Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
IE opens on its own
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > IE opens on its own  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : IE opens on its own
[ << Previous Thread | Next Thread >> ]

tinasg
New Member


Date Joined Sep 2008
Total Posts : 6
 
   Posted 9-9-2008 10:28 (GMT +1)    Quote: IE opens on its ownAlert an admin about: IE opens on its own
hi,
 
i need a small help. my internet explorer seems to be infected with virus. at times it opens up on its own with some chinese games sites. they open up with some website name or an ip address. this is very irritating and i hope it is not going to harm my machine.
this problem is since past 2 weeks and my machine got installed with windows update today (SP3)
can some1 help me in removing this virus?
many thanks in advance!
 
PS: read the previous threads and currently scanning using Malware software
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14295
 
   Posted 9-9-2008 12:06 (GMT +1)    Quote: IE opens on its ownAlert an admin about: IE opens on its own
Hello smile
 
 
After the malware scan ->
 
 
Click here - >> Before posting a log 
 
 
 After You have run the scan tools -
 
Reboot normally
 
Post Hijackthis log along with SuperAntiSpyware log, , C: combofix TXT  in this topic
 
Please copy and paste your log. DO NOT add it as an attachment
Kindly do not annotate or format the log with color or font changes.
NB. If you are using any P2P (file sharing) programs, please remove them before we clean your computer.. We do not clean logs that have P2P applications installed as this can cause reinfection during your cleaning.


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

tinasg
New Member


Date Joined Sep 2008
Total Posts : 6
 
   Posted 9-9-2008 12:17 (GMT +1)    Quote: IE opens on its ownAlert an admin about: IE opens on its own
Thanks!
 
Will do the same and update you.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14295
 
   Posted 9-9-2008 12:35 (GMT +1)    Quote: IE opens on its ownAlert an admin about: IE opens on its own
Ok


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

tinasg
New Member


Date Joined Sep 2008
Total Posts : 6
 
   Posted 9-10-2008 7:33 (GMT +1)    Quote: IE opens on its ownAlert an admin about: IE opens on its own
Ok here are the malware logs:
===>
Malwarebytes' Anti-Malware 1.27
Database version: 1131
Windows 5.1.2600 Service Pack 3
9/9/2008 5:30:38 PM
mbam-log-2008-09-09 (17-30-38).txt
Scan type: Full Scan (C:\|)
Objects scanned: 118565
Time elapsed: 21 minute(s), 46 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper
(Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
<===

I then ran a spyware and found 42 adware tracking cookies which were qurantined. Here are the logs:
===>
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 09/10/2008 at 11:30 AM
Application Version : 4.21.1004
Core Rules Database Version : 3561
Trace Rules Database Version: 1549
Scan type       : Complete Scan
Total Scan Time : 00:33:57
Memory items scanned      : 541
Memory threats detected   : 0
Registry items scanned    : 6733
Registry threats detected : 0
File items scanned        : 33765
File threats detected     : 42
Adware.Tracking Cookie
 C:\Documents and Settings\groopali\Cookies\groopali@apmebf[2].txt
 C:\Documents and Settings\groopali\Cookies\groopali@questionmarket[1].txt
 C:\Documents and Settings\groopali\Cookies\groopali@atdmt[1].txt
 C:\Documents and Settings\groopali\Cookies\groopali@www.googleadservices[1].txt
 C:\Documents and Settings\groopali\Cookies\groopali@specificclick[2].txt
 C:\Documents and Settings\groopali\Cookies\groopali@adopt.specificclick[2].txt
 C:\Documents and Settings\groopali\Cookies\groopali@112.2o7[2].txt
 C:\Documents and Settings\groopali\Cookies\groopali@indextools[3].txt
 C:\Documents and Settings\groopali\Cookies\groopali@mediaplex[1].txt
 C:\Documents and Settings\groopali\Cookies\groopali@ad.yieldmanager[2].txt
 C:\Documents and Settings\groopali\Cookies\groopali@www.googleadservices[3].txt
 C:\Documents and Settings\groopali\Cookies\groopali@adinterax[2].txt
 C:\Documents and Settings\groopali\Cookies\groopali@advertising[2].txt
 C:\Documents and Settings\groopali\Cookies\groopali@doubleclick[1].txt
 C:\Documents and Settings\groopali\Cookies\groopali@www.googleadservices[2].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@bs.serving-sys[2].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@adopt.euroclick[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@d2.zedo[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@2o7[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@richmedia.yahoo[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@xiti[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@zedo[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@specificclick[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@adultfriendfinder[2].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@advertising[2].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[2].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@casalemedia[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@accounts[2].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@adinterax[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[2].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[1].txt
 C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[1].txt
 .doubleclick.net [ C:\Documents and Settings\groopali\Application
Data\Mozilla\Firefox\Profiles\9jxn2gee.default\cookies.txt ]
 C:\Documents and Settings\groopali\Cookies\groopali@ad.yieldmanager[1].txt
 C:\Documents and Settings\groopali\Cookies\groopali@mediaplex[2].txt
 C:\Documents and Settings\groopali\Cookies\groopali@indextools[2].txt
 C:\Documents and Settings\groopali\Cookies\groopali@doubleclick[2].txt
 C:\Documents and Settings\groopali\Cookies\groopali@apmebf[1].txt
 C:\Documents and Settings\groopali\Cookies\groopali@richmedia.yahoo[1].txt
<===
Here are the hijack this logs:
===>
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:39:13 AM, on 9/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\FLEXlm\Lmgrd.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\FLEXlm\genesys.d.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlagent.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\FlashGet\flashget.exe
C:\Documents and Settings\groopali\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program
Files\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan
Enterprise\Scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program
files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program
Files\FlashGet\getflash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel
PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe"
/StartedFromRunKey
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC
Suite\SEPCSuite.exe" /systray /nologon
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
(User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
(User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
(User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
(User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program
Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program
Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra button: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\Program
Files\WebEx\WebEx\350\atonecli.dll (HKCU)
O9 - Extra 'Tools' menuitem: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} -
C:\Program Files\WebEx\WebEx\350\atonecli.dll (HKCU)
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) -
http://www.aajtak.com/wfplayer/tdserver.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program
Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
http://img2.orkut.com/activex/10035/photouploader.cab
O16 - DPF: {4D1DA428-3B37-44E6-893A-D3A5BCE0E7E3} (Siebel High Interactivity Framework) -
http://panorama.genesyslab.com/callcenter_enu/18382/applets/SiebelAx_HI_Client.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://indiafreetrial.webex.com/client/T26L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ismartpanache.net
O17 - HKLM\Software\..\Telephony: DomainName = ismartpanache.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ismartpanache.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ismartpanache.net
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Genesys Data Mart [ETL_Runtime] (CCADataMart) - Genesys Telecommunication Laboratories, Inc.
- C:\Program Files\GCTI\Data Mart\ETL_Runtime\etl_runtime\starter.exe
O23 - Service: Genesys Data Sourcer [DataSourcer] (CCADataSourcer) - Genesys Telecommunications
Laboratories, Inc. - C:\Program Files\GCTI\Data Sourcer\DataSourcer\data_sourcer.exe
O23 - Service: Genesys Singletenant Configuration Server (ConfigServerST) - Genesys Telecomm. Labs -
C:\Program Files\GCTI\Singletenant Configuration Server\confserv.exe
O23 - Service: Genesys Singletenant Configuration Server (1) (ConfigServerST_1) - Genesys Telecomm. Labs -
D:\GCTI\ConfigServer\confserv.exe
O23 - Service: Genesys Call Progress Detection Server [cpdsvr76] (CPDServer) - GCTI -
C:\GCTI\cpdsvr76\cpdproxy.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco
Systems\VPN Client\cvpnd.exe
O23 - Service: Genesys DB Server (DBServer) - Genesys Telecommunications Laboratories, Inc.  - C:\Program
Files\GCTI\DB Server\multiserver.exe
O23 - Service: Genesys DB Server [LogDBServer] (DBServer_1) - Genesys Telecommunications Laboratories, Inc.
 - C:\Program Files\GCTI\DB Server\LogDBServer\multiserver.exe
O23 - Service: Genesys DB Server [OCSDBServer] (DBServer_2) - Genesys Telecommunications Laboratories, Inc.
 - C:\Program Files\GCTI\DB Server\OCSDBServer\multiserver.exe
O23 - Service: Genesys DB Server [ODSDBServer] (DBServer_3) - Genesys Telecommunications Laboratories, Inc.
 - C:\Program Files\GCTI\DB Server\ODSDBServer\multiserver.exe
O23 - Service: Genesys DB Server [ETL_DBServer] (DBServer_4) - Genesys Telecommunications Laboratories,
Inc.  - C:\Program Files\GCTI\DB Server\ETL_DBServer\multiserver.exe
O23 - Service: Genesys DB Server (1) (DBServer_5) - Genesys Telecommunications Laboratories, Inc.  -
D:\GCTI\DBServer\multiserver.exe
O23 - Service: Genesys DB Server [ODS_DBServer_bkup] (DBServer_6) - Genesys Telecommunications
Laboratories, Inc.  - C:\Program Files\GCTI\DB Server\ODS_DBServer_bkup\multiserver.exe
O23 - Service: Genesys DB Server (2) (DBServer_7) - Genesys Telecommunications Laboratories, Inc.  -
D:\GCTI\DBServer7.5\multiserver.exe
O23 - Service: Genesys DB Server [OCSDBServer] (1) (DBServer_8) - Genesys Telecommunications Laboratories,
Inc.  - C:\Program Files\GCTI\DB Server\OCSDBServer_1\multiserver.exe
O23 - Service: Genesys DB Server [OCS_DBServer] (DBServer_9) - Genesys Telecommunications Laboratories,
Inc.  - C:\Program Files\GCTI\DB Server\OCS_DBServer\multiserver.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program
Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXlm Service 1 - Macrovision Corporation - C:\FLEXlm\Lmgrd.exe
O23 - Service: Genesys Desktop [GAD_76] (GDesktop_1) - Genesys Telecommunication Laboratories Inc. -
C:\GCTI\GenesysDesktop\GAD_76\bin\GDesktopDriver.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterService.exe
O23 - Service: Genesys Local Control Agent (LCA) - Genesys Telecommunication Laboratories Inc. - C:\Program
Files\GCTI\Local Control Agent\lca.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common
Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan
Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan
Enterprise\VsTskMgr.exe
O23 - Service: Genesys Message Server [MessageServer] (MsgServer) - Genesys Telecommunications
Laboratories, Inc.  - C:\Program Files\GCTI\MsgServer\MessageServer\MessageServer.exe
O23 - Service: Genesys Message Server [RoutingMessageServer] (MsgServer_1) - Genesys Telecommunications
Laboratories, Inc.  - C:\Program Files\GCTI\MsgServer\RoutingMessageServer\MessageServer.exe
O23 - Service: Genesys Message Server [MS] (MsgServer_2) - Genesys Telecommunications Laboratories, Inc.  -
C:\Program Files\GCTI\MsgServer\MS\MessageServer.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Genesys Outbound Contact Server [OCS] (OCServer) - Genesys Telecommunications Laboratories,
Inc. - C:\Program Files\GCTI\OCServer\OCS\cm_server.exe
O23 - Service: Genesys Outbound Contact Server [OCS_76] (OCServer_1) - Genesys Telecommunications
Laboratories, Inc. - C:\Program Files\GCTI\OCServer\OCS_76\cm_server.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program
Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program
Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Genesys Solution Control Server [SCS] (SCServer) - Genesys Telecommunication Laboratories
Inc. - C:\Program Files\GCTI\SCServer\SCS\scs.exe
O23 - Service: Genesys Stat Server [RoutingStatServer] (StatServer) - Genesys - C:\Program Files\GCTI\Stat
Server\RoutingStatServer\statserv.exe
O23 - Service: Genesys Stat Server [ReportingStatServer] (StatServer_1) - Genesys - C:\Program
Files\GCTI\Stat Server\ReportingStatServer\statserv.exe
O23 - Service: Genesys Stat Server [OutBoundStatServer75] (StatServer_2) - Genesys - C:\Program
Files\GCTI\Stat Server\OutBoundStatServer75\statserv.exe
O23 - Service: Apache Tomcat (Tomcat5) - Apache Software Foundation - C:\Program Files\Apache Software
Foundation\Tomcat 5.5\bin\tomcat5.exe
O23 - Service: Genesys T-Server for Avaya Communication Manager [TServer] (TSrvG3) - Unknown owner -
C:\Program Files\GCTI\TSrvG3\TServer\avayacm_server.exe
O23 - Service: Genesys SIP Server [SIPServer] (TSrvSIP) - Unknown owner - C:\Program Files\GCTI\SIP
Server\SIPServer\sip_server.exe
O23 - Service: Genesys Universal Routing Server [URS] (URServer) - Unknown owner - C:\Program
Files\GCTI\URServer\URS\ur_server.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program
Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common
Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware
Server\vmserverdWin32.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Genesys Stream Manager [StreamManager] (VoIPSM) - Genesys Telecommunications Laboratories,
Inc. - C:\Program Files\GCTI\IPMX\VoIPSM\StreamManager\sm.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program
Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 16497 bytes
<===
I was not able to download the combofix.
Please let me know what do i do next.
Many thanks!
Back to Top
 

