Hi everyone,
Jabra Pc Suite Of Saasung Software 91 PC Suite for iPhone v.2.9.60.262 PC Suite is a comprehensive application that will enable you to manage data on your iPhone with greater ease, regardless of its model. Download 'Abstract. From the TOL PC, launch the Avaya IP Office User Suite setup.exe in the CDROM drive from an account with administrative privileges.
It appears that I've got the Reveton malware on my machine. It showeed up last night, and I tried the fix at this link:
http://www.bleepingcomputer.com/virus-removal/remove-police-central-e-crime-unit-reveton-ransomware
But it did not appear to work so I am posting here. Here is the DDS log ... I've also attached the attach.txt log as well. Thanks for your help.
DDS (Ver_10-12-12.02) - NTFSx86 NETWORK
Run by John_Hock at 16:10:35.93 on Fri 12/14/2012
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Enterprise 6.1.7600.0.1252.1.1033.18.3572.2921 [GMT -6:00]
AV: McAfee VirusScan Enterprise *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee VirusScan Enterprise Antispyware Module *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
Running Processes
C:Windowssystem32wininit.exe
C:Windowssystem32lsm.exe
C:Windowssystem32svchost.exe -k DcomLaunch
C:Windowssystem32svchost.exe -k RPCSS
C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted
C:Windowssystem32svchost.exe -k netsvcs
C:Windowssystem32svchost.exe -k LocalSystemNetworkRestricted
C:Windowssystem32WUDFHost.exe
C:Windowssystem32svchost.exe -k LocalService
C:Windowssystem32svchost.exe -k NetworkService
C:Windowssystem32svchost.exe -k LocalServiceAndNoImpersonation
C:Windowssystem32svchost.exe -k LocalServiceNoNetwork
C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted
C:WindowsSystem32svchost.exe -k secsvcs
C:WindowsExplorer.EXE
Jabra Software Download
C:Windowssystem32ctfmon.exeC:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Usersjohn_hockDesktopHijackThis.exe
C:Program FilesInternet Exploreriexplore.exe
C:Windowssystem32NOTEPAD.EXE
C:Windowssystem32DllHost.exe
C:Usersjohn_hockDesktopdds.scr
C:Windowssystem32conhost.exe
C:Windowssystem32wbemwmiprvse.exe
Pseudo HJT Report
uStart Page = hxxp://wxp-9lv50c1.aus.amer.dell.com/snp/default.html
uWindow Title = Windows Internet Explorer provided by Dell Client Engineering Team
uInternet Settings,ProxyServer = http=proxy:80;https=proxy:80;ftp=proxy:80;gopher=proxy:80;socks=proxy:80
uInternet Settings,ProxyOverride = 143.166.*;*.dell.co*;163.244.*;10.*;127.*;198.185.237.*;*.corptvl.com;ORL10PLUSWS01.CSERVER;dell.mtgworksphere.com;dellhome.mtgworksphere.com;64.207.0.*;*.tbgfinancial.com;myinvoice.csd.disa.mil;vdc.emc.com;192.0.2.*;*.servigistics.com
mWinlogon: Userinit=c:windowssystem32userinit.exe,'c:program filesmicrosoft application virtualization clientsftdcc.exe'
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:progra~1micros~1office14GROOVEEX.DLL
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:progra~1micros~1office14URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:program filesjavajre6binjp2ssv.dll
uRun: [Sidebar] c:program fileswindows sidebarsidebar.exe /autoRun
uRun: [Steam] 'c:program filessteamSteam.exe' -silent
uRun: [OfficeSyncProcess] 'c:program filesmicrosoft officeoffice14MSOSYNC.EXE'
mRun: [BCSSync] 'c:program filesmicrosoft officeoffice14BCSSync.exe' /DelayServices
mRun: [Communicator] 'c:program filesmicrosoft office communicatorcommunicator.exe' /fromrunkey
mRun: [SoftGridTray] 'c:program filesmicrosoft application virtualization clientSFTTray.exe' /autostart
mRun: [McAfeeUpdaterUI] 'c:program filesmcafeecommon frameworkudaterui.exe' /StartedFromRunKey
mRun: [ShStatEXE] 'c:program filesmcafeevirusscan enterpriseSHSTAT.EXE' /STANDALONE
mRun: [Apoint] c:program filesdelltpadApoint.exe
mRun: [SysTrayApp] c:program filesidtwdmsttray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:windowssystem32NvCpl.dll,NvStartup
mRun: [NVHotkey] rundll32.exe c:windowssystem32nvHotkey.dll,Start
mRun: [SafeBootTrayManager] 'c:program filessafeboot tray managerSbTrayManager.exe'
mRun: [SafeBootTokenWatcher] 'c:program filesmcafeeendpoint encryption for pcSbTokWatch.exe'
mRun: [Adobe ARM] 'c:program filescommon filesadobearm1.0AdobeARM.exe'
StartupFolder: c:usersjohn_h~1appdataroamingmicros~1windowsstartm~1programsstartuprunctf.lnk - c:windowssystem32rundll32.exe
StartupFolder: c:progra~2micros~1windowsstartm~1programsstartupjabrad~1.lnk - c:program filesjabrajabra pc suiteJabraDeviceService.exe
uPolicies-explorer: NoWindowsUpdate = 1 (0x1)
uPolicies-explorer: HideSCAHealth = 1 (0x1)
uPolicies-explorer: DisallowCpl = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
dPolicies-explorer: NoWindowsUpdate = 1 (0x1)
dPolicies-explorer: DisallowCpl = 1 (0x1)
dPolicies-explorer: HideSCAHealth = 1 (0x1)
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:program filesmicrosoft officeoffice14ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:program filesmicrosoft officeoffice14ONBttnIELinkedNotes.dll
Trusted Zone: activationnow.comdell
Trusted Zone: activationnow.comdell-ist
Trusted Zone: convergencenow.eudell
Trusted Zone: dell.combrowsestaging
Trusted Zone: dell.combrowsewip
Trusted Zone: dell.comchat2.ap
Trusted Zone: dell.comchat2.euro
Trusted Zone: dell.comchat2.us
Trusted Zone: dell.comchat4.us
Trusted Zone: dell.comchat5.us
Trusted Zone: dell.comchina
Trusted Zone: dell.comcontent
Trusted Zone: dell.comdcv
Trusted Zone: dell.comdellapjemailresponse.us
Trusted Zone: dell.comdellemailresponse.us
Trusted Zone: dell.comdellemeaemailresponse.us
Trusted Zone: dell.comdellserv.aus.amer
Trusted Zone: dell.comdelta-apj.pen.apac
Trusted Zone: dell.comdelta-emea.lim.emea
Trusted Zone: dell.comdelta.pen.apac
Trusted Zone: dell.comecomm
Trusted Zone: dell.comecomm.apj
Trusted Zone: dell.comecomm.euro
Trusted Zone: dell.comisp-apj.us
Trusted Zone: dell.comisp.us
Trusted Zone: dell.comkcs
Trusted Zone: dell.comkulapjdcssap.kul.apac
Trusted Zone: dell.comlearnwip
Trusted Zone: dell.comOnedellway.us
Trusted Zone: dell.comonespot
Trusted Zone: dell.compbar.us
Trusted Zone: dell.comreviews
Trusted Zone: dell.comwww
Trusted Zone: elementk.comcontenthub
Trusted Zone: force.com*
Trusted Zone: on24.comevent
Trusted Zone: perotsystems.com
Trusted Zone: perotsystems.net
Jabra Pro Pc Suite
Trusted Zone: ps.netTrusted Zone: salesforce.com*
DPF: Shopping.Probe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://ingrammicro.webex.com/client/T27L10NSP11EP14/webex/ieatgpc1.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:program filescommon filesmicrosoft sharedoffice14MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:progra~1micros~1office14GROOVEEX.DLL
LSA: Notification Packages = SbNp scecli
FIREFOX
FF - ProfilePath - c:usersjohn_h~1appdataroamingmozillafirefoxprofileskeood3g2.default
FF - plugin: c:progra~1micros~1office14NPAUTHZ.DLL
FF - plugin: c:progra~1micros~1office14NPSPWRAP.DLL
FF - plugin: c:program filesadobereader 10.0readerairnppdf32.dll
FF - plugin: c:program filesjavajre6binnew_pluginnpdeployJava1.dll
FF - plugin: c:program filesmicrosoft silverlight5.1.10411.0npctrlui.dll
FF - plugin: c:program filesmozilla firefoxpluginsNPcol400.dll
FF - plugin: c:program filesmozilla firefoxpluginsnpCouponPrinter.dll
FF - plugin: c:program filesmozilla firefoxpluginsnpMozCouponPrinter.dll
FF - plugin: c:usersjohn_hockappdatalocallowunitywebplayerloadernpUnity3D32.dll
FF - plugin: c:usersjohn_hockappdataroamingmozillapluginsnpMeetingJoinPluginAOCUser.dll
FF - plugin: c:windowssystem32macromedflashNPSWF32_11_5_502_135.dll
SERVICES / DRIVERS
R0 SafeBoot;SafeBoot;c:windowssystem32driversSafeBoot.sys [2010-6-10 103760]
R0 SBAlg;SBAlg;c:windowssystem32driversSbAlg.sys [2008-8-13 44976]
R0 SbFsLock;SbFsLock;c:windowssystem32driversSbFsLock.sys [2010-6-10 6496]
R1 vwififlt;Virtual WiFi Filter Driver;c:windowssystem32driversvwififlt.sys [2009-7-13 48128]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:windowssystem32driverse1y6032.sys [2009-7-13 214016]
R3 NETw5s32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:windowssystem32driversNETw5s32.sys [2011-3-24 6114816]
S0 mfehidk;McAfee Inc. mfehidk;c:windowssystem32driversmfehidk.sys [2011-1-31 343920]
S1 A2DDA;A2 Direct Disk Access Support Driver;c:usersjohn_hockdesktopemsisoftemergencykitruna2ddax86.sys [2012-12-14 17904]
S1 enstart_;enstart_;c:windowssystem32enstart_.sys [2011-3-25 56704]
S1 RsvLock;RsvLock;c:windowssystem32driversRsvLock.sys [2010-6-10 33328]
S1 SbFlop;SbFlop;c:windowssystem32driversSbFlop.sys [2010-6-10 34480]
S1 SbRegFlt;SbRegFlt;c:windowssystem32driversSbRegFlt.sys [2010-6-10 14664]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:program filescommon filesadobearm1.0armsvc.exe [2012-7-27 63960]
S2 AESTFilters;Andrea ST Filters Service;c:windowssystem32driverstorefilerepositorystwrt.inf_x86_neutral_111ae7bb7f222578AEstSrv.exe [2011-3-24 81920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384]
S2 CmRcService;Configuration Manager Remote Control;c:windowsccmremctrlCmRcService.exe [2012-2-20 442224]
S2 dsiasrv;DSM CM Inventory Agent;c:program filesdellsysmgtdsiabinDsiaSrv32.exe [2012-3-29 149528]
S2 enstart;enstart;c:windowssystem32enstart.exe -s --> c:windowssystem32enstart.exe -s [?]
S2 McAfeeEngineService;McAfee Engine Service;c:program filesmcafeevirusscan enterpriseengineserver.exe [2010-3-25 22816]
S2 McAfeeFramework;McAfee Framework Service;c:program filesmcafeecommon frameworkFrameworkService.exe [2010-10-15 120128]
S2 McShield;McAfee McShield;c:program filesmcafeevirusscan enterprisemcshield.exe [2010-3-25 147472]
S2 McTaskManager;McAfee Task Manager;c:program filesmcafeevirusscan enterprisevstskmgr.exe [2010-5-26 61440]
S2 mfevtp;McAfee Validation Trust Protection Service;c:windowssystem32mfevtps.exe [2011-1-31 70728]
S2 NightWatchman;1E NightWatchman;c:program files1eagentnightwatchmanNwmSvc.exe [2011-2-28 1110360]
S2 NomadBranch;1E Nomad Branch;c:program files1enomadbranchNomadBranch.exe [2012-11-19 1452416]
S2 SafeBootClientManager;SafeBoot Client Manager;c:program filesmcafeeendpoint encryption for pcSbClientManager.exe [2010-6-10 380988]
S2 sftlist;Application Virtualization Client;c:program filesmicrosoft application virtualization clientsftlist.exe [2010-12-27 508264]
S2 WakeUpAgt;1E WakeUp Agent;c:program files1eagentwakeupWakeUpAgt.exe [2011-2-28 426824]
S3 Acceler;Accelerometer Service;c:windowssystem32driversAccelern.sys [2011-3-24 42672]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:windowssystem32macromedflashFlashPlayerUpdateService.exe [2012-3-31 250808]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:windowssystem32driversb57nd60x.sys [2009-7-13 229888]
S3 cvusbdrv;Dell ControlVault;c:windowssystem32driverscvusbdrv.sys [2011-3-24 33832]
S3 dc21x4vm;dc21x4vm;c:windowssystem32driversdc21x4vm.sys [2009-6-10 52224]
S3 DIGITECH;DIGITECH;c:windowssystem32driversDIGITECH.sys [2011-3-24 14848]
Jabra Pc Suite Setup Exe Download Windows 7
S3 Impcd;Impcd;c:windowssystem32driversImpcd.sys [2011-3-24 132352]
S3 JabraDFU;Jabra Bluecore DFU driver;c:windowssystem32driversJabraBcDfuWhqlXPx86.sys [2009-12-1 32624]
S3 lpasvc;Microsoft Policy Platform Local Authority;c:program filesmicrosoft policy platformpolicyHost.exe [2011-12-6 48936]
S3 lppsvc;Microsoft Policy Platform Processor;c:program filesmicrosoft policy platformpolicyHost.exe [2011-12-6 48936]
S3 mfeavfk;McAfee Inc. mfeavfk;c:windowssystem32driversmfeavfk.sys [2011-1-31 91832]
S3 mfebopk;McAfee Inc. mfebopk;c:windowssystem32driversmfebopk.sys [2011-1-31 43288]
S3 mferkdet;McAfee Inc. mferkdet;c:windowssystem32driversmferkdet.sys [2011-1-31 66600]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:program filesmicrosoft officeoffice14GROOVE.EXE [2011-6-12 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:program filesmozilla maintenance servicemaintenanceservice.exe [2012-6-26 113120]
S3 osppsvc;Office Software Protection Platform;c:program filescommon filesmicrosoft sharedofficesoftwareprotectionplatformOSPPSVC.EXE [2010-1-9 4640000]
S3 QCFilterdl;Dell Wireless 5600 (EV-DO-HSPA) Mobile Broadband Mini-Card Composite Device Filter Driver;c:windowssystem32driversqcfilterdl.sys [2011-3-24 5248]
S3 qcfilterdl2k;Gobi 2000 USB Composite Device Filter Driver(413C-8186);c:windowssystem32driversqcfilterdl2k.sys [2011-3-24 5248]
S3 qcusbserdl;Dell USB Device for Legacy Serial Communication;c:windowssystem32driversqcusbserdl.sys [2011-3-24 103680]
S3 qcusbserdl2k;Gobi 2000 USB Device for Legacy Serial Communication(413C-8186);c:windowssystem32driversqcusbserdl2k.sys [2011-3-24 106368]
S3 rimspci;rimspci;c:windowssystem32driversrimspe86.sys [2011-3-24 48640]
S3 risdpcie;risdpcie;c:windowssystem32driversrisdpe86.sys [2011-3-24 47616]
S3 rixdpcie;rixdpcie;c:windowssystem32driversrixdpe86.sys [2011-3-24 38912]
S3 Sftfs;Sftfs;c:windowssystem32driversSftfswin7.sys [2010-12-27 578408]
S3 Sftplay;Sftplay;c:windowssystem32driversSftplaywin7.sys [2010-12-27 194408]
S3 Sftredir;Sftredir;c:windowssystem32driversSftredirwin7.sys [2010-12-27 21864]
S3 Sftvol;Sftvol;c:windowssystem32driversSftvolwin7.sys [2010-12-27 19304]
S3 sftvsa;Application Virtualization Service Agent;c:program filesmicrosoft application virtualization clientsftvsa.exe [2010-12-27 219496]
S3 StorSvc;Storage Service;c:windowssystem32svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 SynthVid;SynthVid;c:windowssystem32driversVMBusVideoM.sys [2009-7-14 19456]
S3 tcm;tcm;c:windowssystem32driverstcm.sys [2011-3-24 12952]
Created Last 30
2012-12-14 15:12:38 -------- d-----w- c:usersjohn_h~1appdatalocalElevatedDiagnostics
2012-12-14 08:08:44 34304 ----a-w- c:windowssystem32atmlib.dll
2012-12-14 08:08:43 295424 ----a-w- c:windowssystem32atmfd.dll
2012-12-14 08:08:23 376832 ----a-w- c:windowssystem32dpnet.dll
2012-12-14 08:06:49 2048 ----a-w- c:windowssystem32tzres.dll
2012-12-14 08:03:07 1638912 ----a-w- c:windowssystem32mshtml.tlb
2012-12-14 08:03:03 44544 ----a-w- c:windowssystem32licmgr10.dll
2012-12-14 02:51:53 197632 ----a-w- c:usersjohn_hockwgsdgsdgdsgsd.exe
2012-12-01 08:15:13 6812136 ----a-w- c:progra~2microsoftwindows defenderdefinition updates{e15e64a4-9f14-4721-8d4e-fa1823816eaf}mpengine.dll
2012-11-16 14:15:31 78336 ----a-w- c:windowssystem32synceng.dll
Find3M
2012-12-13 04:48:43 73656 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl
2012-12-13 04:48:43 697272 ----a-w- c:windowssystem32FlashPlayerApp.exe
2012-11-22 07:43:13 2344960 ----a-w- c:windowssystem32win32k.sys
2012-10-29 19:02:31 188416 ----a-w- c:windowsADDMRemQuery_x86.exe
Jabra Pc Suite Setupexe Download Free
2012-10-27 05:00:40 981504 ----a-w- c:windowssystem32wininet.dll
2012-10-27 03:52:14 386048 ----a-w- c:windowssystem32html.iec
2012-10-04 16:53:53 169984 ----a-w- c:windowssystem32winsrv.dll
2012-10-04 16:49:12 293376 ----a-w- c:windowssystem32KernelBase.dll
2012-10-04 15:00:00 271360 ----a-w- c:windowssystem32conhost.exe
2012-10-04 14:44:29 6144 ---ha-w- c:windowssystem32api-ms-win-security-base-l1-1-0.dll
2012-10-04 14:44:29 4608 ---ha-w- c:windowssystem32api-ms-win-core-threadpool-l1-1-0.dll
2012-10-04 14:44:29 3584 ---ha-w- c:windowssystem32api-ms-win-core-xstate-l1-1-0.dll
Jabra Pc Suite Setup Exe Download Windows 10
2012-10-04 14:44:29 3072 ---ha-w- c:windowssystem32api-ms-win-core-util-l1-1-0.dll
FINISH: 16:13:16.82
Attached Files
- Attach 12-14-12.zip5.21KB1 downloads