This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Need help to remove multiple viruses and worms!

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI,

Hope all of you are doing good. I need help on urgent basis, as my system is giving troubles for quite some time and hangs without any apparent reason and sometimes stucks during the startup process.

I have run a few malware removal tools, but have not deleted anything as yet.

————————————————————————————————–
Firstly i used RemoveIT Pro, and following malwares/viruses are reported:

RemoveIT Pro v7 Enterprise (Build date: 11.11.2008) log.
Generated at: 1/17/2009 on 11:56:03 PM
Microsoft Windows XP Professional Service Pack 3 (Build 2600)

11:56:03 PM: Scanning, please wait…
11:56:11 PM: Infected file (Win32.Unknown.Random.X) c:\windows\temp\jm6882.exe -> No action taken.
11:59:04 PM: Infected file (Sys32.kwinhook) c:\windows\system32\kwinhook.dll -> No action taken.
11:59:16 PM: Infected file (Sys32.partizan) C:\WINDOWS\system32\partizan.exe -> No action taken.
11:59:16 PM: Infected file (Sys32.partizan) C:\WINDOWS\system32\drivers\partizan.sys -> No action taken.
12:00:15 AM: Infected file (Sys32.webcheck) C:\WINDOWS\webcheck.exe -> No action taken.
12:00:47 AM: Infected file (Sys32.rpcapd) C:\Program Files\winpcap\rpcapd.exe -> No action taken.
12:00:51 AM: 6 Dangerous files has been found on your computer.
Click on "Fix" button to fix selected tasks.
Finished…
————————————————————————————————–


Then i ran the HijackThis, following is the output:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:23, on 1/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\KACE\KBOX\KBOXManagementService.exe
C:\Program Files\KACE\KBOX\KBOXSMMPService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\TEMP\JM6882.EXE
C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://portal.transitt.telenor.no/index.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://portal.transitt.telenor.no/index.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60341
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60341
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.5.3.44:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = x5chris.telenor.com.pk;crm.telenor.com.pk;pos.telenor.com.pk;shoptool.bss.teleno
r.com.pk;webmail.telenor.com.pk;helpdesk.telenor.com.pk;tpptestdb.bss.telenor.com
.pk;10.1.4.190;10.1.4.183;172.18.26.139;*.bss.telenor.com.pk;partner.telenor.com;
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - (no file)
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [Switcher.exe] "C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe"
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: SysIntegrity.lnk = C:\Program Files\SysIntegrity\SysIntegrity.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://crm.telenor.com.pk
O15 - Trusted Zone: http://cxpress.telenor.com.pk
O15 - Trusted Zone: http://hrsurvey.telenor.com.pk
O15 - Trusted Zone: http://isb-chq-catlyst.telenor.com.pk
O15 - Trusted Zone: http://pos.telenor.com.pk
O15 - Trusted Zone: http://sps.telenor.com.pk
O15 - Trusted Zone: http://tpptestdb.bss.telenor.com.pk
O15 - Trusted Zone: http://*.crm
O15 - Trusted Zone: http://*.pos
O15 - Trusted Zone: http://portal.transitt.telenor.no
O15 - Trusted IP range: 10.1.4.183
O15 - Trusted IP range: http://10.1.4.183
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229190672531
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229190611640
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553550000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = telenor.com.pk
O17 - HKLM\Software\..\Telephony: DomainName = telenor.com.pk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = telenor.com.pk
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: kwinhook - C:\WINDOWS\SYSTEM32\kwinhook.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KBOX Management Service (KBOXManagementService) - KACE Networks, Inc. - C:\Program Files\KACE\KBOX\KBOXManagementService.exe
O23 - Service: KBOX SMMP Management Service (KBOXSMMP) - KACE Networks, Inc. - C:\Program Files\KACE\KBOX\KBOXSMMPService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: OfficeScan NT Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe

–
End of file - 12601 bytes
————————————————————————————————–


Currently i am running a scan with Malwarebytes Anti-Malware, will share the logs if you need them. Please advice how to proceed and get rid of these malicious propgrams, worms, trojans and viruses….. :(

Thanks & Regards
Hello imi_boi

Welcome to the Whatthetech Malware Removal Forum,

All advice given by anyone volunteering here, is taken at your own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.
It is advisable that you back up your personal data before starting any clean up procedure.

Please do not attach any logs or reports, just copy and paste them in. When you run Malwarebytes, make sure you removal all it finds and post the report along with a new Hijackthis log.

Instructions for Malwarebytes

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.
Hi Ken, Thanks for the response. But i have managed to rectify the problems on my own :) and my system seems to be running fine right now. Will surely bug you guys in case i face any issues in future. Really appreciate your response, thanks! Regards//imi_boi
Hi,

Hopefully you go it fixed but there is more to this than just deleting a few files, there could be more. Its up to you but you can run this quick scan and we can find out for sure.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Hi Ken,

Thansk fo concern, i would for sure like to fix everything properly and completely. Here goes the snap of the two logs after running RSIT:

log.txt

Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-01-23 14:21:37
Microsoft Windows XP Professional Service Pack 3
System drive C: has 37 GB (74%) free of 50 GB
Total RAM: 2046 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:21, on 1/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\KACE\KBOX\KBOXManagementService.exe
C:\Program Files\KACE\KBOX\KBOXSMMPService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
C:\WINDOWS\TEMP\CX7034.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\imran.aftab\Desktop\RSIT.exe
C:\Program Files\trend micro\imran.aftab.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://portal.transitt.telenor.no/index.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://portal.transitt.telenor.no/index.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.5.3.44:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = x5chris.telenor.com.pk;crm.telenor.com.pk;pos.telenor.com.pk;shoptool.bss.teleno
r.com.pk;webmail.telenor.com.pk;helpdesk.telenor.com.pk;tpptestdb.bss.telenor.com
.pk;10.1.4.190;10.1.4.183;172.18.26.139;*.bss.telenor.com.pk;partner.telenor.com;
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\KUsrInit.exe,
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - (no file)
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [Switcher.exe] "C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe"
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-658022821-2193089035-1317499546-1003\..\Run: [] (User '?')
O4 - HKUS\S-1-5-21-658022821-2193089035-1317499546-1003\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User '?')
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - S-1-5-21-658022821-2193089035-1317499546-1003 Startup: CCC.lnk = ? (User '?')
O4 - Global Startup: Bluetooth.lnk = ?
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://crm.telenor.com.pk
O15 - Trusted Zone: http://cxpress.telenor.com.pk
O15 - Trusted Zone: http://hrsurvey.telenor.com.pk
O15 - Trusted Zone: http://isb-chq-catlyst.telenor.com.pk
O15 - Trusted Zone: http://pos.telenor.com.pk
O15 - Trusted Zone: http://sps.telenor.com.pk
O15 - Trusted Zone: http://tpptestdb.bss.telenor.com.pk
O15 - Trusted Zone: http://*.crm
O15 - Trusted Zone: http://*.pos
O15 - Trusted Zone: http://portal.transitt.telenor.no
O15 - Trusted IP range: 10.1.4.183
O15 - Trusted IP range: http://10.1.4.183
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229190672531
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229190611640
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553550000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = telenor.com.pk
O17 - HKLM\Software\..\Telephony: DomainName = telenor.com.pk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = telenor.com.pk
O20 - Winlogon Notify: kwinhook - C:\WINDOWS\SYSTEM32\kwinhook.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KBOX Management Service (KBOXManagementService) - KACE Networks, Inc. - C:\Program Files\KACE\KBOX\KBOXManagementService.exe
O23 - Service: KBOX SMMP Management Service (KBOXSMMP) - KACE Networks, Inc. - C:\Program Files\KACE\KBOX\KBOXSMMPService.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: OfficeScan NT Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe

–
End of file - 11518 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-02-22 401968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [2008-02-20 53248]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-02-20 69632]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-02-20 774233]
"SonyPowerCfg"=C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2007-03-26 217088]
"Switcher.exe"=C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe [2007-08-31 503808]
"VAIOCameraUtility"=C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe [2007-02-07 411768]
"PSQLLauncher"=C:\Program Files\Protector Suite QL\launcher.exe [2007-01-05 49168]
"OfficeScanNT Monitor"=C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe [2009-01-12 718120]
"NSLauncher"=C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe [2006-11-28 2658304]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-16 136600]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"COMMUNICATOR"=C:\Program Files\Microsoft Office Communicator\Communicator.exe [2005-05-12 4167376]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2008-12-03 1205760]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2003-12-18 4677632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bionix Wallpaper 5]
C:\BioniX Wallpaper\Bionix Wallpaper 5.exe [2008-12-26 712192]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegRun WinBait]
C:\WINDOWS\winbait.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Regrun2]
C:\PROGRA~1\Greatis\REGRUN~1\WatchDog.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2009]
C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-02-20 110592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kwinhook]
C:\WINDOWS\system32\kwinhook.dll [2007-10-31 6144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psfus]
C:\WINDOWS\system32\psqlpwd.dll [2007-01-05 90112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon]
C:\WINDOWS\system32\VESWinlogon.dll [2007-05-16 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC}
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{F552DDE6-2090-4bf4-B924-6141E87789A5}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
psqlpwd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"HideLegacyLogonScripts"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableTaskMgr"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"ForceStartMenuLogOff"=1
"ForceClassicControlPanel"=1
"NoSimpleStartMenu"=1
"NoStartMenuMyMusic"=1
"NoSMMyPictures"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe"="C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe:*:Enabled:MSN"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office Communicator\communicator.exe"="C:\Program Files\Microsoft Office Communicator\communicator.exe:*:Enabled:Communicator"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Windows Live\Messenger\msnmsgr1.exe.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr1.exe.exe:*:Enabled:Windows Live Messenger"
"C:\WINDOWS\system32\nvsvc32.exe"="C:\WINDOWS\system32\nvsvc32.exe:*:Enabled:NVIDIA Driver Helper Service, Version 93.71"
"C:\WINDOWS\system32\jview.exe"="C:\WINDOWS\system32\jview.exe:*:Enabled:Microsoft® VM Command Line Interpreter"
"C:\Documents and Settings\imran.aftab\Desktop\HW-RouteSim\HW-RouteSim.exe"="C:\Documents and Settings\imran.aftab\Desktop\HW-RouteSim\HW-RouteSim.exe:*:Enabled:HW-RouteSim"

======File associations======

.ini - open - notepad.exe %1
.scr - config - "%1" %*
.txt - open - notepad.exe %1

======List of files/folders created in the last 1 months======

2009-01-23 14:21:37 —-D—- C:\rsit
2009-01-23 11:53:21 —-D—- C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.1.0207
2009-01-23 11:53:18 —-D—- C:\Program Files\MSN Messenger
2009-01-23 11:52:51 —-D—- C:\WINDOWS\LastGood
2009-01-23 11:51:57 —-D—- C:\Program Files\Windows Live
2009-01-21 21:47:51 —-A—- C:\WINDOWS\rootkitno.ini
2009-01-21 21:47:39 —-D—- C:\RootkitNO
2009-01-21 21:24:56 —-D—- C:\Documents and Settings\imran.aftab\Application Data\Help
2009-01-21 21:22:46 —-D—- C:\Program Files\Greatis
2009-01-21 12:49:53 —-D—- C:\WINDOWS\Sev7nInspirat
2009-01-21 12:49:48 —-A—- C:\WINDOWS\Uninstall.exe
2009-01-21 11:55:06 —-A—- C:\WINDOWS\_MSRSTRT.EXE
2009-01-18 15:33:03 —-D—- C:\Documents and Settings\imran.aftab\Application Data\Uniblue
2009-01-18 14:44:40 —-D—- C:\WINDOWS\pss
2009-01-18 00:48:20 —-A—- C:\WINDOWS\system32\ntkrnlpa.exe.zottel
2009-01-18 00:48:18 —-A—- C:\WINDOWS\system32\ntoskrnl.exe.zottel
2009-01-18 00:34:16 —-D—- C:\BioniX Wallpaper
2009-01-17 23:38:47 —-D—- C:\Documents and Settings\imran.aftab\Application Data\Malwarebytes
2009-01-17 23:38:42 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-17 20:53:16 —-RASHOT—- C:\WINDOWS\winstart.bat
2009-01-17 20:48:16 —-D—- C:\Documents and Settings\imran.aftab\Application Data\System
2009-01-17 20:48:13 —-D—- C:\Documents and Settings\imran.aftab\Application Data\Sagyn Solutions
2009-01-17 20:48:00 —-D—- C:\Program Files\SysIntegrity
2009-01-17 17:07:17 —-D—- C:\Program Files\Anti Trojan Elite
2009-01-17 16:59:09 —-A—- C:\ipconfig.txt
2009-01-16 20:18:12 —-D—- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2009-01-16 20:01:52 —-D—- C:\Program Files\AVG
2009-01-16 20:01:52 —-D—- C:\Documents and Settings\All Users\Application Data\avg8
2009-01-16 16:45:42 —-A—- C:\WINDOWS\system32\deploytk.dll
2009-01-16 15:09:20 —-D—- C:\Documents and Settings\imran.aftab\Application Data\GetRight
2009-01-16 12:25:47 —-D—- C:\Documents and Settings\imran.aftab\Application Data\Digsby
2009-01-16 12:13:58 —-HD—- C:\WINDOWS\PIF
2009-01-16 11:44:43 —-A—- C:\WINDOWS\VPC32.INI
2009-01-16 10:54:36 —-A—- C:\WINDOWS\system32\capicom.dll
2009-01-16 10:54:17 —-D—- C:\Program Files\Symantec AntiVirus
2009-01-16 10:54:17 —-D—- C:\Program Files\Common Files\Symantec Shared
2009-01-16 10:54:17 —-D—- C:\Documents and Settings\All Users\Application Data\Symantec
2009-01-16 09:34:50 —-D—- C:\Program Files\ThreatFire
2009-01-16 09:34:29 —-D—- C:\Documents and Settings\imran.aftab\Application Data\TrojanHunter
2009-01-16 09:32:25 —-R—- C:\WINDOWS\system32\streamhlp.dll
2009-01-16 09:32:25 —-D—- C:\Program Files\TrojanHunter 5.0
2009-01-15 22:57:17 —-D—- C:\Documents and Settings\imran.aftab\Application Data\Spyware Terminator
2009-01-15 22:47:20 —-D—- C:\Documents and Settings\imran.aftab\Application Data\Yahoo!
2009-01-15 22:47:13 —-D—- C:\Program Files\Yahoo!
2009-01-15 22:47:10 —-D—- C:\Documents and Settings\imran.aftab\Application Data\IObit
2009-01-15 22:21:13 —-D—- C:\Documents and Settings\All Users\Application Data\587507495
2009-01-15 19:39:57 —-D—- C:\WINDOWS\Minidump
2009-01-15 17:43:04 —-D—- C:\Documents and Settings\imran.aftab\Application Data\wsInspector
2009-01-15 17:38:21 —-D—- C:\Program Files\Startup Inspector for Windows
2009-01-15 17:32:36 —-A—- C:\ndcnlcdr.exe
2009-01-15 03:02:14 —-HDC—- C:\WINDOWS\$NtUninstallKB958687$
2009-01-15 03:02:07 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2009-01-14 21:16:29 —-D—- C:\Program Files\Utherverse Digital Inc
2009-01-14 12:47:30 —-A—- C:\WINDOWS\system32\hwwcdmaui.ini
2009-01-14 12:47:21 —-D—- C:\HWLMT
2009-01-14 10:13:24 —-D—- C:\Program Files\GTEC
2009-01-13 23:52:28 —-D—- C:\Program Files\PC Connectivity Solution
2009-01-13 23:03:18 —-A—- C:\WINDOWS\webcheck.exe
2009-01-09 09:54:39 —-SHD—- C:\Config.Msi
2009-01-09 09:46:30 —-A—- C:\WINDOWS\system32\mucltui.dll.mui
2009-01-09 09:46:30 —-A—- C:\WINDOWS\system32\mucltui.dll
2009-01-03 22:02:58 —-D—- C:\Documents and Settings\imran.aftab\Application Data\Windows Search
2009-01-03 21:50:34 —-HDC—- C:\WINDOWS\$NtUninstallKB943729$
2009-01-03 21:50:18 —-D—- C:\Documents and Settings\imran.aftab\Application Data\Windows Desktop Search
2009-01-03 21:49:57 —-D—- C:\Program Files\Windows Desktop Search
2009-01-03 21:49:56 —-HD—- C:\WINDOWS\system32\GroupPolicy
2009-01-03 21:49:31 —-HDC—- C:\WINDOWS\$NtUninstallKB915800-v4$
2009-01-03 20:30:05 —-A—- C:\WINDOWS\Winchat.ini
2009-01-03 20:29:48 —-A—- C:\WINDOWS\admintxt.txt
2009-01-03 20:20:22 —-A—- C:\WINDOWS\msnfix.txt
2009-01-03 19:50:36 —-D—- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-12-29 16:57:12 —-HDC—- C:\WINDOWS\$NtUninstallWudf01005$
2008-12-28 01:49:21 —-D—- C:\Documents and Settings\imran.aftab\Application Data\dvdcss

