Vovin
Topic Starter
Hi,
I used Malawarebytes to perform quick scan and it discovered Trojan.
I have proceeded with removal steps.
After reboot scanned one more time and saw one of the suspicious files still existed.
So removed it with Malawarebytes one more time, but after restart it apeared again.
The computer is starting slow as well, but I used to it and don't reboot too frequently.
Please help me get my computer clean.
Malaware log (same delete on reboot second time):
Malwarebytes' Anti-Malware 1.35
Database version: 1944
Windows 5.2.3790 Service Pack 2
4/6/2009 13:25:56
mbam-log-2009-04-06 (13-25-56).txt
Scan type: Quick Scan
Objects scanned: 91090
Time elapsed: 9 minute(s), 50 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\a (Trojan.Agent) -> Delete on reboot.
And hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:34:19, on 4/6/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Eracent\EAS\EracentAuditSyncService.exe
c:\Eracent\EDA\EracentEDAService.exe
c:\EracentCli\EPA\EracentEPAService.exe
c:\EracentCli\EPM\EracentEPMService.exe
c:\EracentCli\EUA\EracentEUAService.exe
C:\Eracent\EMQS\EracentMQService.exe
c:\EracentCli\SUM\EracentSUMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\iisgSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Troxo\IISGuard\iisgWS.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\VMware\VMware Server\tomcat\bin\Tomcat6.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Eracent\EEDS\EracentEDService.exe
C:\Eracent\EEPAC\EracentEPACollector.exe
C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
C:\WINDOWS\Explorer.EXE
C:\Eracent\EEPMC\EracentEPMCollector.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Eracent\ESUMC\EracentSUMCollector.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\CCTray\cctray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\EracentCli\EPM\epm.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
D:\Programs\totalcmd\TOTALCMD.EXE
C:\Program Files\TortoiseSVN\bin\TortoiseProc.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gmail.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = w3cache.icm.edu.pl:8080
O1 - Hosts: 209.85.137.125 gmail.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2504630063-1718762433-3400453705-1023\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'EracentService')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: CCTray.lnk = C:\Program Files\CCTray\cctray.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware server\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware server\vsocklib.dll
O15 - ESC Trusted Zone: http://runonce.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1233223353043
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233219652264
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eracent.pl
O17 - HKLM\Software\..\Telephony: DomainName = eracent.pl
O17 - HKLM\System\CCS\Services\Tcpip\..\{7C5877BA-9134-4104-80D1-BA4833DFFA4E}: NameServer = 192.168.0.16
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eracent.pl
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: EnterpriseEMTaskService - Unknown owner - C:\Inetpub\wwwroot\EnterpriseEM\EnterpriseEMTaskService\EnterpriseEMTaskService.exe
O23 - Service: EracentAuditProcessor - Eracent Corporation - C:\Eracent\EAP\EracentAuditProcessor.exe
O23 - Service: EracentAuditSyncService - Eracent Corporation - C:\Eracent\EAS\EracentAuditSyncService.exe
O23 - Service: EracentCMPService - Eracent Corporation - C:\Eracent\ECMP\EracentCMPService.exe
O23 - Service: EracentDTCService - Eracent Corporation - C:\Eracent\EDTC\EracentDTCService.exe
O23 - Service: EracentEDAService - Eracent Corporation - c:\Eracent\EDA\EracentEDAService.exe
O23 - Service: EracentEDService - Eracent Corporation - C:\Eracent\EEDS\EracentEDService.exe
O23 - Service: EracentEPACollector - Eracent Corporation - C:\Eracent\EEPAC\EracentEPACollector.exe
O23 - Service: EracentEPACollector8Legacy - Eracent Corporation - C:\Eracent\EEPAC8L\EracentEPACollector8L.exe
O23 - Service: EracentEPAService - Eracent Corporation - c:\EracentCli\EPA\EracentEPAService.exe
O23 - Service: EracentEPMBucketProcessor - Eracent Corporation - C:\Eracent\EBP\EracentEPMBucketProcessor.exe
O23 - Service: EracentEPMCollector - Eracent Corporation - C:\Eracent\EEPMC\EracentEPMCollector.exe
O23 - Service: EracentEPMCollector8L - Eracent Corporation - C:\Eracent\EEPMC8L\EracentEPMCollector8L.exe
O23 - Service: EracentEPMService - Eracent Corporation - c:\EracentCli\EPM\EracentEPMService.exe
O23 - Service: EracentEUAService - Eracent Corporation - c:\EracentCli\EUA\EracentEUAService.exe
O23 - Service: EracentMQService - Eracent Corporation - C:\Eracent\EMQS\EracentMQService.exe
O23 - Service: EracentNetworkProbe - Eracent Corporation - C:\Eracent\ENP\EracentNetworkProbe.exe
O23 - Service: EracentSUMCollector - Eracent Corporation - C:\Eracent\ESUMC\EracentSUMCollector.exe
O23 - Service: EracentSUMService - Eracent Corporation - c:\EracentCli\SUM\EracentSUMService.exe
O23 - Service: EracentTaskScheduler - Eracent Corporation - C:\Eracent\ETS\EracentTaskScheduler.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IISGuard Service (IISGuardSVC) - Troxo - C:\WINDOWS\system32\iisgSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: VMware Converter Service (ufad-p2v) - VMware, Inc. - C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
O23 - Service: VisualSVN Server (VisualSVNServer) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: VMware Host Agent (VMwareHostd) - Unknown owner - C:\Program Files\VMware\VMware Server\vmware-hostd.exe
O23 - Service: VMware Server Web Access (VMwareServerWebAccess) - Apache Software Foundation - C:\Program Files\VMware\VMware Server\tomcat\bin\Tomcat6.exe
O23 - Service: VMware VSS Writer (vmwriter) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmVssWriter.exe
–
End of file - 11111 bytes
I used Malawarebytes to perform quick scan and it discovered Trojan.
I have proceeded with removal steps.
After reboot scanned one more time and saw one of the suspicious files still existed.
So removed it with Malawarebytes one more time, but after restart it apeared again.
The computer is starting slow as well, but I used to it and don't reboot too frequently.
Please help me get my computer clean.
Malaware log (same delete on reboot second time):
Malwarebytes' Anti-Malware 1.35
Database version: 1944
Windows 5.2.3790 Service Pack 2
4/6/2009 13:25:56
mbam-log-2009-04-06 (13-25-56).txt
Scan type: Quick Scan
Objects scanned: 91090
Time elapsed: 9 minute(s), 50 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\a (Trojan.Agent) -> Delete on reboot.
And hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:34:19, on 4/6/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Eracent\EAS\EracentAuditSyncService.exe
c:\Eracent\EDA\EracentEDAService.exe
c:\EracentCli\EPA\EracentEPAService.exe
c:\EracentCli\EPM\EracentEPMService.exe
c:\EracentCli\EUA\EracentEUAService.exe
C:\Eracent\EMQS\EracentMQService.exe
c:\EracentCli\SUM\EracentSUMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\iisgSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Troxo\IISGuard\iisgWS.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\VMware\VMware Server\tomcat\bin\Tomcat6.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Eracent\EEDS\EracentEDService.exe
C:\Eracent\EEPAC\EracentEPACollector.exe
C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
C:\WINDOWS\Explorer.EXE
C:\Eracent\EEPMC\EracentEPMCollector.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Eracent\ESUMC\EracentSUMCollector.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\CCTray\cctray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\EracentCli\EPM\epm.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
D:\Programs\totalcmd\TOTALCMD.EXE
C:\Program Files\TortoiseSVN\bin\TortoiseProc.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gmail.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = w3cache.icm.edu.pl:8080
O1 - Hosts: 209.85.137.125 gmail.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2504630063-1718762433-3400453705-1023\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'EracentService')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: CCTray.lnk = C:\Program Files\CCTray\cctray.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware server\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware server\vsocklib.dll
O15 - ESC Trusted Zone: http://runonce.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1233223353043
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233219652264
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eracent.pl
O17 - HKLM\Software\..\Telephony: DomainName = eracent.pl
O17 - HKLM\System\CCS\Services\Tcpip\..\{7C5877BA-9134-4104-80D1-BA4833DFFA4E}: NameServer = 192.168.0.16
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eracent.pl
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: EnterpriseEMTaskService - Unknown owner - C:\Inetpub\wwwroot\EnterpriseEM\EnterpriseEMTaskService\EnterpriseEMTaskService.exe
O23 - Service: EracentAuditProcessor - Eracent Corporation - C:\Eracent\EAP\EracentAuditProcessor.exe
O23 - Service: EracentAuditSyncService - Eracent Corporation - C:\Eracent\EAS\EracentAuditSyncService.exe
O23 - Service: EracentCMPService - Eracent Corporation - C:\Eracent\ECMP\EracentCMPService.exe
O23 - Service: EracentDTCService - Eracent Corporation - C:\Eracent\EDTC\EracentDTCService.exe
O23 - Service: EracentEDAService - Eracent Corporation - c:\Eracent\EDA\EracentEDAService.exe
O23 - Service: EracentEDService - Eracent Corporation - C:\Eracent\EEDS\EracentEDService.exe
O23 - Service: EracentEPACollector - Eracent Corporation - C:\Eracent\EEPAC\EracentEPACollector.exe
O23 - Service: EracentEPACollector8Legacy - Eracent Corporation - C:\Eracent\EEPAC8L\EracentEPACollector8L.exe
O23 - Service: EracentEPAService - Eracent Corporation - c:\EracentCli\EPA\EracentEPAService.exe
O23 - Service: EracentEPMBucketProcessor - Eracent Corporation - C:\Eracent\EBP\EracentEPMBucketProcessor.exe
O23 - Service: EracentEPMCollector - Eracent Corporation - C:\Eracent\EEPMC\EracentEPMCollector.exe
O23 - Service: EracentEPMCollector8L - Eracent Corporation - C:\Eracent\EEPMC8L\EracentEPMCollector8L.exe
O23 - Service: EracentEPMService - Eracent Corporation - c:\EracentCli\EPM\EracentEPMService.exe
O23 - Service: EracentEUAService - Eracent Corporation - c:\EracentCli\EUA\EracentEUAService.exe
O23 - Service: EracentMQService - Eracent Corporation - C:\Eracent\EMQS\EracentMQService.exe
O23 - Service: EracentNetworkProbe - Eracent Corporation - C:\Eracent\ENP\EracentNetworkProbe.exe
O23 - Service: EracentSUMCollector - Eracent Corporation - C:\Eracent\ESUMC\EracentSUMCollector.exe
O23 - Service: EracentSUMService - Eracent Corporation - c:\EracentCli\SUM\EracentSUMService.exe
O23 - Service: EracentTaskScheduler - Eracent Corporation - C:\Eracent\ETS\EracentTaskScheduler.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IISGuard Service (IISGuardSVC) - Troxo - C:\WINDOWS\system32\iisgSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: VMware Converter Service (ufad-p2v) - VMware, Inc. - C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
O23 - Service: VisualSVN Server (VisualSVNServer) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: VMware Host Agent (VMwareHostd) - Unknown owner - C:\Program Files\VMware\VMware Server\vmware-hostd.exe
O23 - Service: VMware Server Web Access (VMwareServerWebAccess) - Apache Software Foundation - C:\Program Files\VMware\VMware Server\tomcat\bin\Tomcat6.exe
O23 - Service: VMware VSS Writer (vmwriter) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmVssWriter.exe
–
End of file - 11111 bytes