tinasg
New Member


Date Joined Sep 2008
Total Posts : 6
 
   Posted 9-10-2008 7:37 (GMT +1)    Quote: IE opens on its ownAlert an admin about: IE opens on its own
Please note that the sites are not opening now since yesterday, after i started the malware scan and installed McAfee. Please let me know if the porblem is fixed and what was the cause of the virus. This can help me avoid the same in future.

Also, let me know the guidelines to keep my machine safe. Anything to be done on timely basis?

Thanks!
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14295
 
   Posted 9-10-2008 7:58 (GMT +1)    Quote: IE opens on its ownAlert an admin about: IE opens on its own
Sounds good smile
 
I can´t tell what the cause is, as i can´t see any infections in the logfiles.
 
Please read this article by Tony Klein: How I got Infected in the First Place

 
 
Otherwise ->
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
Post back with both the resulting logs.

 
 
 




Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

tinasg
New Member


Date Joined Sep 2008
Total Posts : 6
 
   Posted 9-10-2008 8:11 (GMT +1)    Quote: IE opens on its ownAlert an admin about: IE opens on its own
Ok here is the info.txt content:
 
===>
info.txt logfile of random's system information tool 2008-09-10 12:46:38
Uninstall list
-->MsiExec.exe /I{09715083-BF10-4834-9E28-B5D8820513CA}
-->MsiExec.exe /I{1E049668-AD90-4008-B213-E20CED2324DD}
-->MsiExec.exe /I{35103A8A-E9D8-40FA-AEC7-4D138952DB30}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Apache Tomcat 5.5 (remove only)-->"C:\Program Files\Apache Software Foundation\Tomcat 5.5\Uninstall.exe"
Apple Software Update-->MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Avanquest update-->C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\setup.exe -runfromtemp -l0x0009 -removeonly
Broadcom Gigabit Integrated Controller-->MsiExec.exe /X{B7F54262-AB66-44B3-88BF-9FC69941B643}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Conexant HDA D110 MDC V.92 Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3\HXFSETUP.EXE -U -Idel1028p.inf
Dell Resource CD-->MsiExec.exe /X{FCD9CD52-7222-4672-94A0-A722BA702FD0}
FlashGet 1.9.0.1012-->C:\Program Files\FlashGet\uninst.exe
FLEXlm License Manager 9.5-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{19C78084-507F-4450-9BEE-50F999DE13C6}
Genesys ActiveX Interface for Desktop Toolkit 7.2.000.00-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{6EEDB110-63C0-4EC9-9CA1-BEFE04BC8156}
Genesys Call Progress Detection Server 7.6.100.02 [cpdsvr76]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{310123F7-FD8B-4212-A9C7-138269BB788A}\setup.exe" -l0x9
Genesys CCPulse+ 7.5.000.10-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3D81427E-5106-4512-BCEE-F9CB435CD5F1}\setup.exe" -l0x9
Genesys Configuration Manager 7.5.000.11-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A26D74E3-6F13-4B56-85A4-FD17336248FB}\setup.exe" -l0x9
Genesys Data Mart 7.2.002.08 [ETL_Runtime]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{31FA0ADF-AC6C-44DC-8CBA-E91ED7EFFB18}\setup.exe" -l0x9
Genesys Data Modeling Assistant 7.2.001.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{748B4379-CF76-4D7C-AE44-5F44063E2182}\setup.exe" -l0x9
Genesys Data Sourcer 7.2.002.18 [DataSourcer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CD6070CF-C4B4-4E05-8A53-9C9239A5E5EA}\setup.exe" -l0x9
Genesys DB Server 7.2.000.03-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F328B2A1-127A-487D-B936-96CAE094127C}\setup.exe" -l0x9
Genesys DB Server 7.5.000.07 [ETL_DBServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BA591060-3558-4DA6-A516-419D2D53CCDB}\setup.exe" -l0x9
Genesys DB Server 7.5.000.07 [LogDBServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{47E9F52B-C784-4FFD-A891-529B785A6B8D}\setup.exe" -l0x9
Genesys DB Server 7.5.000.07 [OCS_DBServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0CCEC1C2-B660-4472-93B2-108D87F91F04}\setup.exe" -l0x9
Genesys DB Server 7.5.000.07 [OCSDBServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4B0BEC25-E5DD-4BD7-9600-AE9D01C9E61B}\setup.exe" -l0x9
Genesys DB Server 7.5.000.07 [OCSDBServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{668E5D63-8D35-42D0-872F-84258E3A49FF}\setup.exe" -l0x9
Genesys DB Server 7.5.000.07 [ODS_DBServer_bkup]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{65A0291A-78EE-4D76-978E-3941C8509DF8}\setup.exe" -l0x9
Genesys DB Server 7.5.000.07 [ODSDBServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9582F4AC-F86C-453B-AB87-2D4EE62C2860}\setup.exe" -l0x9
Genesys DB Server 7.5.000.07-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4404A67F-1879-42BF-B988-963AB6CCA5A1}\setup.exe" -l0x9
Genesys DB Server 7.5.000.07-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3F6C73B-72E3-4662-BD48-11FB4947182A}\setup.exe" -l0x9
Genesys Desktop 7.6.001.11 [GAD_76]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0EFEAE43-03A6-4296-BBA5-75239FAE6987}\setup.exe" -l0x9
Genesys Desktop SIP Endpoint 7.5.000.04-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{21D7E367-F87A-4044-BD9B-F02FDCE832A8}\setup.exe" -l0x9
Genesys Interaction Routing Designer 7.5.002.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{46300494-3921-402B-BD41-BD6A02008ABF}\setup.exe" -l0x9
Genesys Local Control Agent 7.5.000.06-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6F372F1B-4E48-4550-97A8-1EF2E3865AF8}\setup.exe" -l0x9
Genesys Local Control Agent-->C:\GCTI\LocalControlAgent\CleanLCA.bat
Genesys Message Server 7.5.000.06 [MessageServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BDD2F757-B005-4B97-A2D0-92DD3DCC8912}\setup.exe" -l0x9
Genesys Message Server 7.5.000.06 [RoutingMessageServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{54C8B277-E215-4157-B899-958A29AD2DA8}\setup.exe" -l0x9
Genesys Message Server 7.6.000.01 [MS]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{90BD2C2E-EF79-4BA7-A6ED-423F0898CA93}\setup.exe" -l0x9
Genesys Outbound Contact Configuration Wizard 7.5.000.05-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FE497AE-E87B-4192-8FD0-6ECAEE9ADC7E}\setup.exe" -l0x9
Genesys Outbound Contact Manager 7.5.000.07-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4090EBF1-9FA6-4E5A-9E86-3DEBA29310AE}\setup.exe" -l0x9
Genesys Outbound Contact Server 7.5.000.17 [OCS]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EDFA574B-7450-4B86-B664-1F2FC43F57F1}\setup.exe" -l0x9
Genesys Outbound Contact Server 7.6.100.02 [OCS_76]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{662BDA93-2534-4DE6-B33F-BFF7784C3DA8}\setup.exe" -l0x9
Genesys Singletenant Configuration Server 7.2.000.22-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A32D021C-8AFC-48DC-8714-03CA45D6B0F5}\setup.exe" -l0x9
Genesys Singletenant Configuration Server 7.5.000.11-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63DF5AD0-D1CF-4D88-ADFF-AEF20ADEB348}\setup.exe" -l0x9
Genesys SIP Server 7.5.000.37 [SIPServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2031C903-BDDA-4462-87E3-632070C26776}\setup.exe" -l0x9
Genesys Solution Control Interface 7.5.000.12-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6C91DCEB-0A34-4D09-8DE3-97AED5A81E54}\setup.exe" -l0x9
Genesys Solution Control Server 7.5.000.08 [SCS]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A49F6F8-9BC4-44D6-B407-F632A4E49B27}\setup.exe" -l0x9
Genesys Stat Server 7.5.000.21 [OutBoundStatServer75]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B772EA61-A9DF-45EB-B6EE-95602475DF7D}\setup.exe" -l0x9
Genesys Stat Server 7.5.000.21 [ReportingStatServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E318C1F3-10A0-42E5-AC23-A113F9D05508}\setup.exe" -l0x9
Genesys Stat Server 7.5.000.21 [RoutingStatServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{097F1A51-270E-40D0-999F-798AA0DD54C2}\setup.exe" -l0x9
Genesys Stream Manager 7.5.004.02 [StreamManager]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0DDF9F55-CC20-48B5-BF70-4137F549E006}\setup.exe" -l0x9
Genesys T-Server for Avaya Communication Manager 7.5.009.00 [TServer]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DC78E31-982E-4A98-89C3-C14624D47BB3}\setup.exe" -l0x9
Genesys Universal Routing Server 7.5.002.02 [URS]-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E35C1030-B8DE-4B7A-948E-A7A89106919F}\setup.exe" -l0x9
GoldWave v5.22-->"C:\Program Files\GoldWave\unstall.exe" "GoldWave v5.22" "C:\Program Files\GoldWave\unstall.log"
Google Desktop Search-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSearchSetup.exe -uninstall
Google Talk (remove only)-->"C:\Program Files\Google\Google Talk\uninstall.exe"
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Gplus Simulator Test Toolkit-->C:\WINDOWS\IsUninst.exe -fC:\GCTI\Simulator\Uninst.isu
High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2-->"C:\Documents and Settings\groopali\Desktop\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hyperion Intelligence Designer-->C:\Program Files\Brio\Brio8\_uninst\uninstallClient.exe
iBall Pro Cam 486-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECD03DA7-5952-406A-8156-5F0C93618D1F}\Setup.exe" -l0x9
Intel(R) PROSet/Wireless Software-->C:\WINDOWS\Installer\iProInst.exe
Java 2 Runtime Environment, SE v1.4.2_17-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142170}
Java DB 10.3.1.4-->MsiExec.exe /X{CD49361E-3FE6-457E-90A1-9C59E29B5D02}
Java Web Start-->"C:\Program Files\Java Web Start\uninst-javaws.exe"
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java(TM) SE Development Kit 6 Update 5-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160050}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee VirusScan Enterprise-->MsiExec.exe /I{35C03C04-3F1F-42C2-A989-A757EE691F65}
mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
mDriver-->MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}
mDrWiFi-->MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}
mHlpDell-->MsiExec.exe /I{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Communicator 2005-->MsiExec.exe /X{BE5AD430-9E0C-4243-AB3F-593835869855}
Microsoft Office Live Meeting 2007-->MsiExec.exe /I{C2DA1CDC-EF9D-4B7C-91F8-710B17AD44A7}
Microsoft Office Standard Edition 2003-->MsiExec.exe /I{90120409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2000-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Microsoft SQL Server\MSSQL\Uninst.isu" -c"C:\Program Files\Microsoft SQL Server\MSSQL\sqlsun.dll" -msql.mif i=MSSQLSERVER
Microsoft Visual Studio 6.0 Enterprise Edition-->"C:\Program Files\Microsoft Visual Studio\Common\Setup\1033\Setup.exe"
Microsoft Web Publishing Wizard 1.53-->RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie3x86.inf,WebPostUninstall
mIWA-->MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
mLogView-->MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
mPfWiz-->MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
mSSO-->MsiExec.exe /I{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
mWMI-->MsiExec.exe /I{63DB9CCD-2B56-4217-9A3D-507AC78320CA}
mXML-->MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
mZConfig-->MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
OpenOffice.org Installer 1.0-->MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe"
QuickTime-->MsiExec.exe /I{5B09BD67-4C99-46A1-8161-B7208CE18121}
RTC Client API V1.3 SDK and Samples-->MsiExec.exe /X{934D6176-210A-4FA5-BEE6-5285BA1B9F12}
RTC Client API v1.3-->MsiExec.exe /X{143DF9B1-5534-4F84-BBC6-65B2154D8A34}
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
SigmaTel Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
Skype 3.0-->"C:\Program Files\Skype\Phone\unins000.exe"
Skype Plugin Manager-->MsiExec.exe /I{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}
Sony Ericsson PC Suite 3.106.00-->C:\Program Files\InstallShield Installation Information\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}\Setup.exe -runfromtemp -l0x0009 -removeonly
SUPERAntiSpyware Professional-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
TeamViewer 3-->C:\Program Files\TeamViewer3\uninstall.exe
TextPad 4.7-->MsiExec.exe /X{B510A987-487E-4C66-9F4F-D386AC275715}
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
VideoLAN VLC media player 0.8.6-->C:\Program Files\VideoLAN\VLC\uninstall.exe
VMware Server-->MsiExec.exe /I{FEE84D71-7FF0-46C1-AED4-1BD821D53A9F}
VPN Client-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5624C000-B109-11D4-9DB4-00E0290FCAC5}\Setup.exe" -l0x9  VpnUninstall
WebEx One-Click-->MsiExec.exe /I{F7860272-1D15-4FB7-BD46-EA058872F5FB}
WebEx-->C:\WINDOWS\DOWNLO~1\atcliun.exe
Windows Driver Package - Microsoft Corporation (usbvideo) Image  (05/25/2007 1.0.3656.0)-->rundll32.exe C:\PROGRA~1\DIFX\7AA84A78695B31A503D9537A76801D74E0FD14BD\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\WINDOWS\system32\DRVSTORE\RoundTable_F29D632BDCC1844B9B7688A0A4B4DA9E716B76FF\RoundTable.inf
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
Yahoo! Install Manager-->C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Internet Mail-->C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe
Hosts File
192.168.100.83 gvpusers
192.168.100.199 ismart-27950ab8
Security center information
AV: McAfee VirusScan Enterprise
Environment variables
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"JAVA_HOME"=C:\Program Files\Java\jdk1.6.0_05
"NUMBER_OF_PROCESSORS"=2
"OS"=Windows_NT
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Microsoft SQL Server\80\Tools\BINN;C:\Program Files\Common Files\Teleca Shared;C:\Program Files\QuickTime\QTSystem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_LEVEL"=6
"PROCESSOR_REVISION"=0f06
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"windir"=%SystemRoot%
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"VSEDEFLOGDIR"=C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
"DEFLOGDIR"=C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
-----------------EOF-----------------
<===
 
Here is the log.txt content:
 
===>
Logfile of random's system information tool (written by random/random)
Run by groopali at 2008-09-10 12:45:54
Microsoft Windows XP Professional Service Pack 3
System drive C: has 7 GB (28%) free of 25 GB
Total RAM: 2046 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:46, on 2008-09-10
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\FLEXlm\Lmgrd.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\FLEXlm\genesys.d.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlagent.exe
C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
C:\Program Files\Cisco Systems\VPN Client\ipseclog.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
D:\Install\Antivirus\RSIT.exe
C:\Program Files\trend micro\groopali.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\Program Files\WebEx\WebEx\350\atonecli.dll (HKCU)
O9 - Extra 'Tools' menuitem: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - C:\Program Files\WebEx\WebEx\350\atonecli.dll (HKCU)
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.aajtak.com/wfplayer/tdserver.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://img2.orkut.com/activex/10035/photouploader.cab
O16 - DPF: {4D1DA428-3B37-44E6-893A-D3A5BCE0E7E3} (Siebel High Interactivity Framework) - http://panorama.genesyslab.com/callcenter_enu/18382/applets/SiebelAx_HI_Client.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://indiafreetrial.webex.com/client/T26L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ismartpanache.net
O17 - HKLM\Software\..\Telephony: DomainName = ismartpanache.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F0BFAE2-2F87-4D30-9342-B36865459BFB}: NameServer = 192.168.20.167,192.168.20.134
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ismartpanache.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ismartpanache.net
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Genesys Data Mart [ETL_Runtime] (CCADataMart) - Genesys Telecommunication Laboratories, Inc. - C:\Program Files\GCTI\Data Mart\ETL_Runtime\etl_runtime\starter.exe
O23 - Service: Genesys Data Sourcer [DataSourcer] (CCADataSourcer) - Genesys Telecommunications Laboratories, Inc. - C:\Program Files\GCTI\Data Sourcer\DataSourcer\data_sourcer.exe
O23 - Service: Genesys Singletenant Configuration Server (ConfigServerST) - Genesys Telecomm. Labs - C:\Program Files\GCTI\Singletenant Configuration Server\confserv.exe
O23 - Service: Genesys Singletenant Configuration Server (1) (ConfigServerST_1) - Genesys Telecomm. Labs - D:\GCTI\ConfigServer\confserv.exe
O23 - Service: Genesys Call Progress Detection Server [cpdsvr76] (CPDServer) - GCTI - C:\GCTI\cpdsvr76\cpdproxy.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Genesys DB Server (DBServer) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\DB Server\multiserver.exe
O23 - Service: Genesys DB Server [LogDBServer] (DBServer_1) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\DB Server\LogDBServer\multiserver.exe
O23 - Service: Genesys DB Server [OCSDBServer] (DBServer_2) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\DB Server\OCSDBServer\multiserver.exe
O23 - Service: Genesys DB Server [ODSDBServer] (DBServer_3) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\DB Server\ODSDBServer\multiserver.exe
O23 - Service: Genesys DB Server [ETL_DBServer] (DBServer_4) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\DB Server\ETL_DBServer\multiserver.exe
O23 - Service: Genesys DB Server (1) (DBServer_5) - Genesys Telecommunications Laboratories, Inc.  - D:\GCTI\DBServer\multiserver.exe
O23 - Service: Genesys DB Server [ODS_DBServer_bkup] (DBServer_6) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\DB Server\ODS_DBServer_bkup\multiserver.exe
O23 - Service: Genesys DB Server (2) (DBServer_7) - Genesys Telecommunications Laboratories, Inc.  - D:\GCTI\DBServer7.5\multiserver.exe
O23 - Service: Genesys DB Server [OCSDBServer] (1) (DBServer_8) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\DB Server\OCSDBServer_1\multiserver.exe
O23 - Service: Genesys DB Server [OCS_DBServer] (DBServer_9) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\DB Server\OCS_DBServer\multiserver.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXlm Service 1 - Macrovision Corporation - C:\FLEXlm\Lmgrd.exe
O23 - Service: Genesys Desktop [GAD_76] (GDesktop_1) - Genesys Telecommunication Laboratories Inc. - C:\GCTI\GenesysDesktop\GAD_76\bin\GDesktopDriver.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Genesys Local Control Agent (LCA) - Genesys Telecommunication Laboratories Inc. - C:\Program Files\GCTI\Local Control Agent\lca.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Genesys Message Server [MessageServer] (MsgServer) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\MsgServer\MessageServer\MessageServer.exe
O23 - Service: Genesys Message Server [RoutingMessageServer] (MsgServer_1) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\MsgServer\RoutingMessageServer\MessageServer.exe
O23 - Service: Genesys Message Server [MS] (MsgServer_2) - Genesys Telecommunications Laboratories, Inc.  - C:\Program Files\GCTI\MsgServer\MS\MessageServer.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Genesys Outbound Contact Server [OCS] (OCServer) - Genesys Telecommunications Laboratories, Inc. - C:\Program Files\GCTI\OCServer\OCS\cm_server.exe
O23 - Service: Genesys Outbound Contact Server [OCS_76] (OCServer_1) - Genesys Telecommunications Laboratories, Inc. - C:\Program Files\GCTI\OCServer\OCS_76\cm_server.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Genesys Solution Control Server [SCS] (SCServer) - Genesys Telecommunication Laboratories Inc. - C:\Program Files\GCTI\SCServer\SCS\scs.exe
O23 - Service: Genesys Stat Server [RoutingStatServer] (StatServer) - Genesys - C:\Program Files\GCTI\Stat Server\RoutingStatServer\statserv.exe
O23 - Service: Genesys Stat Server [ReportingStatServer] (StatServer_1) - Genesys - C:\Program Files\GCTI\Stat Server\ReportingStatServer\statserv.exe
O23 - Service: Genesys Stat Server [OutBoundStatServer75] (StatServer_2) - Genesys - C:\Program Files\GCTI\Stat Server\OutBoundStatServer75\statserv.exe
O23 - Service: Apache Tomcat (Tomcat5) - Apache Software Foundation - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
O23 - Service: Genesys T-Server for Avaya Communication Manager [TServer] (TSrvG3) - Unknown owner - C:\Program Files\GCTI\TSrvG3\TServer\avayacm_server.exe
O23 - Service: Genesys SIP Server [SIPServer] (TSrvSIP) - Unknown owner - C:\Program Files\GCTI\SIP Server\SIPServer\sip_server.exe
O23 - Service: Genesys Universal Routing Server [URS] (URServer) - Unknown owner - C:\Program Files\GCTI\URServer\URS\ur_server.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware Registration Service (vmserverdWin32) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Genesys Stream Manager [StreamManager] (VoIPSM) - Genesys Telecommunications Laboratories, Inc. - C:\Program Files\GCTI\IPMX\VoIPSM\StreamManager\sm.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 16810 bytes
Registry dump
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-06-29 94308]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll [2006-11-30 67136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-03-17 2018368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll [2008-04-21 734704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-16 163840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-03-17 2018368]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"=C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2005-12-28 667718]
"IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2005-12-28 602182]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-01-19 7401472]
"nwiz"=C:\WINDOWS\system32\nwiz.exe [2006-01-19 1519616]
"NVHotkey"=C:\WINDOWS\system32\nvHotkey.dll [2006-01-19 73728]
"SigmatelSysTrayApp"=C:\WINDOWS\stsystra.exe [2006-03-24 282624]
"tsnpstd3"=C:\WINDOWS\tsnpstd3.exe []
"snpstd3"=C:\WINDOWS\vsnpstd3.exe [2006-09-19 827392]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-02 3739648]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2007-10-19 286720]
"ShStatEXE"=C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [2006-11-30 112216]
"McAfeeUpdaterUI"=C:\Program Files\McAfee\Common Framework\UdaterUI.exe [2006-11-17 136768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-03-18 68856]
"Yahoo! Pager"=C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE [2007-08-30 4670704]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"COMMUNICATOR"=C:\Program Files\Microsoft Office Communicator\Communicator.exe [2005-05-12 4167376]
"Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2007-11-20 356352]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2008-09-03 1576176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMMUNICATOR]
C:\Program Files\Microsoft Office Communicator\Communicator.exe [2005-05-12 4167376]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GDeskSIPEndpoint]
C:\Program Files\GCTI\Genesys Desktop SIP Endpoint\GDSipEndPoint.exe [2007-09-18 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe /startoptions []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2004-12-14 29696]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-07-23 352256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\Microsoft Office Communicator\communicator.exe"="C:\Program Files\Microsoft Office Communicator\communicator.exe:*:Enabled:Communicator"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\V-Gear BEE\VBService.exe"="C:\Program Files\V-Gear BEE\VBService.exe:*:Enabled:V-Gear Bee Service"
"C:\Program Files\FlashGet\flashget.exe"="C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office Communicator\communicator.exe"="C:\Program Files\Microsoft Office Communicator\communicator.exe:*:Enabled:Communicator"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:YServer Module"
"C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\VARPC.EXE"="C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\VARPC.EXE:*:Enabled:Microsoft (R) Visual Studio VSA RPC Event Creator"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Java\jdk1.6.0_05\bin\java.exe"="C:\Program Files\Java\jdk1.6.0_05\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\FlashGet\flashget.exe"="C:\Program Files\FlashGet\flashget.exe:*:Enabled:FlashGet"
"C:\GCTI\Simulator\TestSim\testsim.exe"="C:\GCTI\Simulator\TestSim\testsim.exe:*:Enabled:testsim"
"C:\Program Files\GCTI\Genesys Desktop SIP Endpoint\GDSipEndpoint.exe"="C:\Program Files\GCTI\Genesys Desktop SIP Endpoint\GDSipEndpoint.exe:*:Enabled:GD Sip Endpoint"
"C:\GCTI\LocalControlAgent\lca.exe"="C:\GCTI\LocalControlAgent\lca.exe:*:Enabled:Local Control Agent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe"="C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad39999c-2159-11dd-aab0-00059a3c7800}]
shell\AutoRun\command - qwc.exe
shell\explore\command - qwc.exe
shell\open\command - qwc.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d9fede58-6600-11dd-ab75-0018ded86fd2}]
shell\AutoRun\command - scvhost.exe
shell\Open\command - scvhost.exe

List of files/folders created in the last three months
2008-09-10 12:45:55 ----D---- C:\Program Files\trend micro
2008-09-10 12:45:54 ----D---- C:\rsit
2008-09-10 12:07:58 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-09-10 12:07:49 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-09-10 12:01:43 ----D---- C:\WINDOWS\erdnt
2008-09-10 12:01:24 ----A---- C:\WINDOWS\zip.exe
2008-09-10 12:01:24 ----A---- C:\WINDOWS\swreg.exe
2008-09-10 12:01:24 ----A---- C:\WINDOWS\sed.exe
2008-09-10 12:01:24 ----A---- C:\WINDOWS\Nircmd.exe
2008-09-10 12:01:24 ----A---- C:\WINDOWS\grep.exe
2008-09-10 12:01:23 ----A---- C:\WINDOWS\VFind.exe
2008-09-10 12:01:23 ----A---- C:\WINDOWS\swxcacls.exe
2008-09-10 12:01:23 ----A---- C:\WINDOWS\swsc.exe
2008-09-10 12:01:23 ----A---- C:\WINDOWS\fdsv.exe
2008-09-10 12:01:19 ----D---- C:\ComboFix
2008-09-10 12:01:18 ----A---- C:\WINDOWS\system32\CF23299.exe
2008-09-10 12:00:37 ----D---- C:\QooBox
2008-09-10 11:58:30 ----A---- C:\WINDOWS\system32\CF22750.exe
2008-09-10 10:48:09 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-10 10:47:54 ----D---- C:\Program Files\SUPERAntiSpyware
2008-09-10 10:47:54 ----D---- C:\Documents and Settings\groopali\Application Data\SUPERAntiSpyware.com
2008-09-10 10:47:35 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-09 18:38:40 ----D---- C:\QUARANTINE
2008-09-09 18:26:58 ----D---- C:\Program Files\Common Files\Cisco Systems
2008-09-09 18:26:58 ----A---- C:\WINDOWS\system32\epoPGPsdk.dll.sig
2008-09-09 18:26:58 ----A---- C:\WINDOWS\system32\epoPGPsdk.dll
2008-09-09 18:26:57 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-09 18:26:17 ----D---- C:\Program Files\McAfee
2008-09-09 18:26:17 ----D---- C:\Program Files\Common Files\McAfee
2008-09-09 17:06:08 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-09-09 16:55:00 ----D---- C:\Program Files\CCleaner
2008-09-09 14:52:20 ----D---- C:\Documents and Settings\groopali\Application Data\Malwarebytes
2008-09-09 14:52:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-09 14:52:17 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-09 11:27:38 ----D---- C:\WINDOWS\Prefetch
2008-09-09 09:34:01 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-09-09 09:33:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-09-09 09:33:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-09-09 09:33:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-09-09 09:33:36 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-09-09 09:33:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-09-09 09:33:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-09-09 09:33:20 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-09-09 09:33:15 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-09-09 09:33:09 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-09-09 09:29:40 ----D---- C:\WINDOWS\system32\scripting
2008-09-09 09:29:40 ----D---- C:\WINDOWS\system32\en
2008-09-09 09:29:40 ----D---- C:\WINDOWS\l2schemas
2008-09-09 09:29:39 ----D---- C:\WINDOWS\system32\bits
2008-09-09 09:23:56 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-09-09 09:21:41 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-09-08 13:15:05 ----N---- C:\WINDOWS\system32\wmphoto.dll
2008-09-08 13:15:04 ----N---- C:\WINDOWS\system32\wlanapi.dll
2008-09-08 13:15:03 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2008-09-08 13:15:03 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2008-09-08 13:15:00 ----N---- C:\WINDOWS\system32\tspkg.dll
2008-09-08 13:15:00 ----N---- C:\WINDOWS\system32\tsgqec.dll
2008-09-08 13:14:55 ----N---- C:\WINDOWS\system32\setupn.exe
2008-09-08 13:14:54 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2008-09-08 13:14:54 ----N---- C:\WINDOWS\system32\rasqec.dll
2008-09-08 13:14:53 ----N---- C:\WINDOWS\system32\qutil.dll
2008-09-08 13:14:53 ----N---- C:\WINDOWS\system32\qcliprov.dll
2008-09-08 13:14:53 ----N---- C:\WINDOWS\system32\qagentrt.dll
2008-09-08 13:14:53 ----N---- C:\WINDOWS\system32\qagent.dll
2008-09-08 13:14:53 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2008-09-08 13:14:52 ----N---- C:\WINDOWS\system32\onex.dll
2008-09-08 13:14:49 ----N---- C:\WINDOWS\system32\napstat.exe
2008-09-08 13:14:49 ----N---- C:\WINDOWS\system32\napmontr.dll
2008-09-08 13:14:49 ----N---- C:\WINDOWS\system32\napipsec.dll
2008-09-08 13:14:48 ----N---- C:\WINDOWS\system32\msxml6r.dll
2008-09-08 13:14:48 ----N---- C:\WINDOWS\system32\msxml6.dll
2008-09-08 13:14:48 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2008-09-08 13:14:48 ----N---- C:\WINDOWS\system32\mssha.dll
2008-09-08 13:14:43 ----N---- C:\WINDOWS\system32\mmcperf.exe
2008-09-08 13:14:43 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-09-08 13:14:43 ----N---- C:\WINDOWS\system32\mmcex.dll
2008-09-08 13:14:43 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-09-08 13:14:39 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2008-09-08 13:14:39 ----N---- C:\WINDOWS\system32\kmsvc.dll
2008-09-08 13:14:39 ----N---- C:\WINDOWS\system32\kbdpash.dll
2008-09-08 13:14:39 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2008-09-08 13:14:39 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2008-09-08 13:14:39 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2008-09-08 13:14:35 ----N---- C:\WINDOWS\system32\smtpapi.dll
2008-09-08 13:14:35 ----N---- C:\WINDOWS\system32\rwnh.dll
2008-09-08 13:14:31 ----N---- C:\WINDOWS\system32\eapsvc.dll
2008-09-08 13:14:31 ----N---- C:\WINDOWS\system32\eapqec.dll
2008-09-08 13:14:31 ----N---- C:\WINDOWS\system32\eappprxy.dll
2008-09-08 13:14:31 ----N---- C:\WINDOWS\system32\eapphost.dll
2008-09-08 13:14:31 ----N---- C:\WINDOWS\system32\eappgnui.dll
2008-09-08 13:14:31 ----N---- C:\WINDOWS\system32\eappcfg.dll
2008-09-08 13:14:31 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2008-09-08 13:14:31 ----N---- C:\WINDOWS\system32\eapolqec.dll
2008-09-08 13:14:31 ----A---- C:\WINDOWS\003527_.tmp
2008-09-08 13:14:30 ----N---- C:\WINDOWS\system32\dot3ui.dll
2008-09-08 13:14:30 ----N---- C:\WINDOWS\system32\dot3svc.dll
2008-09-08 13:14:30 ----N---- C:\WINDOWS\system32\dot3msm.dll
2008-09-08 13:14:30 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-09-08 13:14:30 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2008-09-08 13:14:30 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2008-09-08 13:14:30 ----N---- C:\WINDOWS\system32\dot3api.dll
2008-09-08 13:14:29 ----N---- C:\WINDOWS\system32\dimsroam.dll
2008-09-08 13:14:29 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2008-09-08 13:14:29 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2008-09-08 13:14:28 ----N---- C:\WINDOWS\system32\credssp.dll
2008-09-08 13:14:25 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2008-09-08 13:14:25 ----N---- C:\WINDOWS\system32\azroles.dll
2008-09-08 13:14:22 ----N---- C:\WINDOWS\system32\aaclient.dll
2008-09-01 11:38:54 ----D---- C:\Virtual Machines
2008-09-01 10:52:57 ----D---- C:\Documents and Settings\groopali\Application Data\TeamViewer
2008-09-01 10:52:55 ----D---- C:\Program Files\TeamViewer3
2008-08-17 14:38:57 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2008-08-17 14:38:52 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2008-08-17 14:38:47 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$
2008-08-17 14:38:42 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2008-08-17 14:37:01 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-08-17 14:36:46 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2