======List of files/folders modified in the last 1 months======

2009-01-23 14:21:56 —-D—- C:\Program Files\Trend Micro
2009-01-23 14:21:46 —-D—- C:\WINDOWS\Prefetch
2009-01-23 13:58:14 —-D—- C:\WINDOWS\Temp
2009-01-23 13:58:12 —-D—- C:\WINDOWS
2009-01-23 11:53:21 —-SHD—- C:\WINDOWS\Installer
2009-01-23 11:53:21 —-D—- C:\WINDOWS\WinSxS
2009-01-23 11:53:18 —-RD—- C:\Program Files
2009-01-23 11:53:18 —-D—- C:\WINDOWS\system32
2009-01-23 11:52:57 —-HD—- C:\WINDOWS\inf
2009-01-23 11:52:57 —-D—- C:\Program Files\MSN
2009-01-23 11:52:51 —-D—- C:\WINDOWS\system32\CatRoot2
2009-01-23 11:52:09 —-D—- C:\Program Files\Common Files\Microsoft Shared
2009-01-23 09:20:33 —-D—- C:\WINDOWS\security
2009-01-23 09:02:09 —-A—- C:\WINDOWS\cfgall.ini
2009-01-23 08:56:35 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-01-21 22:19:16 —-D—- C:\WINDOWS\system32\drivers
2009-01-21 22:05:46 —-ASH—- C:\boot.ini
2009-01-21 22:05:46 —-A—- C:\WINDOWS\win.ini
2009-01-21 22:05:46 —-A—- C:\WINDOWS\system.ini
2009-01-21 21:47:44 —-D—- C:\WINDOWS\system32\config
2009-01-21 11:13:13 —-D—- C:\WINDOWS\system32\wbem
2009-01-21 11:13:13 —-D—- C:\WINDOWS\system32\Restore
2009-01-21 11:13:13 —-D—- C:\WINDOWS\system32\oobe
2009-01-21 11:13:13 —-D—- C:\WINDOWS\network diagnostic
2009-01-21 11:13:12 —-D—- C:\WINDOWS\system32\usmt
2009-01-21 11:13:12 —-D—- C:\Program Files\Windows NT
2009-01-21 11:13:11 —-D—- C:\WINDOWS\system32\Setup
2009-01-21 11:13:11 —-D—- C:\WINDOWS\srchasst
2009-01-21 11:13:11 —-D—- C:\WINDOWS\msagent
2009-01-21 11:13:11 —-D—- C:\WINDOWS\ime
2009-01-21 11:13:11 —-D—- C:\Program Files\Common Files\System
2009-01-21 11:13:08 —-D—- C:\WINDOWS\system32\1033
2009-01-21 11:13:07 —-D—- C:\Program Files\Outlook Express
2009-01-21 11:13:07 —-D—- C:\Program Files\NetMeeting
2009-01-21 11:13:06 —-D—- C:\Program Files\Windows Media Player
2009-01-21 11:13:06 —-D—- C:\Program Files\Movie Maker
2009-01-21 11:13:06 —-D—- C:\Program Files\Messenger
2009-01-21 11:13:06 —-D—- C:\Program Files\Internet Explorer
2009-01-21 11:08:15 —-D—- C:\WINDOWS\Media
2009-01-21 11:08:15 —-D—- C:\WINDOWS\Cursors
2009-01-21 11:07:15 —-RSHDC—- C:\WINDOWS\system32\dllcache
2009-01-21 10:24:29 —-A—- C:\WINDOWS\CPTI_SearchHistory.INI
2009-01-21 10:24:08 —-A—- C:\WINDOWS\SW_Win2000X24.DLL
2009-01-19 22:03:02 —-A—- C:\WINDOWS\Uedit32.INI
2009-01-19 16:42:32 —-SHD—- C:\System Volume Information
2009-01-18 21:30:24 —-SD—- C:\WINDOWS\Downloaded Program Files
2009-01-18 14:42:28 —-SHD—- C:\WINDOWS\CSC
2009-01-18 00:49:33 —-RSD—- C:\WINDOWS\Fonts
2009-01-17 22:18:51 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-17 21:45:16 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2009-01-16 16:52:57 —-D—- C:\WINDOWS\system32\en-us
2009-01-16 16:50:10 —-RD—- C:\UDC Output Files
2009-01-16 16:48:50 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-01-16 16:45:30 —-A—- C:\WINDOWS\system32\javaws.exe
2009-01-16 16:45:30 —-A—- C:\WINDOWS\system32\javaw.exe
2009-01-16 16:45:30 —-A—- C:\WINDOWS\system32\java.exe
2009-01-16 16:45:28 —-D—- C:\Program Files\Java
2009-01-16 16:42:09 —-RSD—- C:\WINDOWS\assembly
2009-01-16 15:14:25 —-D—- C:\Downloads
2009-01-16 10:54:17 —-D—- C:\Program Files\Common Files
2009-01-15 19:38:16 —-D—- C:\WINDOWS\SxsCaPendDel
2009-01-15 19:37:48 —-D—- C:\Program Files\OpenOffice.org 3
2009-01-15 13:44:19 —-D—- C:\Program Files\Stardock
2009-01-15 13:44:11 —-D—- C:\Program Files\Common Files\stardock
2009-01-15 09:53:28 —-D—- C:\WINDOWS\system32\DirectX
2009-01-15 03:02:13 —-HD—- C:\WINDOWS\$hf_mig$
2009-01-15 03:02:12 —-A—- C:\WINDOWS\imsins.BAK
2009-01-14 12:47:21 —-HD—- C:\Program Files\InstallShield Installation Information
2009-01-13 23:53:35 —-D—- C:\WINDOWS\system32\ReinstallBackups
2009-01-13 23:53:29 —-DC—- C:\WINDOWS\system32\DRVSTORE
2009-01-13 23:53:07 —-D—- C:\Program Files\Nokia
2009-01-13 23:53:07 —-D—- C:\Program Files\Common Files\Nokia
2009-01-13 23:53:00 —-D—- C:\Program Files\Common Files\PCSuite
2009-01-13 12:28:19 —-SD—- C:\WINDOWS\Tasks
2009-01-12 09:30:04 —-D—- C:\Program Files\XVideoConverter
2009-01-11 23:22:36 —-D—- C:\Documents and Settings\All Users\Application Data\Installations
2009-01-09 17:35:30 —-A—- C:\WINDOWS\system32\mrt.exe
2009-01-09 09:31:18 —-D—- C:\WINDOWS\system32\DRM
2009-01-09 09:31:18 —-D—- C:\WINDOWS\system32\CatRoot
2009-01-07 01:20:58 —-D—- C:\Documents and Settings\imran.aftab\Application Data\Nokia
2009-01-03 21:50:46 —-D—- C:\WINDOWS\ie7updates
2009-01-03 17:39:43 —-A—- C:\WINDOWS\ModemLog_Nokia N95 Bluetooth Modem.txt
2008-12-29 16:56:37 —-D—- C:\Documents and Settings\All Users\Application Data\PC Suite

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 DMICall;Sony DMI Call service; C:\WINDOWS\system32\DRIVERS\DMICall.sys [2000-12-05 3952]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 tmtdi;Trend Micro TDI Driver; C:\WINDOWS\system32\DRIVERS\tmtdi.sys [2009-01-12 76304]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.4.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-05-20 21393]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2008-02-20 12672]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-05-29 12416]
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R2 TmFilter;Trend Micro Filter; \??\C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys []
R2 TmPreFilter;Trend Micro PreFilter; \??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys []
R2 VSApiNt;Trend Micro VSAPI NT; \??\C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys []
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-02-20 1972736]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2008-02-20 539512]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-02-20 37424]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-02-20 879624]
R3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2008-02-20 156392]
R3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys [2008-02-20 55352]
R3 btwmodem;Bluetooth Modem; C:\WINDOWS\system32\DRIVERS\btwmodem.sys [2008-02-20 37280]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-02-20 74688]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2008-02-20 988800]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2008-02-20 209664]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-02-20 4397568]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 NETw4x32;Intel® Wireless WiFi Link Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2007-06-21 2208512]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 R5U870FLx86;R5U870 UVC Lower Filter ; C:\WINDOWS\System32\Drivers\R5U870FLx86.sys [2008-02-20 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ; C:\WINDOWS\System32\Drivers\R5U870FUx86.sys [2008-02-20 43904]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-08-23 5888]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-02-20 96896]
R3 SNC;Sony Notebook Control Device; C:\WINDOWS\system32\DRIVERS\SonyNC.sys [2008-02-20 48896]
R3 SonyImgF;Sony Image Conversion Filter Driver; C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2007-08-09 30976]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-02-20 193088]
R3 ti21sony;ti21sony; C:\WINDOWS\system32\drivers\ti21sony.sys [2008-02-20 808448]
R3 tmcfw;Trend Micro Common Firewall Service; C:\WINDOWS\system32\DRIVERS\TM_CFW.sys [2009-01-12 338448]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 usbvideo;R5U870 (UVC) ; C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2008-02-20 730112]
S1 a1d73681;a1d73681; C:\WINDOWS\System32\drivers\a1d73681.sys []
S1 a6a4f9b7;a6a4f9b7; C:\WINDOWS\System32\drivers\a6a4f9b7.sys []
S1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
S1 TDSSserv.sys;TDSSserv.sys; C:\WINDOWS\system32\drivers\TDSSrvdc.sys []
S3 ATE_PROCMON;ATE_PROCMON; \??\C:\Program Files\Anti Trojan Elite\ATEPMon.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nm;Network Monitor Driver; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 8320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2005-08-03 32512]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RegGuard;RegGuard; \??\C:\WINDOWS\system32\Drivers\regguard.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-02-20 446464]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2007-12-06 264800]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2006-07-19 169632]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-06-01 647168]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-16 152984]
R2 KBOXManagementService;KBOX Management Service; C:\Program Files\KACE\KBOX\KBOXManagementService.exe [2008-08-08 49152]
R2 KBOXSMMP;KBOX SMMP Management Service; C:\Program Files\KACE\KBOX\KBOXSMMPService.exe [2008-08-08 983040]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 ntrtscan;OfficeScanNT RealTime Scan; C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe [2009-01-12 918824]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-06-01 327680]
R2 S24EventMonitor;Intel® PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2007-06-01 987136]
R2 tmlisten;OfficeScan NT Listener; C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe [2009-01-12 988456]
R2 VAIO Event Service;VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [2007-05-16 176128]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-11-11 620544]
R3 TmPfw;OfficeScan NT Firewall; C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe [2008-07-08 488768]
S2 SPBBCSvc;Symantec SPBBCSvc; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2006-04-11 1160848]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2005-08-03 86016]
S3 TmProxy;OfficeScan NT Proxy Service; C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe [2008-07-08 652552]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

—————–EOF—————–


info.txt

info.txt logfile of random's system information tool 1.05 2009-01-23 14:21:58

======Uninstall list======

–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.3–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
ATI - Software Uninstall Utility–>C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
ATI Display Driver–>rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATI Parental Control & Encoder–>MsiExec.exe /I{36CDA33B-909B-4719-97D1-C4B99309BDC7}
Choice Guard–>MsiExec.exe /I{EBD5E7A9-DBB8-4E24-AE3A-CF9390AF1CCB}
Compatibility Pack for the 2007 Office system–>MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Contacts–>MsiExec.exe /I{C6BDA6E5-B391-4CE5-8D86-B53AC96FFE03}
Free PS Convert driver 8.15–>"C:\Program Files\psconvert\unins000.exe"
HDAUDIO SoftV92 Data Fax Modem with SmartCP–>C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFA&SUBSYS;_104D0200\UIU32m.exe -U -ISnSZIRX5.inf
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)–>"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB915800-v4)–>"C:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB954708)–>"C:\WINDOWS\$NtUninstallKB954708$\spuninst\spuninst.exe"
hp OpenView service desk 4.5 client–>MsiExec.exe /I{04308080-34D6-44A7-8505-8496E7CD64F9}
Intel® PROSet/Wireless Software–>C:\WINDOWS\Installer\iProInst.exe
Java 2 Runtime Environment Standard Edition v1.3.1_10–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{68249B6E-B714-11D7-88E8-0050DA21757E}\Setup.exe" -uninst
Java™ 6 Update 11–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
KBOX–>C:\Program Files\KACE\KBOX\kinstaller.exe -uninstall
mCore–>MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
mDriver–>MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5–>"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7–>"C:\WINDOWS\$NtUninstallWdf01007$\spuninst\spuninst.exe"
Microsoft Office Communicator 2005–>MsiExec.exe /X{BE5AD430-9E0C-4243-AB3F-593835869855}
Microsoft Office Converter Pack–>MsiExec.exe /X{6EECB283-E65F-40EF-86D3-D51BF02A8D43}
Microsoft Office Outlook Connector–>MsiExec.exe /I{95120000-011F-0409-0000-0000000FF1CE}
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Project Professional 2003–>MsiExec.exe /I{903B0409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Visio Professional 2003–>MsiExec.exe /I{90510409-6000-11D3-8CFE-0150048383C9}
Microsoft SQL Server 2005 Compact Edition [ENU]–>MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft User-Mode Driver Framework Feature Pack 1.5–>"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
mMHouse–>MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
mPfMgr–>MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
mProSafe–>MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
MSIcon–>C:\PROGRA~1\MSIcon\UNWISE.EXE C:\PROGRA~1\MSIcon\INSTALL.LOG
MSN Messenger 6.1–>MsiExec.exe /I{ABEB838C-A1A7-4C5D-B7E1-8B4314600207}
MSN–>C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSVC80_x86–>MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSVCRT–>MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser–>MsiExec.exe /I{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}
mWlsSafe–>MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
Nokia Connectivity Cable Driver–>MsiExec.exe /X{15AC0C5D-A6FB-4CE2-8CD0-28179EEB5625}
Nokia Flashing Cable Driver–>MsiExec.exe /X{2A0A6470-FD0F-4F45-9B11-85F3167DB943}
Nokia Lifeblog 2.1–>MsiExec.exe /I{EE565795-2776-415A-B31C-EB3A8D7C6FA4}
Nokia MTP driver–>MsiExec.exe /I{0E94871C-623C-464F-A117-B8474BFF84E1}
Nokia PC Suite–>C:\Documents and Settings\All Users\Application Data\Installations\{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}\Nokia_PC_Suite_7_1_18_0_eng.exe
Nokia PC Suite–>MsiExec.exe /I{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}
Nokia Software Launcher–>MsiExec.exe /I{5CCABD37-479D-4304-B1A5-67952C25F8F2}
Nokia Software Updater–>MsiExec.exe /X{0332234E-09D1-4B74-A5F3-73E34BA29F5B}
OpenOffice.org 3.0–>MsiExec.exe /I{F44DA61E-720D-4E79-871F-F6E628B33242}
Outlook Sensitivity Add-in–>MsiExec.exe /I{FAEB109F-1C6C-4BB0-8F9E-8E1DAC9399F7}
PC Connectivity Solution–>MsiExec.exe /I{D848D140-41C3-4A53-86D8-E866A100B4CD}
Realtek High Definition Audio Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Windows Internet Explorer 7 (KB938127-v2)–>"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)–>"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)–>"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)–>"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)–>"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Segoe UI–>MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Setting Utility Series–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59452470-A902-477F-9338-9B88101681BD}\setup.exe" -l0x9 UNINSTALL -removeonly
Sony Utilities DLL–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF3D45BB-2260-4008-88EA-492E7744A9DF}\setup.exe" -l0x9 -removeonly
SonyImgF–>C:\PROGRA~1\SonyImgF\UNWISE.EXE C:\PROGRA~1\SonyImgF\INSTALL.LOG
Synaptics Pointing Device Driver–>rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Trend Micro OfficeScan Client–>"C:\Program Files\Trend Micro\OfficeScan Client\ntrmv.exe"
Update for Windows XP (KB943729)–>"C:\WINDOWS\$NtUninstallKB943729$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
VAIO Camera Capture Utility–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6D2576EC-A0E9-418A-A09A-409933A3B6F4}\setup.exe" -l0x9 -removeonly
VAIO Camera Utility–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1417F599-1DBD-4499-9375-B2813E9F890C}\setup.exe" -l0x9 -removeonly
VAIO Control Center–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC37C108-821D-4EDE-8F40-D5B497586805}\Setup.exe" -l0x9
VAIO Event Service–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}\setup.exe" -l0x9 -removeonly
VAIO Power Management–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E319E96-ED8E-4B01-9775-C521A1869A25}\setup.exe" -l0x9 UNINSTALL -removeonly
VideoLAN VLC media player 0.8.6h–>C:\Program Files\VideoLAN\VLC\uninstall.exe
WIDCOMM Bluetooth Software–>MsiExec.exe /X{84814E6B-2581-46EC-926A-823BD1C670F6}
Windows Driver Package - Nokia Modem (05/22/2008 3.8)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia_blue_6F90B0F4A73A2F780A1010B5D6CB5DDFB098181E\nokia_bluetooth.inf
Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_E68D50F7E25BFE399D47C864C3B52557346242A9\nokbtmdm.inf
Windows Driver Package - Nokia Modem (10/27/2008 3.9)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia_blue_79486EC6AA0D1732FB17E5167077C07ECAE1B870\nokia_bluetooth.inf
Windows Driver Package - Nokia Modem (10/27/2008 7.01.0.1)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_247189AEBF39EB69A7C75429610DFED2F2EDC1B6\nokbtmdm.inf
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
Windows Internet Explorer 7–>"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live Beta (all programs)–>C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Beta (all programs)–>MsiExec.exe /I{5D4A033A-A286-44BE-A0F0-B05FAC25D07F}
Windows Live Call–>MsiExec.exe /I{78AC782A-C708-4B21-A3A0-ECD4A3284588}
Windows Live Sign-in Assistant–>MsiExec.exe /I{8984E374-6C93-427C-A3B9-AD92472FDCA0}
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Rights Management Client Backwards Compatibility SP2–>MsiExec.exe /X{EC905264-BCFE-423B-9C42-C3A106266790}
Windows Rights Management Client with Service Pack 2–>MsiExec.exe /X{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}
WinPcap 3.1–>C:\Program Files\WinPcap\uninstall.exe
WinRAR archiver–>C:\Program Files\WinRAR\uninstall.exe
WinZip–>"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
Wireless Switch Setting Utility–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}\setup.exe" -l0x9 -removeonly

======Security center information======

AV: Trend Micro OfficeScan Antivirus
FW: Trend Micro Personal Firewall

System event log

Computer Name: ISB-VAS-IMRANA
Event Code: 7036
Message: The Network Location Awareness (NLA) service entered the running state.

Record Number: 822
Source Name: Service Control Manager
Time Written: 20090117222238.000000+300
Event Type: information
User:

Computer Name: ISB-VAS-IMRANA
Event Code: 7035
Message: The Network Location Awareness (NLA) service was successfully sent a start control.

Record Number: 821
Source Name: Service Control Manager
Time Written: 20090117222238.000000+300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: ISB-VAS-IMRANA
Event Code: 7035
Message: The Remote Access Connection Manager service was successfully sent a start control.

Record Number: 820
Source Name: Service Control Manager
Time Written: 20090117222238.000000+300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: ISB-VAS-IMRANA
Event Code: 7036
Message: The Telephony service entered the running state.

Record Number: 819
Source Name: Service Control Manager
Time Written: 20090117222238.000000+300
Event Type: information
User:

Computer Name: ISB-VAS-IMRANA
Event Code: 29
Message: The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 14 minutes.
NtpClient has no source of accurate time.

Record Number: 818
Source Name: W32Time
Time Written: 20090117222224.000000+300
Event Type: error
User:

Application event log

Computer Name: ISB-VAS-IMRANA
Event Code: 6
Message:
Record Number: 45934
Source Name: Symantec AntiVirus
Time Written: 20090119154653.000000+300
Event Type: warning
User:

Computer Name: ISB-VAS-IMRANA
Event Code: 6
Message:
Record Number: 45933
Source Name: Symantec AntiVirus
Time Written: 20090119154650.000000+300
Event Type: warning
User:

Computer Name: ISB-VAS-IMRANA
Event Code: 6
Message:
Record Number: 45932
Source Name: Symantec AntiVirus
Time Written: 20090119154643.000000+300
Event Type: warning
User:

Computer Name: ISB-VAS-IMRANA
Event Code: 6
Message:
Record Number: 45931
Source Name: Symantec AntiVirus
Time Written: 20090119154640.000000+300
Event Type: warning
User:

Computer Name: ISB-VAS-IMRANA
Event Code: 6
Message:
Record Number: 45930
Source Name: Symantec AntiVirus
Time Written: 20090119154631.000000+300
Event Type: warning
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\Intel\Wireless\Bin\;C:\Program Files\Hewlett-Packard\OpenView\service desk 4.5\client\bin
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=1706
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"SD_CLIENTHOME"=C:\Program Files\Hewlett-Packard\OpenView\service desk 4.5\client\

—————–EOF—————–


Looking forward to your response, thanks!!!


Best Regards
Hello,

StylerToolbar <–has mixed results, if you don't is it uninstall it.

Look over all the entries in your Trusted Zone…all the 015 entries, if you don't want them there then run this quick
tool.


Internet Explorer is needed to run this program properly.
Download: DelDomains and save it to the desktop.
  • Close all open windows and your browser
  • Right Click DelDomains.inf and select > Install
  • Reboot your computer





Please download ATF Cleaner by Atribune to your desktop.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.





Lets make sure its all gone.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hi Ken, I have done the first three steps: 1 - Couldn't find any tracks of Styler Toolbar (no folder, no entry in Add/Remove Hardware) 2 - The trusted zone items are required 3 - Have run the ATF-Cleaner For the next step i.e. running ComboFix, requires me to quit all Anti Virus programs, but one program Trend Micro Office Scan is installed by Office and it requires a password while quitting, which i dont know :) so looking forward to your guidance in moving forward, if i can run ComboFix with Tren Micro Office Scan running or is there any way to get the password? Thanks!
Hello,

Run Combofix in Safemode.


To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode
Hi Ken,

Thanks for the support, please find below the logs of ComboFix followed by HijackThis log:

ComboFix.txt

ComboFix 09-01-21.04 - Administrator 2009-01-23 23:28:20.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1772 [GMT 5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro OfficeScan Antivirus *On-access scanning enabled* (Updated)
FW: Trend Micro Personal Firewall *enabled*

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\pdfdoc2.dll
c:\windows\admintxt.txt
c:\windows\IE4 Error Log.txt
c:\windows\SW_Win2000X24.DLL
c:\windows\system32\TDSSilft.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys


((((((((((((((((((((((((( Files Created from 2008-12-23 to 2009-01-23 )))))))))))))))))))))))))))))))
.

2009-01-23 14:21 . 2009-01-23 14:21 d——– C:\rsit
2009-01-23 11:53 . 2009-01-23 11:53 d——– c:\program files\MSN Messenger
2009-01-23 11:53 . 2009-01-23 11:53 d——– c:\documents and settings\All Users\Application Data\MSN Messenger 6.1.0207
2009-01-23 11:51 . 2009-01-23 11:52 d——– c:\program files\Windows Live
2009-01-21 21:47 . 2009-01-21 21:47 d——– C:\RootkitNO
2009-01-21 21:47 . 2009-01-21 21:47 123 –a—— c:\windows\rootkitno.ini
2009-01-21 21:29 . 2009-01-21 21:29 29,584 –a—— c:\windows\system32\drivers\regguard.sys
2009-01-21 21:22 . 2009-01-21 21:22 d——– c:\program files\Greatis
2009-01-21 12:49 . 2009-01-21 12:50 d——– c:\windows\Sev7nInspirat
2009-01-21 12:49 . 2009-01-21 12:50 155,496 –a—— c:\windows\Uninstall.exe
2009-01-21 11:55 . 2009-01-21 11:55 2,560 –a—— c:\windows\_MSRSTRT.EXE
2009-01-20 18:19 . 2009-01-20 18:19 20 –a—— C:\KBSERVICE.BOOTUP.RUNNING
2009-01-18 15:33 . 2009-01-18 15:33 d——– c:\documents and settings\imran.aftab\Application Data\Uniblue
2009-01-18 00:48 . 2008-08-14 15:09 2,145,280 –a—— c:\windows\system32\ntoskrnl.exe.zottel
2009-01-18 00:48 . 2008-08-14 14:33 2,023,936 –a—— c:\windows\system32\ntkrnlpa.exe.zottel
2009-01-18 00:34 . 2009-01-18 14:43 d——– C:\BioniX Wallpaper
2009-01-17 23:38 . 2009-01-17 23:38 d——– c:\documents and settings\imran.aftab\Application Data\Malwarebytes
2009-01-17 23:38 . 2009-01-17 23:38 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-17 20:53 . 2009-01-21 21:29 (2) -rahs-ot- c:\windows\winstart.bat
2009-01-17 20:48 . 2009-01-18 13:04 d——– c:\program files\SysIntegrity
2009-01-17 20:48 . 2009-01-17 20:48 d——– c:\documents and settings\imran.aftab\Application Data\System
2009-01-17 20:48 . 2009-01-17 20:48 d——– c:\documents and settings\imran.aftab\Application Data\Sagyn Solutions
2009-01-17 17:07 . 2009-01-17 20:46 d——– c:\program files\Anti Trojan Elite
2009-01-16 20:18 . 2009-01-16 20:18 d——– c:\program files\Microsoft CAPICOM 2.1.0.2
2009-01-16 20:01 . 2009-01-16 20:01 d——– c:\program files\AVG
2009-01-16 20:01 . 2009-01-21 11:35 d——– c:\documents and settings\All Users\Application Data\avg8
2009-01-16 16:46 . 2009-01-16 16:46 d——– c:\documents and settings\Administrator\Application Data\Yahoo!
2009-01-16 16:45 . 2009-01-16 16:45 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-16 16:38 . 2009-01-16 20:06 d——– c:\documents and settings\Administrator\Application Data\GetRight
2009-01-16 16:27 . 2008-12-10 22:52 218,624 –a—— c:\windows\system32\uxtheme.uxtender
2009-01-16 16:27 . 2009-01-18 00:49 218,624 –a–c— c:\windows\system32\dllcache\uxtheme.dll
2009-01-16 15:09 . 2009-01-16 15:32 d——– c:\documents and settings\imran.aftab\Application Data\GetRight
2009-01-16 12:25 . 2009-01-16 14:50 d——– c:\documents and settings\imran.aftab\Application Data\Digsby
2009-01-16 12:13 . 2009-01-16 12:13 d–h—– c:\windows\PIF
2009-01-16 11:44 . 2009-01-16 11:44 0 –a—— c:\windows\VPC32.INI
2009-01-16 10:54 . 2009-01-21 11:11 d——– c:\program files\Symantec AntiVirus
2009-01-16 10:54 . 2009-01-21 11:49 d——– c:\program files\Common Files\Symantec Shared
2009-01-16 10:54 . 2009-01-16 10:54 d——– c:\documents and settings\All Users\Application Data\Symantec
2009-01-16 09:34 . 2009-01-16 16:52 d——– c:\program files\ThreatFire
2009-01-16 09:34 . 2009-01-16 09:34 d——– c:\documents and settings\imran.aftab\Application Data\TrojanHunter
2009-01-16 09:32 . 2009-01-16 10:39 d——– c:\program files\TrojanHunter 5.0
2009-01-15 22:57 . 2009-01-16 10:43 d——– c:\documents and settings\imran.aftab\Application Data\Spyware Terminator
2009-01-15 22:47 . 2009-01-18 15:14 d——– c:\program files\Yahoo!
2009-01-15 22:47 . 2009-01-15 22:47 d——– c:\documents and settings\imran.aftab\Application Data\Yahoo!
2009-01-15 22:47 . 2009-01-15 22:47 d——– c:\documents and settings\imran.aftab\Application Data\IObit
2009-01-15 22:21 . 2009-01-16 09:19 d——– c:\documents and settings\All Users\Application Data\587507495
2009-01-15 17:43 . 2009-01-15 23:06 d——– c:\documents and settings\imran.aftab\Application Data\wsInspector
2009-01-15 17:38 . 2009-01-16 16:46 d——– c:\program files\Startup Inspector for Windows
2009-01-15 17:32 . 2009-01-15 17:32 8,192 –a—— C:\ndcnlcdr.exe
2009-01-15 17:32 . 2009-01-15 19:43 0 –a—— c:\windows\system32\drivers\a6a4f9b7.sys
2009-01-14 21:16 . 2009-01-14 21:16 d——– c:\program files\Utherverse Digital Inc
2009-01-14 12:47 . 2009-01-14 12:47 d——– C:\HWLMT
2009-01-14 12:47 . 2006-02-28 18:55 2,945,099 –a—— c:\windows\system32\MmlCtor.ocx
2009-01-14 12:47 . 2005-04-25 21:07 1,009,336 –a—— c:\windows\system32\MSCHRT20.OCX
2009-01-14 12:47 . 2005-04-25 21:07 438,976 –a—— c:\windows\system32\MSHFLXGD.OCX
2009-01-14 12:47 . 2005-04-25 21:07 103,744 –a—— c:\windows\system32\MSCOMM32.OCX
2009-01-14 12:47 . 2005-04-25 21:07 90,112 –a—— c:\windows\system32\BCGDateTime.ocx
2009-01-14 12:47 . 2009-01-14 12:47 174 –a—— c:\windows\system32\hwwcdmaui.ini
2009-01-14 10:13 . 2009-01-14 10:13 d——– c:\program files\GTEC
2009-01-13 23:52 . 2009-01-13 23:52 d——– c:\program files\PC Connectivity Solution
2009-01-13 23:03 . 2009-01-13 23:03 1,025 –a—— c:\windows\webcheck.exe
2009-01-09 09:46 . 2008-10-16 14:06 268,648 –a—— c:\windows\system32\mucltui.dll
2009-01-09 09:46 . 2008-10-16 14:06 27,496 –a—— c:\windows\system32\mucltui.dll.mui
2009-01-06 23:19 . 2009-01-15 17:32 2 –a—— C:\1358254015
2009-01-06 23:19 . 2009-01-09 12:37 0 –a—— c:\windows\system32\drivers\a1d73681.sys
2009-01-03 22:02 . 2009-01-03 22:02 d——– c:\documents and settings\imran.aftab\Application Data\Windows Search
2009-01-03 21:58 . 2009-01-14 09:52 1,911,957 –a—— c:\windows\setupapi.log.5.old
2009-01-03 21:50 . 2009-01-03 21:50 d——– c:\documents and settings\imran.aftab\Application Data\Windows Desktop Search
2009-01-03 21:49 . 2009-01-16 22:31 d–h—– c:\windows\system32\GroupPolicy
2009-01-03 21:49 . 2009-01-16 16:52 d——– c:\program files\Windows Desktop Search
2009-01-03 21:49 . 2008-03-07 22:02 192,000 —–c— c:\windows\system32\dllcache\offfilt.dll
2009-01-03 21:49 . 2008-03-07 22:02 98,304 —–c— c:\windows\system32\dllcache\nlhtml.dll
2009-01-03 21:49 . 2008-03-07 22:02 29,696 —–c— c:\windows\system32\dllcache\mimefilt.dll
2009-01-03 20:30 . 2009-01-03 20:30 123 –a—— c:\windows\Winchat.ini
2009-01-03 19:50 . 2009-01-03 20:32 d——– c:\documents and settings\All Users\Application Data\PrevxCSI
2008-12-28 01:49 . 2009-01-11 00:18 d——– c:\documents and settings\imran.aftab\Application Data\dvdcss
2008-12-26 11:35 . 2008-12-26 11:35 244 –ah—– C:\sqmnoopt01.sqm
2008-12-26 11:35 . 2008-12-26 11:35 232 –ah—– C:\sqmdata01.sqm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-23 18:21 ——— d—–w c:\program files\Trend Micro
2009-01-17 16:45 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-16 11:45 ——— d—–w c:\program files\Java
2009-01-15 14:37 ——— d—–w c:\program files\OpenOffice.org 3
2009-01-15 08:44 ——— d—–w c:\program files\Common Files\stardock
2009-01-14 07:47 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-13 18:53 ——— d—–w c:\program files\Nokia
2009-01-13 18:53 ——— d—–w c:\program files\Common Files\PCSuite
2009-01-13 18:53 ——— d—–w c:\program files\Common Files\Nokia
2009-01-12 08:43 76,304 —-a-w c:\windows\system32\drivers\tmtdi.sys
2009-01-12 08:43 338,448 —-a-w c:\windows\system32\drivers\TM_CFW.sys
2009-01-12 08:43 142,992 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-01-12 04:30 ——— d—–w c:\program files\XVideoConverter
2009-01-11 18:22 ——— d—–w c:\documents and settings\All Users\Application Data\Installations
2009-01-06 20:20 ——— d—–w c:\documents and settings\imran.aftab\Application Data\Nokia
2008-12-29 11:56 ——— d—–w c:\documents and settings\All Users\Application Data\PC Suite
2008-12-12 09:21 ——— d—–w c:\documents and settings\imran.aftab\Application Data\Ethereal
2008-12-12 09:20 ——— d—–w c:\program files\WinPcap
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-11 05:54 ——— d—–w c:\documents and settings\imran.aftab\Application Data\Desktop Sidebar
2008-12-10 18:09 ——— d—–w c:\program files\Microsoft Office Outlook Connector
2008-12-10 18:05 ——— d—–w c:\program files\Microsoft
2008-12-10 18:02 ——— d—–w c:\documents and settings\imran.aftab\Application Data\Styler
2008-12-10 17:55 ——— d—–w c:\documents and settings\imran.aftab\Application Data\ViStart
2008-12-10 17:52 47,903 —-a-w c:\windows\BricoPackUninst.cmd
2008-12-10 17:52 2,180 —-a-w c:\windows\BricoPackFoldersDelete.cmd
2008-12-10 16:39 ——— d—–w c:\documents and settings\All Users\Application Data\WLInstaller
2008-12-10 11:53 ——— d—–w c:\program files\Windows Media Connect 2
2008-12-06 21:17 ——— d—–w c:\documents and settings\imran.aftab\Application Data\ComSoft
2008-12-06 20:41 ——— d—–w c:\program files\Winstep
2008-12-06 20:16 ——— d—–w c:\documents and settings\imran.aftab\Application Data\.ZMatrix
2008-11-29 19:18 ——— d—–w c:\program files\DIFX
2008-11-29 19:18 ——— d—–w c:\documents and settings\All Users\Application Data\Downloaded Installations
2008-11-29 19:12 0 —ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2008-11-29 19:12 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2008-11-29 19:11 ——— d—–w c:\documents and settings\All Users\Application Data\Nokia
2008-11-29 11:55 ——— d—–w c:\program files\Microsoft SQL Server Compact Edition
2008-11-29 11:50 ——— dcsh–w c:\program files\Common Files\WindowsLiveInstaller
2008-11-29 11:20 ——— d—–w c:\program files\MSXML 4.0
2008-11-29 11:10 ——— d—–w c:\program files\Microsoft Works
2008-11-24 05:25 ——— d—–w c:\documents and settings\imran.aftab\Application Data\Xerox
2008-08-05 18:17 466,944 —-a-w c:\program files\StickyNotes.exe
2001-01-07 19:00 1,147,139 —-a-w c:\program files\Merge.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-01-05 13:41 2857984 –a—— c:\program files\Protector Suite QL\farchns.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-01-05 13:41 2857984 –a—— c:\program files\Protector Suite QL\farchns.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMMUNICATOR"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2005-05-12 4167376]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2003-12-18 4677632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2008-02-20 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-20 774233]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2007-03-26 217088]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2007-08-31 503808]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-02-07 411768]
"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" [2007-01-05 49168]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2009-01-12 718120]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 2658304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-16 136600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2005-05-12 4167376]

c:\documents and settings\admin\Start Menu\Programs\Startup\
CCC.lnk - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-09-29 49152]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-12-06 576104]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoSimpleStartMenu"= 1 (0x1)
"NoStartMenuMyMusic"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-01-05 13:28 90112 c:\windows\system32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\kwinhook]
2007-10-31 01:05 6144 c:\windows\system32\KWinHook.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-05-16 20:50 73728 c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=computer.BAT

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1506047364-1172942490-3056777903-33117\Scripts\Logon\0\0]
"Script"=user.BAT

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1506047364-1172942490-3056777903-34391\Scripts\Logon\0\0]
"Script"=user.BAT

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1506047364-1172942490-3056777903-34391\Scripts\Logon\1\0]
"Script"=cde.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bionix Wallpaper 5]
–a—— 2008-12-26 23:16 712192 c:\bionix wallpaper\Bionix Wallpaper 5.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN\\MSNCoreFiles\\Install\\msnsusii.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12983:TCP"= 12983:TCP:BitComet 12983 TCP
"12983:UDP"= 12983:UDP:BitComet 12983 UDP
"46423:TCP"= 46423:TCP:Trend Micro OfficeScan Listener

R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2008-05-20 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2008-05-20 43904]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2008-05-20 30976]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2008-05-20 808448]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2007-11-30 338448]
R3 TmPfw;OfficeScan NT Firewall;c:\program files\Trend Micro\OfficeScan Client\TmPfw.exe [2007-11-30 488768]
R4 KBOXManagementService;KBOX Management Service;c:\program files\KACE\KBOX\KBOXManagementService.exe [2008-05-20 49152]
R4 KBOXSMMP;KBOX SMMP Management Service;c:\program files\KACE\KBOX\KBOXSMMPService.exe [2008-05-20 983040]
R4 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\tmxpflt.sys [2008-01-22 205328]
R4 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [2008-01-22 36368]
S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys –> c:\windows\system32\drivers\Partizan.sys [?]
S1 a1d73681;a1d73681;c:\windows\system32\drivers\a1d73681.sys [2009-01-06 0]
S1 a6a4f9b7;a6a4f9b7;c:\windows\system32\drivers\a6a4f9b7.sys [2009-01-15 0]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2008-09-30 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2008-09-30 8320]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-03 32512]
S3 RegGuard;RegGuard;c:\windows\system32\drivers\regguard.sys [2009-01-21 29584]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\Trend Micro\OfficeScan Client\TmProxy.exe [2007-11-30 652552]
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{F552DDE6-2090-4bf4-B924-6141E87789A5} - (no file)
Notify-NavLogon - (no file)
MSConfigStartUp-RegRun WinBait - c:\windows\winbait.exe
MSConfigStartUp-Regrun2 - c:\progra~1\Greatis\REGRUN~1\WatchDog.exe
MSConfigStartUp-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe


.
——- Supplementary Scan ——-
.
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyServer = 10.5.3.44:8080
uInternet Settings,ProxyOverride = x5chris.telenor.com.pk;crm.telenor.com.pk;pos.telenor.com.pk;shoptool.bss.teleno
r.com.pk;webmail.telenor.com.pk;helpdesk.telenor.com.pk;tpptestdb.bss.telenor.com
.pk;10.1.4.190;10.1.4.183;172.18.26.139;*.bss.telenor.com.pk;partner.telenor.com;
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-23 23:35:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1708)
c:\windows\system32\vrlogon.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\kwinhook.dll
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homepass.dll
c:\program files\Protector Suite QL\bio.dll
c:\program files\Protector Suite QL\remote.dll
c:\windows\system32\VESWinlogon.dll
c:\program files\Protector Suite QL\crypto.dll

- - - - - - - > 'lsass.exe'(1768)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infra.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Trend Micro\OfficeScan Client\NTRtScan.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Trend Micro\OfficeScan Client\TmListen.exe
c:\windows\temp\TU55C1.EXE
c:\program files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Protector Suite QL\psqltray.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
.
**************************************************************************
.
Completion time: 2009-01-23 23:37:33 - machine was rebooted [imran.aftab]
ComboFix-quarantined-files.txt 2009-01-23 18:37:30

Pre-Run: 38,608,187,392 bytes free
Post-Run: 38,846,300,160 bytes free

319 — E O F — 2009-01-16 15:18:14





HijackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:40, on 2009-01-23
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\KACE\KBOX\KBOXManagementService.exe
C:\Program Files\KACE\KBOX\KBOXSMMPService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
C:\WINDOWS\TEMP\TU55C1.EXE
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.5.3.44:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = x5chris.telenor.com.pk;crm.telenor.com.pk;pos.telenor.com.pk;shoptool.bss.teleno
r.com.pk;webmail.telenor.com.pk;helpdesk.telenor.com.pk;tpptestdb.bss.telenor.com
.pk;10.1.4.190;10.1.4.183;172.18.26.139;*.bss.telenor.com.pk;partner.telenor.com;
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - (no file)
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [Switcher.exe] "C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe"
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229190672531
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229190611640
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553550000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = telenor.com.pk
O17 - HKLM\Software\..\Telephony: DomainName = telenor.com.pk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = telenor.com.pk
O20 - Winlogon Notify: kwinhook - C:\WINDOWS\SYSTEM32\kwinhook.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KBOX Management Service (KBOXManagementService) - KACE Networks, Inc. - C:\Program Files\KACE\KBOX\KBOXManagementService.exe
O23 - Service: KBOX SMMP Management Service (KBOXSMMP) - KACE Networks, Inc. - C:\Program Files\KACE\KBOX\KBOXSMMPService.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: OfficeScan NT Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe

–
End of file - 9931 bytes




Best Regards
Hi,

Remove this with HJT.
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - (no file)





You need to enable windows to Show all Files and Folders
Instructions for your Operating System HERE

c:\windows\system32\hwwcdmaui.ini <–Delete this file, leave it in the Recycle bin for a few days




Go to VirusTotal and submit these files for analysis, just use the BROWSE feature and then Send File , you will get a report back, post the report into this thread for me to see.

C:\ndcnlcdr.exe
c:\windows\system32\drivers\a6a4f9b7.sys



Everything else looks fine, how are things running now??
Hi,



The following file has been removed using HJT
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - (no file)



The following file has been deleted and left in the Recycle Bin as requested
c:\windows\system32\hwwcdmaui.ini


Below are the analysis results from Virus Total for the two files:

C:\ndcnlcdr.exe

Antivirus Version Last Update Result
a-squared 4.0.0.73 2009.01.24 -
AhnLab-V3 5.0.0.2 2009.01.24 -
AntiVir 7.9.0.60 2009.01.23 TR/Crypt.XPACK.Gen
Authentium 5.1.0.4 2009.01.24 -
Avast 4.8.1281.0 2009.01.23 Win32:Virtumonde-SK
AVG 8.0.0.229 2009.01.23 Generic12.AYHX
BitDefender 7.2 2009.01.24 Trojan.Generic.1382563
CAT-QuickHeal 10.00 2009.01.24 -
ClamAV 0.94.1 2009.01.24 -
Comodo 944 2009.01.24 -
DrWeb 4.44.0.09170 2009.01.24 -
eSafe 7.0.17.0 2009.01.22 Suspicious File
eTrust-Vet 31.6.6325 2009.01.24 -
F-Prot 4.4.4.56 2009.01.23 -
F-Secure 8.0.14470.0 2009.01.24 -
Fortinet 3.117.0.0 2009.01.24 -
GData 19 2009.01.24 Trojan.Generic.1382563
Ikarus T3.1.1.45.0 2009.01.24 -
K7AntiVirus 7.10.602 2009.01.23 Trojan.Win32.Malware.1
Kaspersky 7.0.0.125 2009.01.24 -
McAfee 5504 2009.01.23 -
McAfee+Artemis 5504 2009.01.23 Generic!Artemis
Microsoft 1.4205 2009.01.24 Trojan:Win32/Obduran.A
NOD32 3795 2009.01.23 a variant of Win32/Kryptik.FI
Norman 5.93.01 2009.01.23 -
nProtect 2009.1.8.0 2009.01.23 -
Panda 9.5.1.2 2009.01.24 Generic Trojan
PCTools 4.4.2.0 2009.01.24 -
Prevx1 V2 2009.01.24 Malicious Software
Rising 21.13.42.00 2009.01.23 -
SecureWeb-Gateway 6.7.6 2009.01.24 Trojan.Crypt.XPACK.Gen
Sophos 4.37.0 2009.01.24 Sus/Behav-273
Sunbelt 3.2.1835.2 2009.01.16 -
Symantec 10 2009.01.24 -
TheHacker 6.3.1.5.227 2009.01.24 -
TrendMicro 8.700.0.1004 2009.01.24 -
VBA32 3.12.8.11 2009.01.23 -
ViRobot 2009.1.23.1576 2009.01.23 -
VirusBuster 4.5.11.0 2009.01.23 -
Additional information
File size: 8192 bytes
MD5…: 8e3a23c3d3125a1bbfe327882012d2ca
SHA1..: 1062cc17d04bf0e27841c16923da3897fc0315df
SHA256: 4dbbb4a17f07be149375e8b3cd68f19b4fe08f924de0d7807a8a61e861c8819d
SHA512: f330ff827791f1092849a1f018d9c67c18b4a61240ef5537062460a361a3f81e
50bb88f42711217d3e49d6778da536aaea26eced70c98e48601fdd87a97fe77c

ssdeep: 192:W6s7myVaH5vw6bZJApnK9vHkVzurqkTClMbYaNI:W6DyVavX7ApnKKZutTCm
EaNI

PEiD..: -
TrID..: File type identification
UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x40a640
timedatestamp…..: 0x496e37dc (Wed Jan 14 19:07:08 2009)
machinetype…….: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x28000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x29000 0x2000 0x1800 7.75 87d1737ac1d039887617250f7b4e676d
.rsrc 0x2b000 0x1000 0x400 3.29 1f3362e72c6a4006268a1c5aedcae9e8

( 1 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess

( 0 exports )

packers (Kaspersky): PE_Patch.UPX, UPX
packers (F-Prot): UPX
packers (Avast): UPX
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=10B01FB400DC6A48200C00F17598D500217D2038


c:\windows\system32\drivers\a6a4f9b7.sys

This file is empty and has a file size of 0 Bytes


The things seem to be fine, no hangups and no problems in windows startup so far.

However, the scan with RemoveIT Pro still shows following results:

17:15:43: Scanning, please wait…
17:15:47: Infected file (Win32.Unknown.Random.X) c:\windows\temp\eda4e4.exe -> No action taken.
17:18:03: Infected file (Sys32.kwinhook) c:\windows\system32\kwinhook.dll -> No action taken.
17:18:54: Infected file (Sys32.nircmd) C:\WINDOWS\nircmd.exe -> No action taken.
17:19:00: Infected file (Sys32.webcheck) C:\WINDOWS\webcheck.exe -> No action taken.
17:19:24: Infected file (Sys32.rpcapd) C:\Program Files\winpcap\rpcapd.exe -> No action taken.
17:19:26: 5 Dangerous files has been found on your computer.
Click on "Fix" button to fix selected tasks.


Please confirm if these are of any harm to my machine or not, thanks!
Hello,

Go ahead and delete both of those files that we checked.


RemoveIT Pro



These should be deleted
C:\WINDOWS\webcheck.exe
c:\windows\temp\eda4e4.exe

These are safe
c:\windows\system32\kwinhook.dll
C:\Program Files\winpcap\rpcapd.exe
C:\WINDOWS\nircmd.exe

How are things running now?
Hi, The required files have been removed. Please note that once i had deleted following files, which were identified through RemoveIT Pro: C:\WINDOWS\webcheck.exe c:\windows\temp\eda4e4.exe The first file is gone, however, after first reboot i have run the scan again and a similar file with new filename has been identified: 20:14:17: Infected file (Win32.Unknown.Random.X) c:\windows\temp\zh212b.exe -> No action taken. I think there is some other process/program which runs with the reboot. In case you find it harmless, we can keep it :) its all up to your advice. Thanks!!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI