This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Possible Vundo Virus

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I posted in the Windows forum concerning a strange thing happening on this computer. Tallin, suggested I post the HJT here and see if there is a virus problem.

Thanks in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:27:22 PM, on 4/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sportscitycyclery.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ED61-23EB-11D2-B92F-008048FDD814} (MeadCo ScriptX Advanced) - https://www.polarisdealers.com/Files/Controls/Print/smsx.cab
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} (RRAAINAX_02.RRAAINAX) - http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1237393633515
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O20 - AppInit_DLLs: tnrlod.dll
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
O24 - Desktop Component 0: (no name) - http://www.kawasaki.com/Adplanner2/UploadF…7F_83223_th.jpg

–
End of file - 5968 bytes
Hi SportsCityIT,

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


There is an unidentified file we need to check out.

Open windows explorer (right click the Start button and click Explore)

At the top of windows explorer, click tools, folder options, click the
view tab
  • check Display the contents of system folders
  • check Show hidden files and folders
  • uncheck "Hide extensions for known file types" box
  • uncheck "Hide protecting operating system files" box
Click apply, click ok



At the top of Windows Explorer, click Search


Click on
  • All Files and Folders
  • In the top box, copy and paste this filename
    tnrlod.dll
  • Set the Look in: box to Local Hard Drives(x) (x denotes your hard drives)
  • Click More advanced options
  • Make sure the Type of file is set to (All Files and folders)
  • Check Search System Files
  • Check Search Hidden Files and Folders
  • Check Search Subfolders
  • Click Search
Please note the location(s) of the file and submit the entire filepath to VirScan.

For example c:\windows\system32\tnrlod.dll

To use VirScan
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Use the browse button to navigate to the file you located during the search
  • click open, the file should now be in the "Suspicious files to scan" box on the top of the page:
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Please post back with
  • VirScan results
  • new HJT log

Thanks
Hi,

I followed your directions step by step, 3 times. The search did not find the file in question. However, as you can see in the HJT log, it's still there? :pullhair:

What do we do now?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:49:34 PM, on 4/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sportscitycyclery.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ED61-23EB-11D2-B92F-008048FDD814} (MeadCo ScriptX Advanced) - https://www.polarisdealers.com/Files/Controls/Print/smsx.cab
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} (RRAAINAX_02.RRAAINAX) - http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1237393633515
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O20 - AppInit_DLLs: tnrlod.dll
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
O24 - Desktop Component 0: (no name) - http://www.kawasaki.com/Adplanner2/UploadF…7F_83223_th.jpg

–
End of file - 5759 bytes
Hi sportsCityIt,

Let's have a look with another tool.


Download OTListIt2 to your desktop.
  • Double click on OTList2.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

No need for a Hijackthis log this time.
Here is the OTLisit log. I'll post the "extras" log in a different post.

Thanks,

OTListIt logfile created on: 4/6/2009 8:11:08 AM - Run 6
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Documents and Settings\Sales\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

991.48 Mb Total Physical Memory | 624.87 Mb Available Physical Memory | 63.02% Memory free
2.33 Gb Paging File | 2.08 Gb Available in Paging File | 89.13% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.38 Gb Total Space | 51.08 Gb Free Space | 74.70% Space Free | Partition Type: NTFS
Drive D: | 36.21 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SALES1
Current User Name: Sales
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\carpserv.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE (Logitech, Inc.)
PRC - C:\Documents and Settings\Sales\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (HP Port Resolver [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE (Hewlett-Packard Company)
SRV - (HP Status Server [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE (Hewlett-Packard Company)
SRV - (InCDsrv [Auto | Running]) – C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG)
SRV - (LBTServ [On_Demand | Stopped]) – C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (sdAuxService [On_Demand | Stopped]) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (sdCoreService [On_Demand | Stopped]) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (ThreatFire [On_Demand | Stopped]) – C:\Program Files\Spyware Doctor\TFEngine\TFService.exe (PC Tools)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (GLOGODrv [Auto | Running]) – C:\WINDOWS\System32\drivers\GLOGODrv.sys (Microsoft Corporation)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (IKFileSec [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ikfilesec.sys (PCTools Research Pty Ltd.)
DRV - (IKSysFlt [On_Demand | Running]) – C:\WINDOWS\system32\drivers\iksysflt.sys (PCTools Research Pty Ltd.)
DRV - (IKSysSec [On_Demand | Running]) – C:\WINDOWS\system32\drivers\iksyssec.sys (PCTools Research Pty Ltd.)
DRV - (InCDfs [Disabled | Running]) – C:\WINDOWS\System32\drivers\InCDfs.sys (Nero AG)
DRV - (InCDPass [System | Running]) – C:\WINDOWS\System32\DRIVERS\InCDPass.sys (Nero AG)
DRV - (incdrm [System | Running]) – C:\WINDOWS\System32\drivers\InCDrm.sys (Nero AG)
DRV - (LHidFilt [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (LMouFilt [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (NWADI [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBModem [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort2 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (pctfw2 [System | Running]) – C:\WINDOWS\system32\drivers\pctfw2.sys (PC Tools)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (SiSide [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\siside.sys (Silicon Integrated Systems Corp.)
DRV - (sisidex [Boot | Running]) – C:\WINDOWS\system32\drivers\sisidex.sys (Windows ® 2000 DDK provider)
DRV - (SiSkp [System | Running]) – C:\WINDOWS\system32\DRIVERS\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (SISNIC [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\sisnic.sys (SiS Corporation)
DRV - (sisperf [Boot | Running]) – C:\WINDOWS\system32\drivers\sisperf.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\SiSRaid.sys (Windows ® 2000 DDK provider)
DRV - (StreamDispatcher [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\strmdisp.sys (Conexant Systems, Inc.)
DRV - (TfFsMon [Boot | Running]) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon [On_Demand | Running]) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfSysMon [Boot | Running]) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sportscitycyclery.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CARPService] carpserv.exe (Conexant Systems, Inc.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE (Logitech, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Sales\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 25 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {1663ED61-23EB-11D2-B92F-008048FDD814} https://www.polarisdealers.com/Files/Controls/Print/smsx.cab (MeadCo ScriptX)
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB (RRAAINAX_02.RRAAINAX)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1237393633515 (WUWebControl Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (tnrlod.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 () - http://www.kawasaki.com/Adplanner2/UploadF…7F_83223_th.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AF209DB6-29BB-4F8B-84E8-2056EA999610} - Reg Error: Key error. File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{11f20c7c-ebbc-11dd-a3ee-001485bc611f}\Shell\AutoRun\command - "" = E:\DmailerBackup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/04/06 08:03:03 | 00,499,200 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Sales\Desktop\OTListIt2.exe
[2009/04/06 08:02:04 | 00,662,639 | —- | C] () – C:\Documents and Settings\Sales\Desktop\OTScanIt2.exe
[2009/04/02 16:27:09 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/02 15:36:42 | 00,681,171 | —- | C] () – C:\Documents and Settings\All Users\Documents\md_report.xml
[2009/04/01 14:28:05 | 00,001,768 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/04/01 08:55:52 | 00,001,720 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Logitech Mouse and Keyboard Settings.lnk
[2009/03/31 11:16:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\bd_rem_tool
[2009/03/30 10:44:39 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/03/30 10:44:31 | 00,000,806 | —- | C] () – C:\Documents and Settings\Sales\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/03/30 10:44:25 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/03/30 10:41:00 | 00,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2009/03/24 12:55:34 | 00,020,480 | —- | C] () – C:\Documents and Settings\Sales\My Documents\March 24.doc
[2009/03/18 11:13:53 | 00,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2009/03/18 10:52:13 | 01,307,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6.dll
[2009/03/18 10:52:13 | 01,307,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2009/03/18 10:52:13 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2009/03/18 10:52:13 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2009/03/18 10:52:08 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\irbus.sys
[2009/03/18 10:52:08 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2009/03/18 10:52:08 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2009/03/18 10:52:08 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2009/03/18 10:52:05 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2009/03/18 10:52:04 | 00,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2009/03/18 10:52:04 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\credssp.dll
[2009/03/18 10:52:04 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2009/03/18 10:52:03 | 00,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2009/03/18 10:52:03 | 00,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2009/03/18 10:52:03 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2009/03/18 10:52:03 | 00,132,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3svc.dll
[2009/03/18 10:52:03 | 00,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappcfg.dll
[2009/03/18 10:52:03 | 00,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2009/03/18 10:52:03 | 00,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2009/03/18 10:52:03 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2009/03/18 10:52:03 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2009/03/18 10:52:03 | 00,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2009/03/18 10:52:03 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappprxy.dll
[2009/03/18 10:52:03 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2009/03/18 10:52:03 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2009/03/18 10:52:03 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapsvc.dll
[2009/03/18 10:52:03 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapolqec.dll
[2009/03/18 10:52:03 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3api.dll
[2009/03/18 10:52:03 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsntfy.dll
[2009/03/18 10:52:03 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3dlg.dll
[2009/03/18 10:52:02 | 00,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2009/03/18 10:52:02 | 00,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2009/03/18 10:52:02 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2009/03/18 10:52:02 | 00,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2009/03/18 10:52:02 | 00,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2009/03/18 10:52:02 | 00,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2009/03/18 10:52:02 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2009/03/18 10:52:02 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kmsvc.dll
[2009/03/18 10:52:02 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2009/03/18 10:52:02 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2009/03/18 10:52:02 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2009/03/18 10:52:02 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2009/03/18 10:52:02 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2009/03/18 10:52:02 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2009/03/18 10:52:02 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2009/03/18 10:52:01 | 00,412,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\photometadatahandler.dll
[2009/03/18 10:52:01 | 00,291,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagentrt.dll
[2009/03/18 10:52:01 | 00,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2009/03/18 10:52:01 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2009/03/18 10:52:01 | 00,144,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\onex.dll
[2009/03/18 10:52:01 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qutil.dll
[2009/03/18 10:52:01 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2009/03/18 10:52:01 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rasqec.dll
[2009/03/18 10:52:01 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2009/03/18 10:52:01 | 00,050,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tspkg.dll
[2009/03/18 10:52:01 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2009/03/18 10:52:01 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vidcap.ax
[2009/03/18 10:52:00 | 00,712,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecs.dll
[2009/03/18 10:52:00 | 00,346,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecsext.dll
[2009/03/18 10:52:00 | 00,276,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmphoto.dll
[2009/03/18 10:52:00 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2009/03/18 10:51:59 | 00,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2009/03/18 10:51:59 | 00,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2009/03/18 10:51:58 | 00,000,000 | —D | C] – C:\WINDOWS\System32\en
[2009/03/18 10:51:58 | 00,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2009/03/18 10:50:02 | 00,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2009/03/18 10:48:41 | 00,042,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\agp440.sys
[2009/03/18 10:48:40 | 00,044,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\agpcpq.sys
[2009/03/18 10:48:40 | 00,042,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\alim1541.sys
[2009/03/18 10:48:39 | 00,101,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthpan.sys
[2009/03/18 10:48:39 | 00,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2009/03/18 10:48:39 | 00,046,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\gagp30kx.sys
[2009/03/18 10:48:39 | 00,037,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthmodem.sys
[2009/03/18 10:48:39 | 00,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2009/03/18 10:48:39 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidbth.sys
[2009/03/18 10:48:39 | 00,019,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidir.sys
[2009/03/18 10:48:39 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthusb.sys
[2009/03/18 10:48:39 | 00,017,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthenum.sys
[2009/03/18 10:48:38 | 00,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2009/03/18 10:48:38 | 00,059,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rfcomm.sys
[2009/03/18 10:48:38 | 00,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2009/03/18 10:48:38 | 00,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2009/03/18 10:48:37 | 00,121,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbvideo.sys
[2009/03/18 10:48:37 | 00,042,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\viaagp.sys
[2009/03/18 10:48:37 | 00,014,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\wacompen.sys
[2009/03/18 10:48:37 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usb8023x.sys
[2009/03/18 10:48:37 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\sffp_mmc.sys
[2009/03/18 10:48:37 | 00,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2009/03/18 10:44:51 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2009/03/18 10:27:58 | 00,023,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wuapi.dll.mui
[2009/03/14 12:02:50 | 00,354,816 | —- | C] () – C:\Documents and Settings\All Users\Documents\Tomos 2008 Price List II.pub
[2009/03/14 11:00:06 | 00,561,152 | —- | C] () – C:\Documents and Settings\All Users\Documents\Tomos 2009 Price List.pub
[2009/03/09 16:07:51 | 00,048,640 | —- | C] () – C:\Documents and Settings\All Users\Documents\Showroom Hang Tag Vulcan 500.pub

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/04/06 07:52:29 | 00,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/06 07:52:05 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/06 07:52:03 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/04 12:03:47 | 00,018,593 | —- | M] () – C:\Documents and Settings\Sales\Desktop\MSNBC.url
[2009/04/04 12:03:30 | 00,002,521 | —- | M] () – C:\Documents and Settings\Sales\Desktop\Microsoft Office Outlook 2003.lnk
[2009/04/04 11:50:55 | 00,000,268 | —- | M] () – C:\Documents and Settings\Sales\Desktop\POLARIS .url
[2009/04/04 11:39:24 | 00,000,205 | —- | M] () – C:\Documents and Settings\Sales\Desktop\SCC WEBSITE.url
[2009/04/04 10:07:47 | 00,002,497 | —- | M] () – C:\Documents and Settings\Sales\Desktop\WORD.lnk
[2009/04/03 09:22:33 | 00,000,251 | —- | M] () – C:\Documents and Settings\Sales\Desktop\HONDA IN.url
[2009/04/02 15:33:22 | 00,681,171 | —- | M] () – C:\Documents and Settings\All Users\Documents\md_report.xml
[2009/04/02 15:00:32 | 00,000,299 | —- | M] () – C:\Documents and Settings\Sales\Desktop\GE HONDA.url
[2009/04/02 12:42:19 | 00,000,252 | —- | M] () – C:\Documents and Settings\Sales\Desktop\TRP MT.url
[2009/04/01 15:33:08 | 00,000,247 | —- | M] () – C:\Documents and Settings\Sales\Desktop\Midwest Motor Express, Inc..url
[2009/04/01 14:28:05 | 00,001,768 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/04/01 08:55:52 | 00,001,726 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
[2009/04/01 08:55:52 | 00,001,720 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Logitech Mouse and Keyboard Settings.lnk
[2009/03/31 11:45:55 | 00,081,920 | —- | M] () – C:\Documents and Settings\Sales\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/31 09:12:06 | 00,000,305 | —- | M] () – C:\Documents and Settings\Sales\Desktop\GE POL PA.url
[2009/03/30 10:44:31 | 00,000,806 | —- | M] () – C:\Documents and Settings\Sales\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/03/26 16:49:56 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/26 16:49:50 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/24 15:32:51 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Sales\Desktop\OTListIt2.exe
[2009/03/24 12:55:35 | 00,020,480 | —- | M] () – C:\Documents and Settings\Sales\My Documents\March 24.doc
[2009/03/24 11:58:15 | 00,662,639 | —- | M] () – C:\Documents and Settings\Sales\Desktop\OTScanIt2.exe
[2009/03/24 11:30:51 | 00,000,262 | —- | M] () – C:\Documents and Settings\Sales\Desktop\ADVANCEDESK.url
[2009/03/19 17:12:39 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/18 14:01:11 | 00,318,744 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/18 11:18:16 | 00,510,896 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/18 11:18:16 | 00,430,606 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/18 11:18:16 | 00,071,630 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/18 10:48:21 | 00,250,048 | RHS- | M] () – C:\ntldr
[2009/03/10 11:26:10 | 00,002,495 | —- | M] () – C:\Documents and Settings\Sales\Desktop\EXCEL.lnk
[2009/03/09 14:49:21 | 00,048,640 | —- | M] () – C:\Documents and Settings\All Users\Documents\Showroom Hang Tag Vulcan 500.pub
[2009/03/07 13:21:55 | 00,212,135 | —- | M] () – C:\Documents and Settings\Sales\Desktop\mv70.pdf

========== LOP Check ==========

[2008/11/18 11:06:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/04/01 14:27:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/11/13 09:42:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2006/04/10 12:07:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2007/04/19 08:19:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/02/26 09:33:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/10/24 09:22:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2008/04/10 08:43:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogiShrd
[2008/02/04 09:43:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logitech
[2008/11/18 11:06:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/07/29 15:01:41 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/08/16 12:13:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NOS
[2007/11/20 15:15:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/24 09:52:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2008/10/02 13:03:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/04/06 08:03:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/04/10 10:50:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/02/24 13:14:14 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Sales\Application Data
[2009/02/24 13:14:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Adobe
[2008/08/15 09:47:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\AdobeUM
[2009/02/24 13:14:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2006/11/21 10:19:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Google
[2007/10/24 09:23:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\HP
[2006/04/07 16:36:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Identities
[2008/04/10 08:39:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\InstallShield
[2008/02/04 09:45:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Logitech
[2006/04/14 12:59:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Macromedia
[2008/11/18 11:06:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Malwarebytes
[2009/04/01 08:55:05 | 00,000,000 | –SD | M] – C:\Documents and Settings\Sales\Application Data\Microsoft
[2007/11/20 15:47:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\OfficeUpdate12
[2008/11/18 09:51:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\PC Tools
[2008/09/03 14:16:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Smith Micro
[2007/02/16 16:54:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Sun
[2008/09/24 10:00:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Symantec
[2008/07/29 15:01:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Windows Desktop Search
[2008/08/12 15:00:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Sales\Application Data\Windows Search
[2004/08/04 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/06 07:52:05 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 3638 bytes -> C:\Documents and Settings\Sales\Desktop\MSN.com.url:favicon
@Alternate Data Stream - 3574 bytes -> C:\Documents and Settings\Sales\Desktop\EQUIFAX.url:favicon
@Alternate Data Stream - 3574 bytes -> C:\Documents and Settings\Sales\Desktop\ADVANCEDESK.url:favicon
@Alternate Data Stream - 318 bytes -> C:\Documents and Settings\Sales\Desktop\K-DEALER.url:favicon
@Alternate Data Stream - 15086 bytes -> C:\Documents and Settings\Sales\Desktop\MSNBC.url:favicon
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 1406 bytes -> C:\Documents and Settings\Sales\Desktop\Welcome to TRDealer.com.url:favicon
@Alternate Data Stream - 1406 bytes -> C:\Documents and Settings\Sales\Desktop\TRP MT.url:favicon
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 1150 bytes -> C:\Documents and Settings\Sales\Desktop\POLARIS .url:favicon
< End of report >
Here is the second log you asked for.

Thanks,

OTListIt Extras logfile created on: 4/6/2009 8:04:07 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Documents and Settings\Sales\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

991.48 Mb Total Physical Memory | 643.16 Mb Available Physical Memory | 64.87% Memory free
2.33 Gb Paging File | 2.09 Gb Available in Paging File | 89.68% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.38 Gb Total Space | 51.08 Gb Free Space | 74.71% Space Free | Partition Type: NTFS
Drive D: | 36.21 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SALES1
Current User Name: Sales
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
D:\setup\HPZNET01.EXE:*:Enabled:hpznet01.exe File not found
D:\setup\hppapd.exe:*:Enabled:hppapd.exe File not found
D:\setup\HPNTWKEXE.EXE:*:Enabled:hpntwkexe.exe File not found
C:\WINDOWS\system32\msmgs.exe:*:Enabled:Explorer File not found

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08498FF9-6C9B-4FC2-8DE1-BD98C89CC220}" = RaidApplication
"{0BF5FBE7-3907-4A1F-9E48-8B66E52850D6}" = TrayApp
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0CDD5599-836A-4650-8BE7-F33D8D915A0D}" = dj6980
"{0F40754C-F1FD-43df-B73E-9DA38399CDD6}" = hpf_ProductContext
"{14A67CE0-4F30-4607-885B-43EE27BAC746}" = Readme
"{190D0C6E-C8A7-4019-8FB5-FD041EC1F2D2}" = Mobile Broadband Drivers
"{1E1F1E70-14D8-4380-8652-BD1A895A7D65}" = Status
"{24BEBF2E-73F3-4599-840B-EDC612CCDD0D}" = Destinations
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}" = Unload
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3BC341BD-3736-45F0-B0E0-5664792AC528}" = HP Care Pack Core
"{3D10E608-A4A3-40AD-B91C-6D963BBD91D5}" = LP6980_Help
"{4041C245-7099-4C96-9738-5EBC23827B3C}" = BufferChm
"{414C803A-6115-4DB6-BD4E-FD81EA6BC71C}" = Product_SF_Min_QFolder
"{4BE53DB2-C1F2-44D1-A9AB-1630BA7F2AF1}" = SolutionCenter
"{561D20B1-766E-4EA5-8A1D-B7357D903673}" = hppIOFiles
"{5E55F3F1-2210-4CC9-A761-9E4B818D9FA7}" = HP Care Pack Products
"{6441FECE-0E73-4326-81BF-68503E897820}" = CorePLS_Min_QFolder
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{69E6C13B-CF6B-47A6-B7A5-77FE82B2CB40}" = hppFonts
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7783A050-23C5-11DA-6784-01412D6F18BE}" = Frazer Software for the Used Car Dealer
"{7ADE9F27-A175-447F-A4B4-B05FA82735E1}" = HP Deskjet 6900 series
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{CB1F3886-AE9F-46fb-8325-6B0718989285}" = dj_taplugin
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D7CAE58E-26DE-49B7-A75D-EAEDF76726BE}" = HP Photosmart Essential
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DEBB2986-15B0-4D28-95FA-5C966A396589}" = HPProductAssistant
"{EC2715CE-C182-483C-84CC-81D7D914CF14}" = WebReg
"{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}" = HP Software Update
"{EDABA4A8-8B7E-488A-A85C-17406C1C62CA}" = LP6980Trb
"{EDAE4F43-833C-443B-8DB5-129F897DF3E8}" = hppWebRegMM
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F38D0F99-1BFC-47AB-AC36-8D9D43700CFB}" = hppManualsP2015
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"EasyLoan" = EasyLoan
"ERUNT_is1" = ERUNT 1.1j
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 6.0
"HP LaserJet P2015" = HP LaserJet P2015 Series 1.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center and Imaging Support Tools 6.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SiS VGA Driver" = SiS VGA Utilities
"SiSLan" = SiS 900 PCI Fast Ethernet Adapter Driver
"Spyware Doctor" = Spyware Doctor 6.0
"SpywareBlaster_is1" = SpywareBlaster 4.1
"VZAccess Manager" = VZAccess Manager
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/13/2009 4:55:10 PM | Computer Name = SALES1 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.3156, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/13/2009 4:57:50 PM | Computer Name = SALES1 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.3156, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/14/2009 2:00:09 PM | Computer Name = SALES1 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.3156, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/14/2009 2:00:11 PM | Computer Name = SALES1 | Source = Application Hang | ID = 1001
Description = Fault bucket 452615105.

Error - 3/14/2009 2:01:05 PM | Computer Name = SALES1 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.3156, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/17/2009 10:08:10 AM | Computer Name = SALES1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 3/24/2009 12:39:34 PM | Computer Name = SALES1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 4/1/2009 10:10:12 AM | Computer Name = SALES1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 4/3/2009 3:18:40 PM | Computer Name = SALES1 | Source = Application Error | ID = 1000
Description = Faulting application TFService.exe, version 3.8.6.6, faulting module
TFE.dll, version 3.8.6.6, fault address 0x000082c3.

Error - 4/3/2009 3:18:45 PM | Computer Name = SALES1 | Source = Application Error | ID = 1001
Description = Fault bucket 825502486.

[ System Events ]
Error - 3/14/2009 10:51:11 AM | Computer Name = SALES1 | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{CED5D5C5-3EBC-4AB0-821E-F3AA19A6805E}. The
backup browser is stopping.

Error - 3/14/2009 11:33:58 AM | Computer Name = SALES1 | Source = Service Control Manager | ID = 7034
Description = The HP Port Resolver service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/17/2009 1:59:20 PM | Computer Name = SALES1 | Source = Service Control Manager | ID = 7034
Description = The HP Port Resolver service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/18/2009 12:27:09 PM | Computer Name = SALES1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 3/18/2009 12:27:10 PM | Computer Name = SALES1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 3/18/2009 1:17:10 PM | Computer Name = SALES1 | Source = Service Control Manager | ID = 7022
Description = The Windows Firewall/Internet Connection Sharing (ICS) service hung
on starting.

Error - 3/30/2009 9:45:06 AM | Computer Name = SALES1 | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{CED5D5C5-3EBC-4AB0-821E-F3AA19A6805E}. The
backup browser is stopping.

Error - 4/1/2009 6:08:24 PM | Computer Name = SALES1 | Source = Service Control Manager | ID = 7034
Description = The HP Status Server service terminated unexpectedly. It has done
this 1 time(s).

Error - 4/1/2009 6:15:04 PM | Computer Name = SALES1 | Source = Service Control Manager | ID = 7034
Description = The HP Port Resolver service terminated unexpectedly. It has done
this 1 time(s).

Error - 4/3/2009 3:19:02 PM | Computer Name = SALES1 | Source = Service Control Manager | ID = 7034
Description = The ThreatFire service terminated unexpectedly. It has done this
1 time(s).


< End of report >
Hi

There may have been some vundo on this computer at one time.

Next, Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
Explorer.EXE 

:OTLI
O28 - HKLM ShellExecuteHooks: {AF209DB6-29BB-4F8B-84E8-2056EA999610} - Reg Error: Key error. File not found

:Services

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

:Files

:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL2 log and a new HJT log.




You have some old vulnerable versions of java on your computer. You may want to copy and paste the instructions for this tool into a notepad and save to your desktop for reference as your browser should be closed.

Please download JavaRa to your desktop and unzip it to its own folder. Close your browser.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
The current version is Java™ 6 Update 13



Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with
  • OTLISTIT2 log
  • combofix log
  • new HJT log

Any more occurances of the problems?

Thanks
Here are the 3 logs you requested,

OTListIt2:

========== PROCESSES ==========
Process Explorer.EXE killed successfully!
========== OTLISTIT ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AF209DB6-29BB-4F8B-84E8-2056EA999610} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF209DB6-29BB-4F8B-84E8-2056EA999610}\ not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLs"|"" /E : value set successfully!
========== FILES ==========
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTListIt2 by OldTimer - Version 2.0.7.1 log created on 04082009_084152

Files moved on Reboot…
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.

Registry entries deleted on Reboot…


COMBOFIX:

ComboFix 09-04-04.01 - Sales 2009-04-08 11:54:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.991.596 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\IE4 Error Log.txt
c:\windows\system32\bhqruhhk.ini
c:\windows\system32\mtnlacrw.ini
c:\windows\system32\rjcnywsb.ini

.
((((((((((((((((((((((((( Files Created from 2009-03-08 to 2009-04-08 )))))))))))))))))))))))))))))))
.

2009-04-08 11:48 . 2009-04-08 11:48 410,984 –a—— c:\windows\system32\deploytk.dll
2009-04-08 11:44 . 2009-04-08 11:47 d——– c:\documents and settings\Sales\.SunDownloadManager
2009-04-08 08:41 . 2009-04-08 08:41 d——– C:\_OTListIt
2009-04-02 16:27 . 2009-04-02 16:27 d——– c:\program files\Trend Micro
2009-03-30 10:44 . 2009-03-30 10:44 d——– c:\program files\ERUNT
2009-03-30 10:41 . 2009-03-30 10:41 d——– c:\program files\SpywareBlaster
2009-03-18 10:51 . 2009-03-18 10:51 d——– c:\windows\system32\scripting
2009-03-18 10:51 . 2009-03-18 10:51 d——– c:\windows\system32\en
2009-03-18 10:51 . 2009-03-18 10:51 d——– c:\windows\system32\bits
2009-03-18 10:51 . 2009-03-18 10:51 d——– c:\windows\l2schemas
2009-03-18 10:50 . 2009-03-18 10:52 d——– c:\windows\ServicePackFiles
2009-03-18 10:47 . 2006-12-29 00:31 19,569 –a—— c:\windows\003075_.tmp
2009-03-18 10:27 . 2008-10-16 14:07 23,576 –a—— c:\windows\system32\wuapi.dll.mui

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-08 17:52 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-08 17:52 ——— d—–w c:\program files\Spyware Doctor
2009-04-08 17:48 ——— d—–w c:\program files\Java
2009-04-01 20:27 ——— d—–w c:\program files\Common Files\Adobe
2009-03-30 16:00 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-03-26 22:49 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 22:49 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-02-24 19:16 ——— d—–w c:\program files\Common Files\Adobe AIR
2009-02-24 19:14 ——— d—–w c:\documents and settings\Sales\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-02-24 15:52 ——— d—–w c:\documents and settings\All Users\Application Data\PC Tools
2009-02-24 15:50 51,520 —-a-w c:\windows\system32\drivers\TfFsMon.sys
2009-02-24 15:50 38,208 —-a-w c:\windows\system32\drivers\TfSysMon.sys
2009-02-24 15:50 33,088 —-a-w c:\windows\system32\drivers\TfNetMon.sys
2009-02-24 15:50 12,608 —-a-w c:\windows\system32\drivers\TfKbMon.sys
2009-02-19 06:27 84,496 —-a-w c:\windows\system32\KemXML.dll
2009-02-19 06:27 170,512 —-a-w c:\windows\system32\kemutb.dll
2009-02-19 06:27 145,936 —-a-w c:\windows\system32\KemUtil.dll
2009-02-19 06:27 117,264 —-a-w c:\windows\system32\KemWnd.dll
2009-02-19 06:26 301,656 —-a-w c:\windows\system32\BtCoreIf.dll
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-08 148888]
"CARPService"="carpserv.exe" [2003-05-21 c:\windows\system32\carpserv.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-18 c:\windows\KHALMNPR.Exe]

c:\documents and settings\Sales\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-04-01 809488]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 00:30 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^Sales^Start Menu^Programs^Startup^VZAccess Manager.lnk]
path=c:\documents and settings\Sales\Start Menu\Programs\Startup\VZAccess Manager.lnk
backup=c:\windows\pss\VZAccess Manager.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2005-09-24 00:08 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpbdfawep]
–a—— 2007-12-23 22:47 618496 c:\program files\HP\DfaWep\bin\hpbdfawep.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
——— 2005-01-27 11:17 1381376 c:\program files\Ahead\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2003-10-31 19:42 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
–a—— 2002-07-12 04:15 106496 c:\windows\SiSUSBrg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 04:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
——— 2006-10-18 20:05 204288 c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2005-02-23 04:13 77824 c:\windows\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVGFwSrv"=2 (0x2)
"AVGEMS"=2 (0x2)
"AvgCoreSvc"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-02-24 51520]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-02-24 38208]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2008-11-18 160792]
R2 GLOGODrv;GLOGODrv;c:\windows\system32\drivers\GLOGODrv.sys [2006-04-07 13332]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-02-24 33088]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2007-04-19 99200]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-11-18 356920]
S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service –> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - JAVAQUICKSTARTERSERVICE
*Deregistered* - mchInjDrv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11f20c7c-ebbc-11dd-a3ee-001485bc611f}]
\Shell\AutoRun\command - E:\DmailerBackup.exe
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.sportscitycyclery.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
Trusted Zone: honda.com\www.in
DPF: {297DE2B6-509A-4B36-93C5-A65276606900} - hxxp://www.in.honda.com/rraaapps/rraasec/codebase/RRAAINAX/RraainAX.CAB
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-08 11:56:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(536)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(592)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
Completion time: 2009-04-08 11:57:58
ComboFix-quarantined-files.txt 2009-04-08 17:57:56

Pre-Run: 55,187,046,400 bytes free
Post-Run: 55,273,426,944 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

176 — E O F — 2009-03-19 23:12:47

HJT LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:53 AM, on 4/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sportscitycyclery.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.in.honda.com
O16 - DPF: {1663ED61-23EB-11D2-B92F-008048FDD814} (MeadCo ScriptX Advanced) - https://www.polarisdealers.com/Files/Controls/Print/smsx.cab
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} (RRAAINAX_02.RRAAINAX) - http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1237393633515
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
O24 - Desktop Component 0: (no name) - http://www.kawasaki.com/Adplanner2/UploadF…7F_83223_th.jpg

–
End of file - 5527 bytes

Thanks,
Hi SportsCityIT,

Looks like there was a bit left. How's the computer?

One more scan.

You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Desktop is a good place.
  • Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply along with a new HijackThis log.

Thanks
Hi, I will do this scan as soon as I can kick the OM off her computer. The machine has been tempermental, locking up on boot, slow loading programs, etc. The suprise toolbar has not reappeared. Thanks
Hi,

The computer is running better. Still having some weird things like desktop color changing.

Here are the logs you asked for.

Thanks.

KASPERSKY

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, April 9, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, April 09, 2009 16:05:40
Records in database: 2028317
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Files scanned: 54581
Threat name: 4
Infected objects: 5
Suspicious objects: 0
Duration of the scan: 01:54:07


File name / Threat name / Threats count
C:\LSLOAD\apps\vnc-4_1_1-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 1
C:\LSLOAD\apps\vnc-4_1_1-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\LSLOAD\setup.exe Infected: not-a-virus:RiskTool.Win32.FWDisabler.a 1
C:\WINDOWS\system32\iohfsu.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.eud 1
C:\WINDOWS\system32\mjwcewbx.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.eud 1

The selected area was scanned.

HJT LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:55:49 AM, on 4/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sportscitycyclery.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.in.honda.com
O16 - DPF: {1663ED61-23EB-11D2-B92F-008048FDD814} (MeadCo ScriptX Advanced) - https://www.polarisdealers.com/Files/Controls/Print/smsx.cab
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} (RRAAINAX_02.RRAAINAX) - http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1237393633515
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
O24 - Desktop Component 0: (no name) - http://www.kawasaki.com/Adplanner2/UploadF…7F_83223_th.jpg

–
End of file - 6001 bytes
Hi SportsCityIT,

C:\LSLOAD\apps\vnc-4_1_1-x86_win32.exe
C:\LSLOAD\apps\vnc-4_1_1-x86_win32.exe
C:\LSLOAD\setup.exe


These would appear to be part of a virtual network and adminstrator tools. Kaspersky will detect them as Admin tools and risk ware. Since this is a work computer and I don't know how you have it set up, we'll leave them unless you have information that they should not be installed on this computer.




The other 2 will have to go.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\iohfsu.dll 
    C:\WINDOWS\system32\mjwcewbx.dll 
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Let's see if removing those 2 resolves the remaining issues.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI