 12:06:11 PM | Computer Name = I-127080E3EB544 | Source = Service Control Manager | ID = 7000
Description = The SFilter service failed to start due to the following error: %%2

Error - 20/07/2011 12:06:11 PM | Computer Name = I-127080E3EB544 | Source = Service Control Manager | ID = 7000
Description = The XAMPP Service service failed to start due to the following error:
%%3

Error - 20/07/2011 12:06:11 PM | Computer Name = I-127080E3EB544 | Source = Service Control Manager | ID = 7023
Description = The Manager Shell service terminated with the following error: %%2


< End of report >



should i run the GMER file now?
Yes, please run GMER.

Are you running a web server in your machine?


Please also go to the following site to scan a file: Virus Total

  • Click on Browse, and upload the following files for analysis:

    • C:\WINDOWS\System32\WDFMGR.EXE
      C:\WINDOWS\system32\drivers\zmdpseuk1.sys
      C:\WINDOWS\System32\verinst.exe
  • Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
  • If it says already scanned – click "reanalyze now"
  • Please post the results in your next reply.
Thanks for the logs.

Your machine has several infections onboard, even with a strong security solution like Kaspersky Internet Security. The reason of this is an outdated operative system. May I ask you why do you still have Windows SP2 and not SP3?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI