This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Malware/Trojan infection on one critical AD Server

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello.

I have now tried at least 5 different spyware programs alongside my installation of Endpoint protection 11.

The Domain controller got infected a while back and when it got infected it were not protected by any antivirus software.
Trying to fix it i installed endpoint protection at once but it did not help.
The Trojan it detected were a version of Trojan.Vundo something.

I have then tried to remove the infection with the following programs.

1. Lavasoft Adaware
2. Spybot
3. Malware bytes Anti Malware
4. SuperAntispyware Free edition
5. Trend online scan (House call)
6. Hijackthis (Removed obvious dll files)
7. CWShredder

I have not performed these in any particular order.

My problem is that i can't seem to get rid of the threat, my temp folder inside documents and settings keep filling up with DWHxxxx.tmp files every second.
And to spice things up, i can't go into the quarantine section of the antivirus program, the program just freezes.

It seems like i have got rid of a few things but it looks like there are a few left, like every time i start the server it pops up 2 windows with the message "could not find Mereposa.dll" and another one i can't remember right now.

The problem is that its an Domain controller and i can't shut it down whenever i want to, but after 17:00 i can do pretty much anything i want to it.

Any suggestion on how to best fix my problem.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:49:02, on 02.03.2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\serverappliance\appmgr.exe
C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\WINDOWS\System32\dns.exe
C:\WINDOWS\system32\serverappliance\elementmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\ismserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\ntfrs.exe
C:\Program Files\OmniBack\bin\omniinet.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\serverappliance\srvcsurg.exe
C:\compaq\survey\Surveyor.EXE
C:\WINDOWS\system32\lserver.exe
C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
C:\Program Files\VMware\VMware Tools\VMwareService.exe
C:\Program Files\Seagate Software\WCS\WebCompServer.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\Program Files\Exchsrvr\bin\emsmta.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cpqteam.exe
C:\Program Files\VMware\VMware Tools\VMwareTray.exe
C:\Program Files\VMware\VMware Tools\VMwareUser.exe
C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cpqteam.exe
C:\Program Files\VMware\VMware Tools\VMwareTray.exe
C:\Program Files\VMware\VMware Tools\VMwareUser.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\WINDOWS\system32\MsiExec.exe
D:\Shares\Data\11 Midlertidige filer\Trojanclean tools\HiJackThis.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CPQTEAM] cpqteam.exe
O4 - HKLM\..\Run: [VMware Tools] C:\Program Files\VMware\VMware Tools\VMwareTray.exe
O4 - HKLM\..\Run: [VMware User Process] C:\Program Files\VMware\VMware Tools\VMwareUser.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [0078a50c] rundll32.exe "C:\WINDOWS\system32\sebosasi.dll",b
O4 - HKLM\..\Run: [CPM034b9690] Rundll32.exe "c:\windows\system32\mereposa.dll",a
O4 - HKLM\..\RunOnce: [Remove Backup Exec System Recovery] cmd /c rmdir /q /s "C:\Program Files\Symantec\Backup Exec System Recovery\"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: []  (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: []  (User 'Default user')
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\\NPssView.dll
O15 - ESC Trusted Zone: http://www.bns.no
O15 - ESC Trusted Zone: http://www.itum.com
O15 - ESC Trusted Zone: http://www.oest.no
O15 - ESC Trusted Zone: http://www.pcworld.no
O15 - ESC Trusted Zone: http://www.ups.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk/6u12-b04/jinstall-6u12-windows-i586-jc.cab?e=1234612530364&h=107bf2e6da78c213ab0253333bff6a90/&filename=jinstall-6u12-windows-i586-jc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = bnsc.local
O17 - HKLM\Software\..\Telephony: DomainName = bnsc.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F52DEB8-54F7-4C9F-A32A-E7D6F5C72C5B}: NameServer = 192.168.1.230,192.168.1.10
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = bnsc.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = bnsc.local
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Backup Exec Remote Agent for Windows Systems (BackupExecAgentAccelerator) - Symantec Corporation - C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Data Protector Inet (omniInet) - Hewlett-Packard - C:\Program Files\OmniBack\bin\omniinet.exe
O23 - Service: Seagate Page Server (pageserver) - Seagate Software, Inc. - C:\Program Files\Seagate Software\WCS\pageserver.exe
O23 - Service: PLServer - PaperLess® as - D:\Program\Visma\Business\DocCenter\PLServer.exe
O23 - Service: Primary Logon (prilogon) - Unknown owner - C:\WINDOWS\system32\logon.exe (file missing)
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: Star Engine (StarEngineService_07) - Unknown owner - C:\Program Files\Microsoft Antigen for Exchange\Engines\x86\SpamCure\bin\StarEngine7.exe (file missing)
O23 - Service: Surveyor - Hewlett-Packard Development Group, L.P. - C:\compaq\survey\Surveyor.EXE
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: HP ProLiant System Shutdown Service (sysdown) - Compaq Computer Corporation - C:\WINDOWS\system32\sysdown.exe
O23 - Service: VMware Converter Service (ufad-p2v) - VMware, Inc. - C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
O23 - Service: VMware Tools Service (VMTools) - VMware, Inc. - C:\Program Files\VMware\VMware Tools\VMwareService.exe
O23 - Service: Seagate Web Component Server (WebCompServer) - Seagate Software, Inc. - C:\Program Files\Seagate Software\WCS\WebCompServer.exe
O23 - Service: Windows Host32 Server Service (WinHost32Svr) - Unknown owner - C:\WINDOWS\security\svchost.exe (file missing)
O23 - Service: Logon Authentication Service (WINVINFO) - Unknown owner - C:\WINDOWS\system32\wbem\wmiservice.exe (file missing)

–
End of file - 8932 bytes
hello

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
You did catch that this is a Windows 2003 server 32 Standard edition? Didn't know that you could install the recovery console to those systems. I think i forgot to mention that in my first post.
ugh this is going to be a headache :)

do this instead then

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    %systemroot%\System32\antiwpa.dll
    %systemroot%\SYSTEM32\wpa.dll
    %systemroot%\setup\scripts\biestart.exe
    %systemroot%\system32\serauth1.dll
    %systemroot%\system32\serauth2.dll
    %systemroot%\system32\sysaudio.sys
    %systemroot%\system32\wdmaud.sys
    %systemroot%\system32\aeaudio.sys

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OTListIt logfile created on: 03.03.2009 14:45:56 - Run 1
OTListIt2 by OldTimer - Version 2.0.3.4 Folder = D:\Shares\Data\11 Midlertidige filer\Trojanclean tools
Windows Server 2003 Standard Edition Service Pack 2 (Version = 5.2.3790) - Type = NTDomainController
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000414 | Country: Norway | Language: NOR | Date Format: dd.MM.yyyy

2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 100,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free
Paging file location(s): c:\pagefile.sys 16 16;d:\pagefile.sys 3000 3000;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 60,00 Gb Total Space | 42,64 Gb Free Space | 71,07% Space Free | Partition Type: NTFS
Drive D: | 100,01 Gb Total Space | 25,91 Gb Free Space | 25,90% Space Free | Partition Type: NTFS
Drive E: | 200,00 Gb Total Space | 131,15 Gb Free Space | 65,58% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BNSDC
Current User Name: administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\serverappliance\appmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\Dfssvc.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\dns.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\serverappliance\elementmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\ismserv.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\System32\llssrv.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ntfrs.exe (Microsoft Corporation)
PRC - C:\Program Files\OmniBack\bin\omniinet.exe (Hewlett-Packard)
PRC - C:\WINDOWS\System32\snmp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\serverappliance\srvcsurg.exe (Microsoft Corporation)
PRC - C:\compaq\survey\Surveyor.EXE (Hewlett-Packard Development Group, L.P.)
PRC - C:\WINDOWS\system32\lserver.exe (Microsoft Corporation)
PRC - C:\Program Files\VMware\VMware Converter\vmware-ufad.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware Tools\VMwareService.exe (VMware, Inc.)
PRC - C:\Program Files\Seagate Software\WCS\WebCompServer.exe (Seagate Software, Inc.)
PRC - C:\Program Files\Exchsrvr\bin\mad.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe (Microsoft Corporation)
PRC - C:\Program Files\Exchsrvr\bin\exmgmt.exe (Microsoft Corporation)
PRC - C:\Program Files\Exchsrvr\bin\store.exe (Microsoft Corporation)
PRC - C:\Program Files\Exchsrvr\bin\emsmta.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - c:\windows\system32\inetsrv\w3wp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\logon.scr (Microsoft Corporation)
PRC - C:\WINDOWS\system32\rdpclip.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\cpqteam.exe (Hewlett-Packard Company)
PRC - C:\Program Files\VMware\VMware Tools\VMwareTray.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware Tools\VMwareUser.exe (VMware, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - D:\Shares\Data\11 Midlertidige filer\Trojanclean tools\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (appmgr [Auto | Running]) – C:\WINDOWS\system32\serverappliance\appmgr.exe (Microsoft Corporation)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (BackupExecAgentAccelerator [Auto | Running]) – C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Dfs [Auto | Running]) – C:\WINDOWS\system32\Dfssvc.exe (Microsoft Corporation)
SRV - (DHCPServer [Auto | Running]) – C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)
SRV - (DNS [Auto | Running]) – C:\WINDOWS\System32\dns.exe (Microsoft Corporation)
SRV - (elementmgr [Auto | Running]) – C:\WINDOWS\system32\serverappliance\elementmgr.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IISADMIN [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IMAP4Svc [Disabled | Stopped]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IsmServ [Auto | Running]) – C:\WINDOWS\System32\ismserv.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LicenseService [Auto | Running]) – C:\WINDOWS\System32\llssrv.exe (Microsoft Corporation)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (LPDSVC [Auto | Running]) – C:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)
SRV - (MSExchangeES [On_Demand | Stopped]) – C:\Program Files\Exchsrvr\bin\events.exe (Microsoft Corporation)
SRV - (MSExchangeIS [Auto | Running]) – C:\Program Files\Exchsrvr\bin\store.exe (Microsoft Corporation)
SRV - (MSExchangeMGMT [Auto | Running]) – C:\Program Files\Exchsrvr\bin\exmgmt.exe (Microsoft Corporation)
SRV - (MSExchangeMTA [Auto | Running]) – C:\Program Files\Exchsrvr\bin\emsmta.exe (Microsoft Corporation)
SRV - (MSExchangeSA [Auto | Running]) – C:\Program Files\Exchsrvr\bin\mad.exe (Microsoft Corporation)
SRV - (MSExchangeSRS [Disabled | Stopped]) – C:\Program Files\Exchsrvr\bin\srsmain.exe (Microsoft Corporation)
SRV - (MSSEARCH [Auto | Running]) – C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NntpSvc [Disabled | Stopped]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (NtFrs [Auto | Running]) – C:\WINDOWS\system32\ntfrs.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (omniInet [Auto | Running]) – C:\Program Files\OmniBack\bin\omniinet.exe (Hewlett-Packard)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (pageserver [Auto | Stopped]) – C:\Program Files\Seagate Software\WCS\pageserver.exe (Seagate Software, Inc.)
SRV - (PLServer [On_Demand | Stopped]) – D:\Program\Visma\Business\DocCenter\PLServer.exe (PaperLess® as)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (POP3Svc [Disabled | Stopped]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (prilogon [Auto | Stopped]) – File not found
SRV - (RESvc [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (RSoPProv [On_Demand | Stopped]) – C:\WINDOWS\system32\RSoPProv.exe (Microsoft Corporation)
SRV - (sacsvr [On_Demand | Stopped]) – C:\WINDOWS\system32\sacsvr.dll (Microsoft Corporation)
SRV - (SMTPSVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SNMP [Auto | Running]) – C:\WINDOWS\System32\snmp.exe (Microsoft Corporation)
SRV - (srvcsurg [Auto | Running]) – C:\WINDOWS\system32\serverappliance\srvcsurg.exe (Microsoft Corporation)
SRV - (StarEngineService_07 [On_Demand | Stopped]) – File not found
SRV - (Surveyor [Auto | Running]) – C:\compaq\survey\Surveyor.EXE (Hewlett-Packard Development Group, L.P.)
SRV - (sysdown [On_Demand | Stopped]) – C:\WINDOWS\system32\sysdown.exe (Compaq Computer Corporation)
SRV - (TermServLicensing [Auto | Running]) – C:\WINDOWS\system32\lserver.exe (Microsoft Corporation)
SRV - (TrkSvr [Disabled | Stopped]) – C:\WINDOWS\system32\trksvr.dll (Microsoft Corporation)
SRV - (Tssdis [Disabled | Stopped]) – C:\WINDOWS\System32\tssdis.exe (Microsoft Corporation)
SRV - (ufad-p2v [Auto | Running]) – C:\Program Files\VMware\VMware Converter\vmware-ufad.exe (VMware, Inc.)
SRV - (UMWdf [On_Demand | Stopped]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (uploadmgr [On_Demand | Stopped]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (Visma Sync Exchange [Disabled | Stopped]) – C:\Program Files\Visma\Outlook\Service\VBusSyncSvc.exe ()
SRV - (VMTools [Auto | Running]) – C:\Program Files\VMware\VMware Tools\VMwareService.exe (VMware, Inc.)
SRV - (W3SVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (WebCompServer [Auto | Running]) – C:\Program Files\Seagate Software\WCS\WebCompServer.exe (Seagate Software, Inc.)
SRV - (WinHost32Svr [Auto | Stopped]) – File not found
SRV - (WINVINFO [Auto | Stopped]) – File not found

========== Driver Services (SafeList) ==========

DRV - (adpu160m [Boot | Running]) – C:\WINDOWS\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (ati2mpad [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ati2mpad.sys (ATI Technologies Inc.)
DRV - (ClusDisk [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ClusDisk.sys (Microsoft Corporation)
DRV - (cpqarry2 [Boot | Running]) – C:\WINDOWS\system32\drivers\cpqarry2.sys (Compaq Computer Corporation)
DRV - (cpqasm2 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\cpqasm2.sys (Compaq Computer Corporation)
DRV - (CpqCiDrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CpqCiDrv.sys (Hewlett-Packard Company)
DRV - (CPQCISSE [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CPQCISSE.sys (Hewlett-Packard Company)
DRV - (cpqcissm [Boot | Running]) – C:\WINDOWS\system32\drivers\cpqcissm.sys (Hewlett-Packard Company)
DRV - (CPQPHP [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\CPQPHP.SYS (Hewlett-Packard Company)
DRV - (CPQTeam [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\cpqteam.sys (Hewlett-Packard Company)
DRV - (CPQTeamMP [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\cpqteam.sys (Hewlett-Packard Company)
DRV - (DfsDriver [Boot | Running]) – C:\WINDOWS\system32\drivers\Dfs.sys (Microsoft Corporation)
DRV - (dlttape [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\dlttape.sys (Microsoft Corporation)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EXIFS [Auto | Running]) – C:\WINDOWS\system32\drivers\exifs.sys (Microsoft Corporation)
DRV - (hgfs [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\hgfs.sys (VMware, Inc.)
DRV - (LGTO_Sync [Auto | Running]) – C:\WINDOWS\system32\Drivers\lgtosync.sys (VMware, Inc.)
DRV - (LsiCsb6 [Boot | Running]) – C:\WINDOWS\system32\drivers\LsiCsb6.sys (LSI Logic Corporation.)
DRV - (MegaIDE [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\MegaIDE.sys (LSI Logic Corporation)
DRV - (NAVENG [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090301.024\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090301.024\NAVEX15.SYS (Symantec Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (q57w2k [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\q57xp32.sys (Hewlett-Packard Company)
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (symc810 [Boot | Running]) – C:\WINDOWS\System32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Boot | Running]) – C:\WINDOWS\System32\drivers\symc8xx.sys (LSI Logic)
DRV - (symmpi [Boot | Stopped]) – C:\WINDOWS\system32\DRIVERS\symmpi.sys (LSI Logic)
DRV - (sym_hi [Boot | Running]) – C:\WINDOWS\System32\drivers\sym_hi.sys (LSI Logic)
DRV - (sysmgmt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sysmgmt.sys (Compaq Computer Corporation)
DRV - (tmcomm [Auto | Running]) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (VMMEMCTL [Auto | Running]) – C:\Program Files\VMware\VMware Tools\Drivers\memctl\vmmemctl.sys ()
DRV - (vmmouse [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\vmmouse.sys (VMware, Inc.)
DRV - (vmscsi [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\vmscsi.sys (VMware, Inc.)
DRV - (vmxnet [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\vmxnet.sys (VMware, Inc.)
DRV - (vmx_svga [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\vmx_svga.sys (VMware, Inc.)
DRV - (VSP [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\vsp.sys (Symantec Corporation)
DRV - (vstor2-p2v30 [Auto | Running]) – C:\Program Files\VMware\VMware Converter\vstor2-p2v30.sys (VMware, Inc.)
DRV - (WLBS [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\wlbs.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> %SystemRoot%\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009.02.14 03:18:58 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed] -> %ProgramFiles%\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2009.02.14 12:54:21 00,000,000 | —D | M]

O1 HOSTS File: (289942 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10057 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CPQTEAM] cpqteam.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VMware Tools] C:\Program Files\VMware\VMware Tools\VMwareTray.exe (VMware, Inc.)
O4 - HKLM..\Run: [VMware User Process] C:\Program Files\VMware\VMware Tools\VMwareUser.exe (VMware, Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2\SSUPDATE.EXE Software\SUPERAntiSpyware.com\SUPERAntiSpyware File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ShowSuperHidden = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O12 - Plugin for: .NPSSView - C:\Program Files\Seagate Software\Viewers\ActiveXViewer\NPssView.dll (Seagate Software)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {027CDB6E-0000-0000-0000-000000000000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8138.1724074074 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{6F52DEB8-54F7-4C9F-A32A-E7D6F5C72C5B}\\NameServer = 192.168.1.230,192.168.1.10
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O29 - HKLM SecurityProviders - ( pwdssp.dll) - C:\WINDOWS\system32\pwdssp.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1

========== Files/Folders - Created Within 30 Days ==========

[2009.03.02 14:41:23 | 00,006,824 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate
[2009.02.25 08:06:05 | 01,107,115 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009.02.19 12:47:13 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009.02.19 12:40:01 | 00,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009.02.19 12:39:59 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009.02.19 12:39:59 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2009.02.19 12:38:37 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2009.02.15 17:33:26 | 00,173,456 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Administrator\Desktop\FixVundo.exe
[2009.02.14 12:54:55 | 00,000,000 | —D | C] – C:\WINDOWS\Sun
[2009.02.14 12:54:17 | 00,000,000 | —D | C] – C:\Program Files\Java
[2009.02.14 12:52:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Sun
[2009.02.14 03:14:54 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009.02.14 03:14:53 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009.02.14 03:14:53 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009.02.14 03:14:53 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009.02.14 03:14:53 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009.02.14 03:14:53 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009.02.14 03:14:53 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009.02.14 03:14:30 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2009.02.14 02:46:08 | 00,000,000 | —D | C] – C:\WINDOWS\SoftwareDistribution
[2009.02.14 02:44:09 | 21,244,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009.02.13 10:28:20 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2009.02.13 10:28:12 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009.02.13 10:28:12 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.02.13 10:28:09 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009.02.13 10:28:07 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009.02.13 10:28:07 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009.02.12 22:58:50 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009.02.12 22:56:20 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[2009.03.03 04:07:48 | 00,002,912 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
[2009.03.03 02:08:30 | 01,699,094 | -H– | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2009.03.03 02:00:00 | 00,000,332 | —- | M] () – C:\WINDOWS\tasks\izucvlbf.job
[2009.03.03 01:35:48 | 01,281,078 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009.03.03 01:35:48 | 00,982,972 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009.03.03 01:35:48 | 00,267,632 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009.03.03 01:31:29 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009.03.03 01:30:59 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009.03.03 01:30:51 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009.03.02 22:58:00 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009.03.02 14:49:14 | 00,006,824 | —- | M] () – C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate
[2009.03.01 01:20:00 | 00,000,240 | —- | M] () – C:\WINDOWS\tasks\Shutdown.job
[2009.02.25 12:51:30 | 00,004,861 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009.02.24 13:17:23 | 00,000,187 | —- | M] () – C:\WINDOWS\hpbafd.ini
[2009.02.19 12:40:01 | 00,000,780 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009.02.16 11:43:22 | 00,289,942 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009.02.15 17:33:27 | 00,173,456 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Administrator\Desktop\FixVundo.exe
[2009.02.14 03:28:49 | 00,266,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009.02.13 10:28:12 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009.02.13 03:43:28 | 00,292,053 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2009.02.13 03:41:51 | 00,292,053 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090213-034328.backup
[2009.02.13 03:28:29 | 00,000,933 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Spybot - Search & Destroy.lnk
[2009.02.11 20:56:18 | 21,244,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009.02.11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009.02.11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

========== LOP Check ==========

[2009.02.19 12:39:59 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Administrator\Application Data
[2008.12.08 14:15:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Adobe
[2004.08.09 11:25:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AdobeUM
[2009.01.16 15:14:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Clue
[2006.10.26 11:48:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Download Manager
[2008.09.30 14:06:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Help
[2003.10.31 03:09:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Identities
[2004.06.01 12:03:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2009.02.13 10:28:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2009.01.30 11:06:53 | 00,000,000 | –SD | M] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2009.02.14 12:52:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Sun
[2009.02.19 12:39:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2008.07.18 08:39:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Symantec
[2008.01.19 11:54:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\VMware
[2009.03.03 01:30:44 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008.03.29 15:20:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007.08.24 12:39:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2009.03.02 14:32:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009.02.13 10:28:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009.01.30 10:33:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009.01.30 10:59:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2009.01.19 15:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009.02.19 12:47:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009.03.02 14:49:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008.01.19 18:11:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VMware
[2009.03.02 22:58:00 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2003.03.25 13:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009.03.03 02:00:00 | 00,000,332 | —- | M] () – C:\WINDOWS\Tasks\izucvlbf.job
[2009.03.03 01:30:59 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009.02.06 18:00:00 | 00,032,654 | —- | M] () – C:\WINDOWS\Tasks\SchedLgU.Txt
[2009.03.01 01:20:00 | 00,000,240 | —- | M] () – C:\WINDOWS\Tasks\Shutdown.job

========== Purity Check ==========


========== Custom Scans ==========



========== Net Services ==========

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\NetSvcs

AppMgmt - C:\WINDOWS\System32\appmgmts.dll - (Microsoft Corporation)
AudioSrv - C:\WINDOWS\System32\audiosrv.dll - (Microsoft Corporation)
Browser - C:\WINDOWS\System32\browser.dll - (Microsoft Corporation)
CryptSvc - C:\WINDOWS\System32\cryptsvc.dll - (Microsoft Corporation)
DMServer - C:\WINDOWS\System32\dmserver.dll - (Microsoft Corporation)
EventSystem - C:\WINDOWS\system32\es.dll - (Microsoft Corporation)
HidServ - C:\WINDOWS\System32\hidserv.dll - File not found
Ias - -
Iprip - -
Irmon - -
LanmanServer - C:\WINDOWS\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - C:\WINDOWS\System32\wkssvc.dll - (Microsoft Corporation)
Messenger - C:\WINDOWS\System32\msgsvc.dll - (Microsoft Corporation)
Netman - C:\WINDOWS\System32\netman.dll - (Microsoft Corporation)
Nla - C:\WINDOWS\System32\mswsock.dll - (Microsoft Corporation)
Ntmssvc - C:\WINDOWS\system32\ntmssvc.dll - (Microsoft Corporation)
NWCWorkstation - -
Nwsapagent - -
Rasauto - C:\WINDOWS\System32\rasauto.dll - (Microsoft Corporation)
Rasman - C:\WINDOWS\System32\rasmans.dll - (Microsoft Corporation)
Remoteaccess - C:\WINDOWS\System32\mprdim.dll - (Microsoft Corporation)
Sacsvr - C:\WINDOWS\system32\sacsvr.dll - (Microsoft Corporation)
Schedule - C:\WINDOWS\system32\schedsvc.dll - (Microsoft Corporation)
Seclogon - C:\WINDOWS\System32\seclogon.dll - (Microsoft Corporation)
SENS - C:\WINDOWS\system32\sens.dll - (Microsoft Corporation)
Sharedaccess - C:\WINDOWS\system32\ipnathlp.dll - (Microsoft Corporation)
Themes - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
TrkWks - C:\WINDOWS\system32\trkwks.dll - (Microsoft Corporation)
TrkSvr - C:\WINDOWS\system32\trksvr.dll - (Microsoft Corporation)
WZCSVC - C:\WINDOWS\System32\wzcsvc.dll - (Microsoft Corporation)
Wmi - C:\WINDOWS\System32\advapi32.dll - (Microsoft Corporation)
WmdmPmSp - -
winmgmt - C:\WINDOWS\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
wuauserv - C:\WINDOWS\system32\wuauserv.dll - (Microsoft Corporation)
BITS - C:\WINDOWS\system32\qmgr.dll - (Microsoft Corporation)
ShellHWDetection - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
uploadmgr - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
WmdmPmSN - C:\WINDOWS\system32\mspmsnsv.dll - (Microsoft Corporation)
xmlprov - C:\WINDOWS\System32\xmlprov.dll - (Microsoft Corporation)
AeLookupSvc - C:\WINDOWS\System32\aelupsvc.dll - (Microsoft Corporation)
helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)

======= End Net Services =========




========== SafeBoot-Minimal Settings ==========

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\

AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corporation)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corporation)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corporation)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corporation)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corporation)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
Netlogon - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
Primary disk - Driver Group
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
sacsvr - %SystemRoot%\system32\sacsvr.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
System Bus Extender - Driver Group
vds - %SystemRoot%\System32\vds.exe - (Microsoft Corporation)
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
wd.sys - Driver
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

======= End SafeBoot-Minimal =========



========== SafeBoot-Network Settings ==========

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\

AFD - %SystemRoot%\System32\drivers\afd.sys - (Microsoft Corporation)
AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
Browser - %SystemRoot%\System32\browser.dll - (Microsoft Corporation)
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
Dhcp - %SystemRoot%\System32\dhcpcsvc.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corporation)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corporation)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corporation)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corporation)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corporation)
DnsCache - %SystemRoot%\System32\dnsrslvr.dll - (Microsoft Corporation)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
ip6fw.sys - %SystemRoot%\system32\drivers\ip6fw.sys - (Microsoft Corporation)
ipnat.sys - %SystemRoot%\system32\DRIVERS\ipnat.sys - (Microsoft Corporation)
LanmanServer - %SystemRoot%\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - %SystemRoot%\System32\wkssvc.dll - (Microsoft Corporation)
LmHosts - %SystemRoot%\System32\lmhsvc.dll - (Microsoft Corporation)
Messenger - %SystemRoot%\System32\msgsvc.dll - (Microsoft Corporation)
NDIS - %SystemRoot%\System32\drivers\ndis.sys - (Microsoft Corporation)
NDIS Wrapper - Driver Group
Ndisuio - %SystemRoot%\system32\DRIVERS\ndisuio.sys - (Microsoft Corporation)
NetBIOS - %SystemRoot%\system32\DRIVERS\netbios.sys - (Microsoft Corporation)
NetBIOSGroup - Driver Group
NetBT - %SystemRoot%\system32\DRIVERS\netbt.sys - (Microsoft Corporation)
NetDDEGroup - Driver Group
Netlogon - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
NetMan - %SystemRoot%\System32\netman.dll - (Microsoft Corporation)
Network - Driver Group
NetworkProvider - Driver Group
NtLmSsp - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
PNP_TDI - Driver Group
Primary disk - Driver Group
rdpcdd.sys - %SystemRoot%\System32\DRIVERS\RDPCDD.sys - (Microsoft Corporation)
rdpdd.sys - %SystemRoot%\System32\rdpdd.dll - (Microsoft Corporation)
rdpwd.sys - %SystemRoot%\System32\drivers\rdpwd.sys - (Microsoft Corporation)
rdsessmgr - %SystemRoot%\system32\sessmgr.exe - (Microsoft Corporation)
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
sacsvr - %SystemRoot%\system32\sacsvr.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
sharedaccess - %SystemRoot%\system32\ipnathlp.dll - (Microsoft Corporation)
Streams Drivers - Driver Group
System Bus Extender - Driver Group
Tcpip - %SystemRoot%\system32\DRIVERS\tcpip.sys - (Microsoft Corporation)
TDI - Driver Group
tdpipe.sys - %SystemRoot%\System32\drivers\tdpipe.sys - (Microsoft Corporation)
tdtcp.sys - %SystemRoot%\System32\drivers\tdtcp.sys - (Microsoft Corporation)
termservice - %SystemRoot%\System32\termsrv.dll - (Microsoft Corporation)
UploadMgr - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
vds - %SystemRoot%\System32\vds.exe - (Microsoft Corporation)
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
WZCSVC - %SystemRoot%\System32\wzcsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E972-E325-11CE-BFC1-08002BE10318} - Net
{4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
{4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
{4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

======= End SafeBoot-Network =========



========== ActiveX Components ==========

{08B0E5C0-4FCB-11CF-AAA5-00401C608500}: Java (Sun)
{10072CEC-8CC1-11D1-986E-00A0C955B42F}: Vector Graphics Rendering (VML)
{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}: NetShow
{22d6f312-b0f6-11d0-94ab-0080c74c7e95}: Microsoft Windows Media Player 6.4
{283807B5-2C60-11D0-A31D-00AA00B92C03}: DirectAnimation
{2C7339CF-2B09-4501-B3F3-F3508C9228ED}: %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
{36BBA8D2-CA5C-4847-81CC-4F807DD86C91}: %SystemRoot%\system32\regsvr32.exe /s /n /i:IEUpdateUser urlmon.dll
{36f8ec70-c29a-11d1-b5c7-0000f8051515}: Dynamic HTML Data Binding for Java
{3af36230-a269-11d1-b5bf-0000f8051515}: Offline Browsing Pack
{3bf42070-b3b1-11d1-b5c5-0000f8051515}: Uniscribe
{4278c270-a269-11d1-b5bf-0000f8051515}: Advanced Authoring
{44BBA840-CC51-11CF-AAFA-00AA00B6015C}: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
{44BBA842-CC51-11CF-AAFA-00AA00B6015B}: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
{44BBA848-CC51-11CF-AAFA-00AA00B6015C}: DirectShow
{44BBA855-CC51-11CF-AAFA-00AA00B6015C}: Microsoft DirectX
{44BBA855-CC51-11CF-AAFA-00AA00B6015F}: DirectDrawEx
{45ea75a0-a269-11d1-b5bf-0000f8051515}: Internet Explorer Help
{4CF07653-FE0F-11D4-A548-0090278A1BB8}: .NET Framework
{4f216970-c90c-11d1-b5c7-0000f8051515}: DirectAnimation Java Classes
{4f645220-306d-11d2-995d-00c04f98bbc9}: Microsoft Windows Script 5.6
{5A8D6EE0-3E18-11D0-821E-444553540000}: ICW
{5f3c70b3-ac2f-432c-8f9c-1624df61f54f}: Microsoft Data Access Components KB870669
{5fd399c0-a70a-11d1-9948-00c04f98bbc9}: Internet Explorer Setup Tools
{630b1da0-b465-11d1-9948-00c04f98bbc9}: Browsing Enhancements
{6BF52A52-394A-11d3-B153-00C04F79FAA6}: Microsoft Windows Media Player
{6D69F546-C1AF-4049-AE9E-28627B91D3F5}: %SystemRoot%\system32\regsvr32.exe /s /n /i:IEUpdateAdmin urlmon.dll
{6fab99d0-bab8-11d1-994a-00c04f98bbc9}: MSN Site Access
{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}: .NET Framework
{73FA19D0-2D75-11D2-995D-00C04F98BBC9}: Web Folders
{7790769C-0471-11d2-AF11-00C04FA35D02}: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
{89820200-ECBD-11cf-8B85-00AA005B4340}: regsvr32.exe /s /n /i:U shell32.dll
{89820200-ECBD-11cf-8B85-00AA005B4383}: C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
{89B4C1CD-B018-4511-B0A1-5476DBF70820}: C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
{9381D8F2-0288-11D0-9501-00AA00B911A5}: Dynamic HTML Data Binding
{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}: %SystemRoot%\system32\rundll32.exe iesetup.dll,IEHardenAdmin
{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}: %SystemRoot%\system32\rundll32.exe iesetup.dll,IEHardenUser
{abcdf74f-9a64-4e6e-b8eb-6e5a41de6550}: Help and Support Center
{B508B3F1-A24A-32C0-B310-85786919EF28}: .NET Framework
{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}: .NET Framework
{C9E9A340-D1F1-11D0-821E-444553540600}: Internet Explorer Core Fonts
{CC2A9BA0-3BDD-11D0-821E-444553540000}: Task Scheduler
{D27CDB6E-AE6D-11CF-96B8-444553540000}: Reg Error: Value error.
{de5aed00-a4bf-11d1-9948-00c04f98bbc9}: HTML Help
{E92B03AB-B707-11d2-9CBD-0000F87A369E}: Active Directory Service Interface
<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}: C:\WINDOWS\system32\ieudinit.exe
>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}: C:\WINDOWS\inf\unregmp2.exe /ShowWMP
>{26923b43-4d38-484f-9b9e-de460746276c}: C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
>{60B49E34-C7CC-11D0-8953-00A0C90347FF}: RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS: RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}:

======= End ActiveX =========


< %systemroot%\System32\antiwpa.dll >

< %systemroot%\SYSTEM32\wpa.dll >

< %systemroot%\setup\scripts\biestart.exe >

< %systemroot%\system32\serauth1.dll >

< %systemroot%\system32\serauth2.dll >

< %systemroot%\system32\sysaudio.sys >

< %systemroot%\system32\wdmaud.sys >

< %systemroot%\system32\aeaudio.sys >
< End of report >
OTListIt Extras logfile created on: 03.03.2009 14:45:56 - Run 1
OTListIt2 by OldTimer - Version 2.0.3.4 Folder = D:\Shares\Data\11 Midlertidige filer\Trojanclean tools
Windows Server 2003 Standard Edition Service Pack 2 (Version = 5.2.3790) - Type = NTDomainController
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000414 | Country: Norway | Language: NOR | Date Format: dd.MM.yyyy

2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 100,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free
Paging file location(s): c:\pagefile.sys 16 16;d:\pagefile.sys 3000 3000;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 60,00 Gb Total Space | 42,64 Gb Free Space | 71,07% Space Free | Partition Type: NTFS
Drive D: | 100,01 Gb Total Space | 25,91 Gb Free Space | 25,90% Space Free | Partition Type: NTFS
Drive E: | 200,00 Gb Total Space | 131,15 Gb Free Space | 65,58% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BNSDC
Current User Name: administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
"FirewallDisableNotify" = 0
"UacDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe:*:Enabled:Backup Exec Remote Agent for Windows Systems (Symantec Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe:*:Enabled:Backup Exec Remote Agent for Windows Systems (Symantec Corporation)
C:\WINDOWS\System32\msddns.exe:*:Enabled:Dns Filter Service File not found

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02A021B8-EBCF-4A46-89AA-45B4C1C567D6}" = Visma Business 4.60
"{12725678-5034-4D6D-B033-4F683A21CFAC}" = Softerra LDAP Administrator 2008.1
"{21B90409-8000-11D3-8CFE-0150048383C9}" = Microsoft Application Error Reporting
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 12
"{3B410500-1802-488E-9EF1-4B11992E0440}" = VMware Tools
"{3CE06D54-72B1-44B2-AB60-E4277EC80EF4}" = Microsoft XML Parser
"{42FF18A5-EE1C-11D3-825F-00805FD6C6D4}" = Hewlett-Packard Survey Utility
"{671E4E4D-4798-4F66-9C9E-C5762E73179E}" = Microsoft XML Parser
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7DE7DD1F-6E17-4AF7-8D93-42AAEB2406AA}" = Clue 8.0
"{90120000-0010-0414-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Norwegian (Bokmål)) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0015-0414-0000-0000000FF1CE}" = Microsoft Office Access MUI (Norwegian (Bokmål)) 2007
"{90120000-0015-0414-0000-0000000FF1CE}_PROPLUS_{7C86509D-1CB7-48BE-813E-6585CD97626B}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0414-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Norwegian (Bokmål)) 2007
"{90120000-0016-0414-0000-0000000FF1CE}_PROPLUS_{7C86509D-1CB7-48BE-813E-6585CD97626B}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0414-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Norwegian (Bokmål)) 2007
"{90120000-0018-0414-0000-0000000FF1CE}_PROPLUS_{7C86509D-1CB7-48BE-813E-6585CD97626B}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0414-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Norwegian (Bokmål)) 2007
"{90120000-0019-0414-0000-0000000FF1CE}_PROPLUS_{7C86509D-1CB7-48BE-813E-6585CD97626B}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0414-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Norwegian (Bokmål)) 2007
"{90120000-001A-0414-0000-0000000FF1CE}_PROPLUS_{7C86509D-1CB7-48BE-813E-6585CD97626B}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0414-0000-0000000FF1CE}" = Microsoft Office Word MUI (Norwegian (Bokmål)) 2007
"{90120000-001B-0414-0000-0000000FF1CE}_PROPLUS_{7C86509D-1CB7-48BE-813E-6585CD97626B}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0414-0000-0000000FF1CE}" = Microsoft Office Proof (Norwegian (Bokmål)) 2007
"{90120000-001F-0414-0000-0000000FF1CE}_PROPLUS_{3FE135E8-2B21-44ED-99CA-87C782C4F5F7}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0814-0000-0000000FF1CE}" = Microsoft Office Proof (Norwegian (Nynorsk)) 2007
"{90120000-001F-0814-0000-0000000FF1CE}_PROPLUS_{63BBC1EA-E390-403D-BFDE-B53E1D23FF46}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0414-0000-0000000FF1CE}" = Microsoft Office Proofing (Norwegian (Bokmål)) 2007
"{90120000-0044-0414-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Norwegian (Bokmål)) 2007
"{90120000-0044-0414-0000-0000000FF1CE}_PROPLUS_{7C86509D-1CB7-48BE-813E-6585CD97626B}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0414-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Norwegian (Bokmål)) 2007
"{90120000-006E-0414-0000-0000000FF1CE}_PROPLUS_{3CC75FEB-8AA6-43F5-958E-0D074633CB2E}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91B90409-8000-11D3-8CFE-0150048383C9}" = Microsoft Application Error Reporting
"{9503FDAA-B8F5-4E50-8DEB-AD136DB14964}" = Visma Business printer driver
"{95D3658E-D526-4891-822D-B2A6C3DED9CE}" = SIW 1.68
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A34AC564-B4A3-4D45-B969-403BC39F0E6A}" = Microsoft .NET Framework 1.1 – Device Update 4.0
"{A4D04B1A-DCF1-4C8C-8FFE-07D145812742}" = VMware Converter
"{A4F8313B-0E21-478B-B289-BFB7736CA7AA}" = Remote Administration Tools
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B24B3C4C-FE9D-4457-8F60-6ADCE696DB8B}" = Visma Business Outlook
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C0774966-2821-11D3-B32D-00A0C9DA500E}" = Seagate Crystal Reports Developer Edition
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8DB770E-53AF-420D-B375-1C4832A1A660}" = Symantec Backup Exec Remote Agent for Windows Systems
"{CA3553E0-191B-4E2F-AD3C-82E33CB9D4E4}" = Microsoft Group Policy Management Console with SP1
"{CACFEA37-607D-4FF9-9CC5-792BDFE404F4}" = HP OpenView Storage Data Protector A.06.00
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D7BBCE3B-2237-48DC-850A-F51E8AAF7E4C}" = SetupDALMeta
"{F07F0BCD-5C6D-4499-9F05-6ED747078A72}" = Windows Support Tools
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"9161A261-6ABE-4668-BBFA-AD06B3F642CF" = Microsoft Exchange
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"ConvertX" = ConvertX
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"JRE 1.2.2" = Java 2 Runtime Environment Standard Edition v1.2.2
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Payment module for Visma Installation 5.6 July 2003_is1" = Converter 5.6
"PROPLUS" = Microsoft Office Professional Plus 2007
"Remote Agent for Windows Servers" = Symantec Backup Exec Remote Agent for Windows Systems
"ST6UNST #1" = Business Document
"ST6UNST #2" = Business Document (C:\Program Files\Business Document\)
"Visma Business Report Center" = Visma Business Report Center
"WIC" = Windows Imaging Component
"Windows Server 2003 Service Pack" = Windows Server 2003 Service Pack 2
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 13.02.2009 21:49:10 | Computer Name = BNSDC | Source = Userenv | ID = 1068
Description = Windows ended GPO processing because the computer shut down or the
user logged off.

Error - 13.02.2009 21:49:12 | Computer Name = BNSDC | Source = MSExchangeAL | ID = 8026
Description = LDAP Bind was unsuccessful on directory BNSDC for distinguished name
''. Directory returned error:[0x34] Unavailable. For more information, click http://www.microsoft.com/contentredirect.asp.

Error - 13.02.2009 21:49:18 | Computer Name = BNSDC | Source = MSExchangeAL | ID = 8026
Description = LDAP Bind was unsuccessful on directory BNSDC for distinguished name
''. Directory returned error:[0x51] Server Down. For more information, click http://www.microsoft.com/contentredirect.asp.

Error - 13.02.2009 21:49:19 | Computer Name = BNSDC | Source = MSExchangeAL | ID = 8026
Description = LDAP Bind was unsuccessful on directory BNSDC for distinguished name
''. Directory returned error:[0x51] Server Down. For more information, click http://www.microsoft.com/contentredirect.asp.

Error - 13.02.2009 21:49:19 | Computer Name = BNSDC | Source = MSExchangeAL | ID = 8250
Description = The Win32 API call 'DsGetDCNameW' returned error code [0x862] The
specified component could not be found in the configuration information. The service
could not be initialized. Make sure that the operating system was installed properly.


For
more information, click http://www.microsoft.com/contentredirect.asp.

Error - 13.02.2009 22:00:49 | Computer Name = BNSDC | Source = ESE | ID = 476
Description = Information Store (1732) First Storage Group: The database page read
from the file "E:\Exchange Database\priv2.edb" at offset 12854386688 (0x00000002fe2e6000)
(database page 3138277 (0x2FE2E5)) for 4096 (0x00001000) bytes failed verification
because it contains no page data. The read operation will fail with error -1019
(0xfffffc05). If this condition persists then please restore the database from
a previous backup. This problem is likely due to faulty hardware. Please contact
your hardware vendor for further assistance diagnosing the problem. For more information,
click http://www.microsoft.com/contentredirect.asp.

Error - 13.02.2009 22:27:34 | Computer Name = BNSDC | Source = MSExchangeAL | ID = 8026
Description = LDAP Bind was unsuccessful on directory bnsdc.bnsc.local for distinguished
name ''. Directory returned error:[0x34] Unavailable. For more information, click
http://www.microsoft.com/contentredirect.asp.

Error - 13.02.2009 22:27:40 | Computer Name = BNSDC | Source = MSExchangeAL | ID = 8026
Description = LDAP Bind was unsuccessful on directory bnsdc.bnsc.local for distinguished
name ''. Directory returned error:[0x51] Server Down. For more information, click
http://www.microsoft.com/contentredirect.asp.

Error - 13.02.2009 22:27:41 | Computer Name = BNSDC | Source = MSExchangeAL | ID = 8026
Description = LDAP Bind was unsuccessful on directory bnsdc.bnsc.local for distinguished
name ''. Directory returned error:[0x51] Server Down. For more information, click
http://www.microsoft.com/contentredirect.asp.

Error - 13.02.2009 22:27:41 | Computer Name = BNSDC | Source = MSExchangeAL | ID = 8250
Description = The Win32 API call 'DsGetDCNameW' returned error code [0x862] The
specified component could not be found in the configuration information. The service
could not be initialized. Make sure that the operating system was installed properly.


For
more information, click http://www.microsoft.com/contentredirect.asp.

[ Directory Service Events ]
Error - 13.02.2009 19:51:55 | Computer Name = BNSDC | Source = NTDS Replication | ID = 2426919
Description =

Error - 13.02.2009 19:51:58 | Computer Name = BNSDC | Source = NTDS Replication | ID = 2426919
Description =

Error - 13.02.2009 20:00:53 | Computer Name = BNSDC | Source = NTDS Replication | ID = 2426919
Description =

Error - 13.02.2009 20:00:53 | Computer Name = BNSDC | Source = NTDS Replication | ID = 2426919
Description =

[ DNS Server Events ]
Error - 25.01.2009 10:15:32 | Computer Name = BNSDC | Source = DNS | ID = 4004
Description = The DNS server was unable to complete directory service enumeration
of zone 1.168.192.in-addr.arpa. This DNS server is configured to use information
obtained from Active Directory for this zone and is unable to load the zone without
it. Check that the Active Directory is functioning properly and repeat enumeration
of
the zone. The extended error debug information (which may be empty) is "". The event
data contains the error.

Error - 25.01.2009 10:15:32 | Computer Name = BNSDC | Source = DNS | ID = 4004
Description = The DNS server was unable to complete directory service enumeration
of zone bnsc.local. This DNS server is configured to use information obtained from
Active Directory for this zone and is unable to load the zone without it. Check
that
the Active Directory is functioning properly and repeat enumeration of the zone.
The
extended error debug information (which may be empty) is "". The event data contains
the error.

Error - 12.02.2009 22:36:33 | Computer Name = BNSDC | Source = DNS | ID = 4015
Description = The DNS server has encountered a critical error from the Active Directory.
Check
that the Active Directory is functioning properly. The extended error debug information
(which may be empty) is "". The event data contains the error.

Error - 12.02.2009 22:36:33 | Computer Name = BNSDC | Source = DNS | ID = 4004
Description = The DNS server was unable to complete directory service enumeration
of zone .. This DNS server is configured to use information obtained from Active
Directory
for this zone and is unable to load the zone without it. Check that the Active
Directory is functioning properly and repeat enumeration of the zone. The extended
error debug information (which may be empty) is "". The event data contains the
error.

Error - 12.02.2009 22:36:33 | Computer Name = BNSDC | Source = DNS | ID = 4004
Description = The DNS server was unable to complete directory service enumeration
of zone _msdcs.bnsc.local. This DNS server is configured to use information obtained
from Active Directory for this zone and is unable to load the zone without it.
Check that the Active Directory is functioning properly and repeat enumeration of
the zone. The extended error debug information (which may be empty) is "". The event
data contains the error.

Error - 12.02.2009 22:36:33 | Computer Name = BNSDC | Source = DNS | ID = 4004
Description = The DNS server was unable to complete directory service enumeration
of zone 1.168.192.in-addr.arpa. This DNS server is configured to use information
obtained from Active Directory for this zone and is unable to load the zone without
it. Check that the Active Directory is functioning properly and repeat enumeration
of
the zone. The extended error debug information (which may be empty) is "". The event
data contains the error.

Error - 12.02.2009 22:36:33 | Computer Name = BNSDC | Source = DNS | ID = 4004
Description = The DNS server was unable to complete directory service enumeration
of zone 10.168.192.in-addr.arpa. This DNS server is configured to use information
obtained from Active Directory for this zone and is unable to load the zone without
it. Check that the Active Directory is functioning properly and repeat enumeration
of
the zone. The extended error debug information (which may be empty) is "". The event
data contains the error.

Error - 12.02.2009 22:36:33 | Computer Name = BNSDC | Source = DNS | ID = 4004
Description = The DNS server was unable to complete directory service enumeration
of zone 11.168.192.in-addr.arpa. This DNS server is configured to use information
obtained from Active Directory for this zone and is unable to load the zone without
it. Check that the Active Directory is functioning properly and repeat enumeration
of
the zone. The extended error debug information (which may be empty) is "". The event
data contains the error.

Error - 12.02.2009 22:36:33 | Computer Name = BNSDC | Source = DNS | ID = 4004
Description = The DNS server was unable to complete directory service enumeration
of zone bnsc.local. This DNS server is configured to use information obtained from
Active Directory for this zone and is unable to load the zone without it. Check
that
the Active Directory is functioning properly and repeat enumeration of the zone.
The
extended error debug information (which may be empty) is "". The event data contains
the error.

Error - 13.02.2009 19:51:40 | Computer Name = BNSDC | Source = DNS | ID = 6702
Description = DNS server has updated its own host (A) records. In order to ensure
that its DS-integrated peer DNS servers are able to replicate with this server,
an attempt was made to update them with the new records through dynamic update.
An error was encountered during this update, the record data is the error code. If
this DNS server does not have any DS-integrated peers, then this error should be
ignored. If this DNS server's Active Directory replication partners do not have
the correct IP address(es) for this server, they will be unable to replicate with
it. To ensure proper replication: 1) Find this server's Active Directory replication
partners that run the DNS server. 2) Open DnsManager and connect in turn to each
of the replication partners. 3) On each server, check the host (A record) registration
for THIS server. 4) Delete any A records that do NOT correspond to IP addresses
of this server. 5) If there are no A records for this server, add at least one A
record corresponding to an address on this server, that the replication partner can
contact.
(In other words, if there multiple IP addresses for this DNS server, add at least
one that is on the same network as the Active Directory DNS server you are updating.)

6)
Note, that is not necessary to update EVERY replication partner. It is only necessary
that the records are fixed up on enough replication partners so that every server
that replicates with this server will receive (through replication) the new data.

[ System Events ]
Error - 22.02.2009 19:30:55 | Computer Name = BNSDC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
symmpi

Error - 27.02.2009 10:08:20 | Computer Name = BNSDC | Source = DCOM | ID = 10001
Description = Unable to start a DCOM Server: {A1987DB8-9F0D-47D1-80C9-DFCE76260841}
as /. The error: "%87" Happened while starting this command: "C:\Program Files\Symantec\Symantec
Endpoint Protection\SavUI.exe" -Embedding

Error - 27.02.2009 10:10:30 | Computer Name = BNSDC | Source = DCOM | ID = 10010
Description = The server {A1987DB8-9F0D-47D1-80C9-DFCE76260841} did not register
with DCOM within the required timeout.

Error - 01.03.2009 18:54:32 | Computer Name = BNSDC | Source = Kerberos | ID = 5
Description = The kerberos client received a KRB_AP_ERR_TKT_NYV error from the server
PCS014$. This indicates that the ticket used against that server is not yet valid
(in relationship to that server time). Contact your system administrator to make
sure the client and server times are in sync, and that the KDC in realm BNSC.LOCAL
is in sync with the KDC in the client realm.

Error - 02.03.2009 09:46:58 | Computer Name = BNSDC | Source = Service Control Manager | ID = 7031
Description = The Symantec Endpoint Protection service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in 10000
milliseconds: Restart the service.

Error - 02.03.2009 09:56:55 | Computer Name = BNSDC | Source = Service Control Manager | ID = 7000
Description = The SASDIFSV service failed to start due to the following error: %%183

Error - 02.03.2009 20:32:29 | Computer Name = BNSDC | Source = Service Control Manager | ID = 7000
Description = The Network Load Balancing service failed to start due to the following
error: %%1058

Error - 02.03.2009 20:32:29 | Computer Name = BNSDC | Source = Service Control Manager | ID = 7001
Description = The Seagate Page Server service depends on the Network DDE service
which failed to start because of the following error: %%1058

Error - 02.03.2009 20:32:29 | Computer Name = BNSDC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
symmpi

Error - 02.03.2009 22:50:47 | Computer Name = BNSDC | Source = Kerberos | ID = 5
Description = The kerberos client received a KRB_AP_ERR_TKT_NYV error from the server
PCS014$. This indicates that the ticket used against that server is not yet valid
(in relationship to that server time). Contact your system administrator to make
sure the client and server times are in sync, and that the KDC in realm BNSC.LOCAL
is in sync with the KDC in the client realm.


< End of report >
hello

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    SRV - (WinHost32Svr [Auto | Stopped]) – File not found
    SRV - (WINVINFO [Auto | Stopped]) – File not found
    O4 - HKCU..\Run: [] File not found
    [2009.03.03 02:00:00 | 00,000,332 | —- | M] () – C:\WINDOWS\Tasks\izucvlbf.job
    
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    C:\WINDOWS\System32\msddns.exe=-
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
Thanks, will go through those steps asap and post a reply as soon as the server has been restarted. Ughh…it sucks to have an infection on a critical server

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI