This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan.Agent (a.exe)

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I used mbam to perform quick scan and it discovered Trojan.
I have proceeded with removal steps and immediate reboot.
After reboot scanned one more time and saw one of the suspicious files still existed.
So removed it with Malawarebytes one more time, but after restart it apeared again.

The computer is starting slow as well, but I used to it and don't reboot too frequently.

Please help me get my computer clean.

HJ log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:45:02, on 4/21/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Eracent\EAS\EracentAuditSyncService.exe
c:\Eracent\EDA\EracentEDAService.exe
c:\EracentCli\EPA\EracentEPAService.exe
c:\EracentCli\EPM\EracentEPMService.exe
c:\EracentCli\EUA\EracentEUAService.exe
C:\Eracent\EMQS\EracentMQService.exe
c:\EracentCli\SUM\EracentSUMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\iisgSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Troxo\IISGuard\iisgWS.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\VMware\VMware Server\tomcat\bin\Tomcat6.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Eracent\EEDS\EracentEDService.exe
C:\Eracent\EEPAC\EracentEPACollector.exe
C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
C:\Eracent\EEPMC\EracentEPMCollector.exe
C:\Eracent\ESUMC\EracentSUMCollector.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\VMware\VMware Server\vmware-hostd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\CCTray\cctray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\System32\svchost.exe
D:\Programs\totalcmd\TOTALCMD.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
c:\EracentCli\EPM\epm.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gmail.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = w3cache.icm.edu.pl:8080
O1 - Hosts: 209.85.137.125 gmail.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2504630063-1718762433-3400453705-1023\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'EracentService')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: CCTray.lnk = C:\Program Files\CCTray\cctray.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware server\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware server\vsocklib.dll
O15 - ESC Trusted Zone: http://runonce.msn.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1233223353043
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233219652264
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eracent.pl
O17 - HKLM\Software\..\Telephony: DomainName = eracent.pl
O17 - HKLM\System\CCS\Services\Tcpip\..\{7C5877BA-9134-4104-80D1-BA4833DFFA4E}: NameServer = 192.168.0.16
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eracent.pl
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: EnterpriseEMTaskService - Unknown owner - C:\Inetpub\wwwroot\EnterpriseEM\EnterpriseEMTaskService\EnterpriseEMTaskService.exe
O23 - Service: EracentAuditProcessor - Eracent Corporation - C:\Eracent\EAP\EracentAuditProcessor.exe
O23 - Service: EracentAuditSyncService - Eracent Corporation - C:\Eracent\EAS\EracentAuditSyncService.exe
O23 - Service: EracentCMPService - Eracent Corporation - C:\Eracent\ECMP\EracentCMPService.exe
O23 - Service: EracentDTCService - Eracent Corporation - C:\Eracent\EDTC\EracentDTCService.exe
O23 - Service: EracentEDAService - Eracent Corporation - c:\Eracent\EDA\EracentEDAService.exe
O23 - Service: EracentEDService - Eracent Corporation - C:\Eracent\EEDS\EracentEDService.exe
O23 - Service: EracentEPACollector - Eracent Corporation - C:\Eracent\EEPAC\EracentEPACollector.exe
O23 - Service: EracentEPACollector8Legacy - Eracent Corporation - C:\Eracent\EEPAC8L\EracentEPACollector8L.exe
O23 - Service: EracentEPAService - Eracent Corporation - c:\EracentCli\EPA\EracentEPAService.exe
O23 - Service: EracentEPMBucketProcessor - Eracent Corporation - C:\Eracent\EBP\EracentEPMBucketProcessor.exe
O23 - Service: EracentEPMCollector - Eracent Corporation - C:\Eracent\EEPMC\EracentEPMCollector.exe
O23 - Service: EracentEPMCollector8L - Eracent Corporation - C:\Eracent\EEPMC8L\EracentEPMCollector8L.exe
O23 - Service: EracentEPMService - Eracent Corporation - c:\EracentCli\EPM\EracentEPMService.exe
O23 - Service: EracentEUAService - Eracent Corporation - c:\EracentCli\EUA\EracentEUAService.exe
O23 - Service: EracentMQService - Eracent Corporation - C:\Eracent\EMQS\EracentMQService.exe
O23 - Service: EracentNetworkProbe - Eracent Corporation - C:\Eracent\ENP\EracentNetworkProbe.exe
O23 - Service: EracentSUMCollector - Eracent Corporation - C:\Eracent\ESUMC\EracentSUMCollector.exe
O23 - Service: EracentSUMService - Eracent Corporation - c:\EracentCli\SUM\EracentSUMService.exe
O23 - Service: EracentTaskScheduler - Eracent Corporation - C:\Eracent\ETS\EracentTaskScheduler.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IISGuard Service (IISGuardSVC) - Troxo - C:\WINDOWS\system32\iisgSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: VMware Converter Service (ufad-p2v) - VMware, Inc. - C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
O23 - Service: VisualSVN Server (VisualSVNServer) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: VMware Host Agent (VMwareHostd) - Unknown owner - C:\Program Files\VMware\VMware Server\vmware-hostd.exe
O23 - Service: VMware Server Web Access (VMwareServerWebAccess) - Apache Software Foundation - C:\Program Files\VMware\VMware Server\tomcat\bin\Tomcat6.exe
O23 - Service: VMware VSS Writer (vmwriter) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmVssWriter.exe

–
End of file - 11111 bytes
Hi Vovin,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key repeatedly;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual user account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then please re-run your Malwarebytes

Please download Malwarebytes' Anti-Malware to your desktop.

  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Hi Tomk, thanks you for your prompt answer. Unfortunatelly SDFix didn't run. It looks like it does not support Windows2003 (I can tell from the sources). Vovin
Cleaned everything with ATF Cleaner. Then run Anti-Malware: Malwarebytes' Anti-Malware 1.36 Database version: 2024 Windows 5.2.3790 Service Pack 2 4/22/2009 16:08:16 mbam-log-2009-04-22 (16-08-16).txt Scan type: Quick Scan Objects scanned: 95082 Time elapsed: 3 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\a (Trojan.Agent) -> Delete on reboot. — After reboot, scanned second time with Malaware and got the same results: Malwarebytes' Anti-Malware 1.36 Database version: 2024 Windows 5.2.3790 Service Pack 2 4/22/2009 16:28:13 mbam-log-2009-04-22 (16-28-13).txt Scan type: Quick Scan Objects scanned: 94643 Time elapsed: 7 minute(s), 25 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\a (Trojan.Agent) -> Delete on reboot.
Vovin,

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-21-2504630063-1718762433-3400453705-1023\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'EracentService')
      O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
      O15 - ESC Trusted Zone: http://runonce.msn.com
      O23 - Service: VisualSVN Server (VisualSVNServer) - Unknown owner - C:\Program.exe (file missing)
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Ok, removed items as instructed.
Then run OTLIst:

OTListIt logfile created on: 4/22/2009 18:16:48 - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\popop\Desktop
Windows Server 2003 Standard Edition Service Pack 2 (Version = 5.2.3790) - Type = NTServer
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 2046;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.23 Gb Total Space | 34.57 Gb Free Space | 49.93% Space Free | Partition Type: NTFS
Drive D: | 117.07 Gb Total Space | 18.93 Gb Free Space | 16.17% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VOVIN
Current User Name: popop
NOT logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2006/12/16 15:42:48 | 00,434,176 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2006/09/29 11:01:06 | 00,258,560 | —- | M] (ASUSTeK COMPUTER INC.) – C:\WINDOWS\ATKKBService.exe
PRC - [2008/02/26 14:35:00 | 00,389,120 | —- | M] () – C:\Inetpub\wwwroot\EnterpriseEM\EnterpriseEMTaskService\EnterpriseEMTaskService.exe
PRC - [2008/02/18 14:22:56 | 01,605,632 | —- | M] (Eracent Corporation) – C:\Eracent\EAS\EracentAuditSyncService.exe
PRC - [2008/02/18 18:38:26 | 01,818,624 | —- | M] (Eracent Corporation) – c:\Eracent\EDA\EracentEDAService.exe
PRC - [2009/02/27 19:40:07 | 03,145,728 | —- | M] (Eracent Corporation) – c:\EracentCli\EPA\EracentEPAService.exe
PRC - [2009/02/27 19:40:37 | 01,839,104 | —- | M] (Eracent Corporation) – c:\EracentCli\EPM\EracentEPMService.exe
PRC - [2009/02/27 19:41:34 | 02,146,304 | —- | M] (Eracent Corporation) – c:\EracentCli\EUA\EracentEUAService.exe
PRC - [2008/02/07 22:47:20 | 02,146,304 | —- | M] (Eracent Corporation) – C:\Eracent\EMQS\EracentMQService.exe
PRC - [2009/02/27 19:41:35 | 01,921,024 | —- | M] (Eracent Corporation) – c:\EracentCli\SUM\EracentSUMService.exe
PRC - [2007/02/17 04:19:44 | 00,014,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\inetsrv\inetinfo.exe
PRC - [2006/01/30 14:51:24 | 01,437,696 | —- | M] (Troxo) – C:\WINDOWS\system32\iisgSVC.exe
PRC - [2009/01/14 18:46:17 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2006/01/30 14:50:02 | 00,233,472 | —- | M] (Troxo) – C:\Program Files\Troxo\IISGuard\iisgWS.exe
PRC - [2007/03/04 00:12:02 | 00,202,096 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe
PRC - [2006/12/16 15:42:48 | 00,434,176 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2007/03/04 00:12:56 | 28,771,240 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
PRC - [2007/03/04 00:12:54 | 14,560,624 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
PRC - [2007/03/04 00:09:40 | 00,017,264 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe
PRC - [2007/11/01 17:20:30 | 00,176,128 | —- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
PRC - [2007/02/17 03:31:22 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\cmd.exe
PRC - [2008/07/28 18:09:54 | 00,023,840 | —- | M] (Apache Software Foundation) – C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
PRC - [2008/10/12 14:23:44 | 00,399,920 | —- | M] (VMware, Inc.) – C:\WINDOWS\system32\vmnat.exe
PRC - [2008/10/12 21:27:22 | 00,057,344 | —- | M] (Apache Software Foundation) – C:\Program Files\VMware\VMware Server\tomcat\bin\Tomcat6.exe
PRC - [2008/02/18 14:23:24 | 02,007,040 | —- | M] (Eracent Corporation) – C:\Eracent\EEDS\EracentEDService.exe
PRC - [2008/02/18 14:23:11 | 02,187,264 | —- | M] (Eracent Corporation) – C:\Eracent\EEPAC\EracentEPACollector.exe
PRC - [2008/07/28 18:09:54 | 00,023,840 | —- | M] (Apache Software Foundation) – C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
PRC - [2008/02/18 14:23:19 | 01,810,432 | —- | M] (Eracent Corporation) – C:\Eracent\EEPMC\EracentEPMCollector.exe
PRC - [2008/02/18 14:23:37 | 01,822,720 | —- | M] (Eracent Corporation) – C:\Eracent\ESUMC\EracentSUMCollector.exe
PRC - [2005/08/26 17:00:26 | 00,092,880 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
PRC - [2005/10/14 04:51:20 | 00,318,680 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE
PRC - [2008/10/12 14:23:32 | 00,121,392 | —- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware Server\vmware-authd.exe
PRC - [2008/10/12 14:23:32 | 00,326,192 | —- | M] (VMware, Inc.) – C:\WINDOWS\system32\vmnetdhcp.exe
PRC - [2008/10/12 14:24:26 | 00,322,096 | —- | M] () – C:\Program Files\VMware\VMware Server\vmware-hostd.exe
PRC - [2007/02/17 05:09:46 | 00,207,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2007/02/17 05:09:46 | 00,207,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2009/02/27 19:40:34 | 00,622,592 | —- | M] (Eracent Corporation) – c:\EracentCli\EPM\epm.exe
PRC - [2007/02/17 04:55:16 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\rdpclip.exe
PRC - [2007/02/17 03:58:36 | 01,053,184 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2006/12/16 15:42:48 | 00,434,176 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2008/08/05 21:16:40 | 00,286,720 | —- | M] () – C:\Program Files\Launchy\Launchy.exe
PRC - [2007/08/24 05:45:42 | 00,101,784 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2007/02/17 04:31:48 | 00,509,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\logon.scr
PRC - [2007/02/17 05:08:14 | 00,007,168 | —- | M] (Microsoft Corporation) – c:\windows\system32\inetsrv\w3wp.exe
PRC - [2009/04/22 17:51:09 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\popop\Desktop\OTListIt2.exe
PRC - [2007/02/17 04:41:36 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\notepad.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2006/12/16 15:42:48 | 00,434,176 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2006/09/29 11:01:06 | 00,258,560 | —- | M] (ASUSTeK COMPUTER INC.) – C:\WINDOWS\ATKKBService.exe – (ATKKeyboardService [Auto | Running])
SRV - [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2007/02/17 03:50:02 | 00,164,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\Dfssvc.exe – (Dfs [On_Demand | Stopped])
SRV - [2008/02/26 14:35:00 | 00,389,120 | —- | M] () – C:\Inetpub\wwwroot\EnterpriseEM\EnterpriseEMTaskService\EnterpriseEMTaskService.exe – (EnterpriseEMTaskService [Auto | Running])
SRV - [2008/02/18 14:23:01 | 03,940,352 | —- | M] (Eracent Corporation) – C:\Eracent\EAP\EracentAuditProcessor.exe – (EracentAuditProcessor [On_Demand | Stopped])
SRV - [2008/02/18 14:22:56 | 01,605,632 | —- | M] (Eracent Corporation) – C:\Eracent\EAS\EracentAuditSyncService.exe – (EracentAuditSyncService [Auto | Running])
SRV - [2008/02/07 22:12:56 | 02,232,320 | —- | M] (Eracent Corporation) – C:\Eracent\ECMP\EracentCMPService.exe – (EracentCMPService [On_Demand | Stopped])
SRV - [2008/02/07 22:58:30 | 03,100,672 | —- | M] (Eracent Corporation) – C:\Eracent\EDTC\EracentDTCService.exe – (EracentDTCService [On_Demand | Stopped])
SRV - [2008/02/18 18:38:26 | 01,818,624 | —- | M] (Eracent Corporation) – c:\Eracent\EDA\EracentEDAService.exe – (EracentEDAService [Auto | Running])
SRV - [2008/02/18 14:23:24 | 02,007,040 | —- | M] (Eracent Corporation) – C:\Eracent\EEDS\EracentEDService.exe – (EracentEDService [Auto | Running])
SRV - [2008/02/18 14:23:11 | 02,187,264 | —- | M] (Eracent Corporation) – C:\Eracent\EEPAC\EracentEPACollector.exe – (EracentEPACollector [Auto | Running])
SRV - [2008/02/18 14:23:06 | 04,059,136 | —- | M] (Eracent Corporation) – C:\Eracent\EEPAC8L\EracentEPACollector8L.exe – (EracentEPACollector8Legacy [On_Demand | Stopped])
SRV - [2009/02/27 19:40:07 | 03,145,728 | —- | M] (Eracent Corporation) – c:\EracentCli\EPA\EracentEPAService.exe – (EracentEPAService [Auto | Running])
SRV - [2008/02/18 14:23:28 | 02,228,224 | —- | M] (Eracent Corporation) – C:\Eracent\EBP\EracentEPMBucketProcessor.exe – (EracentEPMBucketProcessor [On_Demand | Stopped])
SRV - [2008/02/18 14:23:19 | 01,810,432 | —- | M] (Eracent Corporation) – C:\Eracent\EEPMC\EracentEPMCollector.exe – (EracentEPMCollector [Auto | Running])
SRV - [2008/02/18 14:23:15 | 02,088,960 | —- | M] (Eracent Corporation) – C:\Eracent\EEPMC8L\EracentEPMCollector8L.exe – (EracentEPMCollector8L [On_Demand | Stopped])
SRV - [2009/02/27 19:40:37 | 01,839,104 | —- | M] (Eracent Corporation) – c:\EracentCli\EPM\EracentEPMService.exe – (EracentEPMService [Auto | Running])
SRV - [2009/02/27 19:41:34 | 02,146,304 | —- | M] (Eracent Corporation) – c:\EracentCli\EUA\EracentEUAService.exe – (EracentEUAService [Auto | Running])
SRV - [2008/02/07 22:47:20 | 02,146,304 | —- | M] (Eracent Corporation) – C:\Eracent\EMQS\EracentMQService.exe – (EracentMQService [On_Demand | Running])
SRV - [2008/02/18 14:23:33 | 02,957,312 | —- | M] (Eracent Corporation) – C:\Eracent\ENP\EracentNetworkProbe.exe – (EracentNetworkProbe [On_Demand | Stopped])
SRV - [2008/02/18 14:23:37 | 01,822,720 | —- | M] (Eracent Corporation) – C:\Eracent\ESUMC\EracentSUMCollector.exe – (EracentSUMCollector [Auto | Running])
SRV - [2009/02/27 19:41:35 | 01,921,024 | —- | M] (Eracent Corporation) – c:\EracentCli\SUM\EracentSUMService.exe – (EracentSUMService [Auto | Running])
SRV - [2008/02/18 14:22:52 | 02,846,720 | —- | M] (Eracent Corporation) – C:\Eracent\ETS\EracentTaskScheduler.exe – (EracentTaskScheduler [On_Demand | Stopped])
SRV - [2008/07/29 22:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2007/02/17 04:45:44 | 00,039,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2005/04/04 01:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 20:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2007/02/17 04:19:44 | 00,014,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\inetsrv\inetinfo.exe – (IISADMIN [Auto | Running])
SRV - [2006/01/30 14:51:24 | 01,437,696 | —- | M] (Troxo) – C:\WINDOWS\system32\iisgSVC.exe – (IISGuardSVC [Auto | Running])
SRV - [2007/02/17 04:20:52 | 00,040,448 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ismserv.exe – (IsmServ [Disabled | Stopped])
SRV - [2009/01/14 18:46:17 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2009/03/12 11:23:09 | 00,951,632 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service [Auto | Stopped])
SRV - [2007/02/18 01:30:26 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\llssrv.exe – (LicenseService [Disabled | Stopped])
SRV - [2007/08/24 07:59:20 | 00,068,464 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe – (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2007/03/04 00:12:02 | 00,202,096 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe – (MsDtsServer [Auto | Running])
SRV - [2005/08/26 17:00:26 | 00,092,880 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe – (msftesql [Auto | Running])
SRV - [2007/03/04 00:12:56 | 28,771,240 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe – (MSSQLSERVER [Auto | Running])
SRV - [2005/10/14 04:50:20 | 00,045,272 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe – (MSSQLServerADHelper [Disabled | Stopped])
SRV - [2007/03/04 00:12:54 | 14,560,624 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe – (MSSQLServerOLAPService [Auto | Running])
SRV - [2005/09/23 08:01:16 | 02,799,808 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe – (msvsmon80 [Disabled | Stopped])
SRV - [2008/07/29 14:10:46 | 03,201,024 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe – (msvsmon90 [Disabled | Stopped])
SRV - [2008/07/29 20:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/02/17 04:41:50 | 00,792,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\ntfrs.exe – (NtFrs [On_Demand | Stopped])
SRV - [2007/08/24 04:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 15:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2007/03/04 00:09:40 | 00,017,264 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe – (ReportServer [Auto | Running])
SRV - [2007/02/17 04:55:56 | 00,067,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\RSoPProv.exe – (RSoPProv [On_Demand | Stopped])
SRV - [2006/03/22 14:00:00 | 00,012,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\sacsvr.dll – (sacsvr [On_Demand | Stopped])
SRV - [2005/10/14 04:51:14 | 00,239,320 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe – (SQLBrowser [Disabled | Stopped])
SRV - [2005/10/14 04:51:20 | 00,318,680 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE – (SQLSERVERAGENT [Auto | Running])
SRV - [2005/10/14 04:53:50 | 00,087,768 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe – (SQLWriter [On_Demand | Stopped])
SRV - [2006/03/22 14:00:00 | 00,050,688 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\trksvr.dll – (TrkSvr [Disabled | Stopped])
SRV - [2007/02/17 05:07:00 | 00,071,168 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tssdis.exe – (Tssdis [Disabled | Stopped])
SRV - [2007/11/01 17:20:30 | 00,176,128 | —- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware Converter\vmware-ufad.exe – (ufad-p2v [Auto | Running])
SRV - [2007/02/17 05:08:32 | 00,039,424 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wdfmgr.exe – (UMWdf [On_Demand | Stopped])
SRV - [2008/07/28 16:59:06 | 00,000,153 | —- | M] () – C:\Program Files\VisualSVN Server\httpd-wrapper.bat – (VisualSVNServer [Auto | Running])
SRV - [2008/10/12 14:23:32 | 00,121,392 | —- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware Server\vmware-authd.exe – (VMAuthdService [Auto | Running])
SRV - [2008/10/12 14:23:32 | 00,326,192 | —- | M] (VMware, Inc.) – C:\WINDOWS\system32\vmnetdhcp.exe – (VMnetDHCP [Auto | Running])
SRV - [2008/10/12 14:23:44 | 00,399,920 | —- | M] (VMware, Inc.) – C:\WINDOWS\system32\vmnat.exe – (VMware NAT Service [Auto | Running])
SRV - [2008/10/12 14:24:26 | 00,322,096 | —- | M] () – C:\Program Files\VMware\VMware Server\vmware-hostd.exe – (VMwareHostd [Auto | Running])
SRV - [2008/10/12 21:27:22 | 00,057,344 | —- | M] (Apache Software Foundation) – C:\Program Files\VMware\VMware Server\tomcat\bin\Tomcat6.exe – (VMwareServerWebAccess [Auto | Running])
SRV - [2008/10/12 14:22:54 | 00,023,040 | —- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware Server\vmVssWriter.exe – (vmwriter [On_Demand | Stopped])
SRV - [2007/02/17 04:19:28 | 00,216,576 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\inetsrv\iisw3adm.dll – (W3SVC [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2007/02/17 03:17:16 | 00,043,520 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\System32\drivers\arc.sys – (arc [Disabled | Stopped])
DRV - [2006/10/31 16:55:38 | 00,011,008 | —- | M] (ASUSTeK COMPUTER INC.) – C:\WINDOWS\system32\drivers\atkkbnt.sys – (asuskbnt [System | Running])
DRV - [2006/12/16 15:50:30 | 01,918,464 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - [2007/02/17 03:31:14 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\ClusDisk.sys – (ClusDisk [Disabled | Stopped])
DRV - [2007/02/17 03:49:38 | 00,034,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\Dfs.sys – (DfsDriver [Boot | Running])
DRV - [2006/10/25 09:48:00 | 00,012,288 | R— | M] (ASUSTeK Computer Inc.) – C:\WINDOWS\system32\drivers\EIO.sys – (EIO [Auto | Running])
DRV - [2008/02/18 18:38:36 | 00,004,608 | —- | M] () – c:\Eracent\EPM\EPMProcMon.sys – (EPMProcMon [On_Demand | Running])
DRV - [2008/02/18 18:38:36 | 00,016,384 | —- | M] () – c:\Eracent\EPM\EPMTcpAn.sys – (EPMTcpAn [On_Demand | Running])
DRV - [2008/02/18 18:38:17 | 00,016,640 | —- | M] (Eracent Corporation) – c:\Eracent\EPA\arpcollector.sys – (EracentARPC [Auto | Running])
DRV - [2008/10/12 14:24:36 | 00,032,304 | —- | M] (VMware, Inc.) – C:\WINDOWS\system32\drivers\hcmon.sys – (hcmon [Auto | Running])
DRV - [2005/07/08 18:56:32 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2007/02/17 04:14:30 | 00,023,552 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\System32\drivers\hpcisss.sys – (hpcisss [Disabled | Stopped])
DRV - [2007/08/10 07:52:44 | 04,603,904 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService [On_Demand | Running])
DRV - [2009/03/05 11:23:20 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd [Boot | Running])
DRV - [2007/02/17 04:54:52 | 00,020,480 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/05/31 09:19:22 | 00,096,896 | R— | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys – (RTLE8023xp [On_Demand | Running])
DRV - [2007/11/13 11:32:23 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2008/02/15 15:33:06 | 00,716,272 | —- | M] () – C:\WINDOWS\System32\Drivers\sptd.sys – (sptd [Boot | Running])
DRV - [2006/09/29 11:06:26 | 00,010,752 | —- | M] (ASUSTeK COMPUTER INC.) – C:\WINDOWS\System32\Drivers\Video3D32.sys – (Video3D [On_Demand | Running])
DRV - [2008/10/12 14:24:38 | 00,054,960 | —- | M] (VMware, Inc.) – C:\WINDOWS\system32\Drivers\vmci.sys – (vmci [Auto | Running])
DRV - [2007/02/18 00:15:34 | 00,232,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\Drivers\vmm.sys – (vmm [System | Running])
DRV - [2008/10/12 14:23:10 | 00,016,560 | —- | M] (VMware, Inc.) – C:\WINDOWS\system32\DRIVERS\vmnetadapter.sys – (VMnetAdapter [On_Demand | Running])
DRV - [2008/10/12 14:23:10 | 00,031,280 | —- | M] (VMware, Inc.) – C:\WINDOWS\system32\DRIVERS\vmnetbridge.sys – (VMnetBridge [Auto | Running])
DRV - [2008/10/12 14:24:34 | 00,026,288 | —- | M] (VMware, Inc.) – C:\WINDOWS\system32\drivers\vmnetuserif.sys – (VMnetuserif [Auto | Running])
DRV - [2008/10/12 14:24:38 | 00,857,392 | —- | M] (VMware, Inc.) – C:\WINDOWS\system32\Drivers\vmx86.sys – (vmx86 [Auto | Running])
DRV - [2007/01/29 06:20:34 | 00,059,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys – (VPCNetS2 [On_Demand | Running])
DRV - [2007/11/01 17:18:34 | 00,019,248 | —- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware Converter\vstor2-p2v30.sys – (vstor2-p2v30 [Auto | Running])
DRV - [2007/02/17 05:09:26 | 00,169,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\wlbs.sys – (WLBS [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-2372228490-329967842-557336892-1517\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-2372228490-329967842-557336892-1517\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\S-1-5-21-2372228490-329967842-557336892-1517\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-2372228490-329967842-557336892-1517\S-1-5-21-2372228490-329967842-557336892-1517\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2372228490-329967842-557336892-1517\S-1-5-21-2372228490-329967842-557336892-1517\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =


========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.pl/ig"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: {2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}:2.1.034
FF - prefs.js..extensions.enabledItems: [removed]:2.0.3
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:2.5.0.122581
FF - prefs.js..extensions.enabledItems: {636fd8b0-ce2b-4e00-b812-2afbe77ee899}:1.4.2
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.9

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/01/14 18:46:17 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/01/16 09:34:12 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/22 16:22:37 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/22 16:22:36 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Components: C:\PROGRAM FILES\MOZILLA THUNDERBIRD\COMPONENTS [2009/03/20 09:19:03 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA THUNDERBIRD\PLUGINS

[2008/08/29 15:20:04 | 00,000,000 | —D | M] – C:\Documents and Settings\popop\Application Data\mozilla\Extensions
[2008/08/29 15:20:04 | 00,000,000 | —D | M] – C:\Documents and Settings\popop\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/22 09:09:37 | 00,000,000 | —D | M] – C:\Documents and Settings\popop\Application Data\mozilla\Firefox\Profiles\cil0tiuw.default\extensions
[2009/03/30 09:01:46 | 00,000,000 | —D | M] – C:\Documents and Settings\popop\Application Data\mozilla\Firefox\Profiles\cil0tiuw.default\extensions\{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}
[2009/04/08 16:24:26 | 00,000,000 | —D | M] – C:\Documents and Settings\popop\Application Data\mozilla\Firefox\Profiles\cil0tiuw.default\extensions\{636fd8b0-ce2b-4e00-b812-2afbe77ee899}
[2009/04/21 13:36:37 | 00,000,000 | —D | M] – C:\Documents and Settings\popop\Application Data\mozilla\Firefox\Profiles\cil0tiuw.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/04/21 13:36:37 | 00,000,000 | —D | M] – C:\Documents and Settings\popop\Application Data\mozilla\Firefox\Profiles\cil0tiuw.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/02/24 09:50:50 | 00,000,000 | —D | M] – C:\Documents and Settings\popop\Application Data\mozilla\Firefox\Profiles\cil0tiuw.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2009/02/10 09:59:54 | 00,000,000 | —D | M] – C:\Documents and Settings\popop\Application Data\mozilla\Firefox\Profiles\cil0tiuw.default\extensions\[removed]
[2009/02/28 11:55:15 | 00,000,000 | —D | M] – C:\Documents and Settings\popop\Application Data\mozilla\Firefox\Profiles\cil0tiuw.default\extensions\[removed]
[2009/04/22 09:09:37 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/22 16:22:30 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/02/18 10:43:51 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/03/18 08:57:00 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/21 17:17:43 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/01/14 18:46:38 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/22 16:22:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/22 16:22:30 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/08/29 15:19:56 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/08/29 15:19:56 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/08/29 15:19:56 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/14 10:04:57 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/08/29 15:19:56 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/08/29 15:19:56 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/08/29 15:19:56 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (761 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 209.85.137.125 gmail.com
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKU\S-1-5-21-2372228490-329967842-557336892-1517..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Launchy.lnk = C:\Program Files\Launchy\Launchy.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\popop\Start Menu\Programs\Startup\CCTray.lnk = C:\Program Files\CCTray\cctray.exe (ThoughtWorks)
O4 - Startup: C:\Documents and Settings\popop\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ShowSuperHidden = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2372228490-329967842-557336892-1517\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2372228490-329967842-557336892-1517\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\S-1-5-21-2504630063-1718762433-3400453705-1023\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files\Fiddler2\Fiddler.exe (Eric Lawrence)
O9 - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files\Fiddler2\Fiddler.exe (Eric Lawrence)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-2372228490-329967842-557336892-1517\..Trusted Domains: eracent.pl ([www.interweb] https in Local intranet)
O15 - HKU\S-1-5-21-2372228490-329967842-557336892-1517\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1233223353043 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1233219652264 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eracent.pl
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{7C5877BA-9134-4104-80D1-BA4833DFFA4E}\\NameServer = 192.168.0.16
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (VMGINA.DLL) - C:\WINDOWS\system32\VMGINA.DLL ()
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/15 11:28:52 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{6427d671-ff00-11dc-b55a-001d9233a0a5}\Shell\AutoRun\command - "" = F:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[8 C:\WINDOWS\*.tmp files]
[2009/04/22 17:51:08 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\popop\Desktop\OTListIt2.exe
[2009/04/22 13:29:09 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/04/22 11:59:53 | 00,000,706 | —- | C] () – C:\Documents and Settings\popop\Desktop\WinDirStat.lnk
[2009/04/22 11:59:53 | 00,000,000 | —D | C] – C:\Program Files\WinDirStat
[2009/04/22 08:29:48 | 00,000,000 | —D | C] – C:\SDFix
[2009/04/22 08:29:35 | 01,529,241 | —- | C] () – C:\Documents and Settings\popop\Desktop\SDFix.exe
[2009/04/21 13:25:02 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/04/07 09:21:24 | 00,738,094 | —- | C] () – C:\Documents and Settings\popop\Desktop\Japan_wiki.pdf
[2009/04/06 15:57:57 | 00,000,000 | —D | C] – C:\Program Files\RapidSVN-0.9.8
[2009/04/06 13:34:12 | 00,001,734 | —- | C] () – C:\Documents and Settings\popop\Desktop\HijackThis.lnk
[2009/04/06 13:34:11 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/06 08:50:29 | 00,000,000 | —D | C] – C:\Documents and Settings\popop\Application Data\Malwarebytes
[2009/04/06 08:50:27 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 08:50:25 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 08:50:24 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/06 08:50:24 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/03 14:04:33 | 00,000,000 | —D | C] – D:\VovinDocuments\My Meetings
[2009/04/03 13:31:39 | 00,081,736 | —- | C] (Microsoft Corporation.) – C:\WINDOWS\System32\lmdimon8.dll
[2009/04/03 13:31:27 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Applications
[2009/03/31 14:38:10 | 00,000,000 | —D | C] – C:\Documents and Settings\popop\Desktop\Interweb Documentation
[2009/03/31 11:16:02 | 00,000,000 | —D | C] – C:\Documents and Settings\popop\Desktop\Interweb Backup
[2009/03/31 10:18:18 | 00,000,000 | —D | C] – C:\Documents and Settings\popop\Desktop\SPIEFolder
[2009/03/31 10:16:05 | 00,917,320 | —- | C] () – C:\Documents and Settings\popop\Desktop\SPIEFolder.zip
[2009/03/31 09:59:03 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Office Project Server 2003 Resource Kit
[2009/03/31 09:56:01 | 00,981,744 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\popop\Desktop\SMIGRATE.exe
[2009/03/30 09:53:08 | 00,718,869 | —- | C] () – C:\Documents and Settings\popop\Desktop\AuditUpdatePatchManagement.zip
[2009/03/27 12:08:32 | 01,212,516 | —- | C] () – C:\Documents and Settings\popop\Desktop\supergstunt_trial_v.zip
[2009/03/25 11:17:59 | 00,326,192 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetdhcp.exe
[2009/03/25 11:17:53 | 00,399,920 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnat.exe
[2009/03/25 11:17:49 | 00,026,288 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnetuserif.sys
[2009/03/25 11:17:23 | 00,723,504 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vnetlib.dll
[2009/03/24 11:48:44 | 00,037,658 | —- | C] () – C:\Documents and Settings\popop\Desktop\duplicate_contact_manager-0.6-tb.xpi
[2009/03/24 11:48:20 | 00,054,164 | —- | C] () – C:\Documents and Settings\popop\Desktop\thunderbirthday-0.2.8.1-tb.xpi
[2009/03/24 11:48:04 | 00,110,142 | —- | C] () – C:\Documents and Settings\popop\Desktop\provider_for_google_calendar-0.5.1-tb+sb.xpi
[2009/03/24 11:47:50 | 00,713,752 | —- | C] () – C:\Documents and Settings\popop\Desktop\foxclocks-2.5.11-fx+tb+sb+sm.xpi
[2009/03/08 22:13:08 | 00,595,160 | R— | C] () – C:\WINDOWS\System32\wodCertificate.dll
[2009/03/08 22:13:08 | 00,053,248 | R— | C] () – C:\WINDOWS\System32\zlib.dll
[2009/02/04 12:06:35 | 00,003,659 | —- | C] () – C:\WINDOWS\iexplore.ini
[2008/10/12 14:24:10 | 00,072,240 | —- | C] () – C:\WINDOWS\System32\vmgina.dll
[2008/10/12 14:23:10 | 00,055,856 | —- | C] () – C:\WINDOWS\System32\vnetinst.dll
[2008/03/13 17:12:13 | 00,000,250 | —- | C] () – C:\WINDOWS\wcx_ftp.ini
[2008/02/18 16:31:02 | 00,004,098 | —- | C] () – C:\WINDOWS\WINCMD.INI
[2008/02/18 11:07:43 | 00,000,052 | —- | C] () – C:\WINDOWS\RTFContentCtrl.INI
[2008/02/15 17:21:43 | 00,009,216 | —- | C] () – C:\WINDOWS\System32\drivers\FlashSys.sys
[2008/02/15 17:12:12 | 00,000,504 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/02/15 16:45:45 | 00,639,046 | —- | C] () – C:\WINDOWS\aticlocklib.dll
[2008/02/15 16:45:45 | 00,110,592 | —- | C] () – C:\WINDOWS\R5ClkLib.dll
[2008/02/15 16:45:44 | 00,046,080 | —- | C] () – C:\WINDOWS\System32\aseng.dll
[2008/02/15 16:45:44 | 00,011,136 | —- | C] () – C:\WINDOWS\System32\ATKOSDMini.DLL
[2008/02/15 16:45:44 | 00,000,018 | —- | C] () – C:\WINDOWS\System32\atkid.ini
[2008/02/15 15:49:55 | 00,050,666 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2008/02/15 15:49:55 | 00,010,793 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2008/02/15 15:49:53 | 00,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2008/02/15 15:33:05 | 00,716,272 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2008/02/15 14:42:27 | 00,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2008/02/15 14:39:34 | 00,000,164 | R— | C] () – C:\WINDOWS\avrack.ini
[2008/02/15 10:27:31 | 00,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[2007/09/06 16:12:02 | 00,851,968 | R— | C] () – C:\WINDOWS\System32\libeay32.dll
[2007/09/06 16:12:02 | 00,159,744 | R— | C] () – C:\WINDOWS\System32\ssleay32.dll
[2007/01/03 12:24:36 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 12:22:46 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 12:22:14 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/03/22 14:00:00 | 00,179,577 | —- | C] () – C:\WINDOWS\System32\schema.ini
[2006/03/22 14:00:00 | 00,024,819 | —- | C] () – C:\WINDOWS\System32\ntdsctrs.ini
[2006/03/22 14:00:00 | 00,020,386 | —- | C] () – C:\WINDOWS\System32\ntfrsrep.ini
[2006/03/22 14:00:00 | 00,011,817 | —- | C] () – C:\WINDOWS\System32\iasperf.ini
[2006/03/22 14:00:00 | 00,011,030 | —- | C] () – C:\WINDOWS\System32\ipsecprf.ini
[2006/03/22 14:00:00 | 00,005,597 | —- | C] () – C:\WINDOWS\System32\ntfrscon.ini
[2006/03/22 14:00:00 | 00,000,624 | —- | C] () – C:\WINDOWS\win.ini
[2006/03/22 14:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[8 C:\WINDOWS\*.tmp files]
[2009/04/22 18:17:09 | 00,004,098 | —- | M] () – C:\WINDOWS\WINCMD.INI
[2009/04/22 17:51:09 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\popop\Desktop\OTListIt2.exe
[2009/04/22 16:46:27 | 00,000,950 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2372228490-329967842-557336892-1517.job
[2009/04/22 16:36:27 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/22 16:36:26 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/22 11:59:53 | 00,000,706 | —- | M] () – C:\Documents and Settings\popop\Desktop\WinDirStat.lnk
[2009/04/22 08:32:20 | 02,643,434 | -H– | M] () – C:\Documents and Settings\popop\Local Settings\Application Data\IconCache.db
[2009/04/22 08:29:36 | 01,529,241 | —- | M] () – C:\Documents and Settings\popop\Desktop\SDFix.exe
[2009/04/21 09:50:11 | 00,010,927 | —- | M] () – D:\VovinDocuments\Requests.xlsx
[2009/04/21 08:47:08 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/08 11:39:28 | 00,106,068 | —- | M] () – C:\WINDOWS\System32\tsmmc.msc
[2009/04/07 09:21:25 | 00,738,094 | —- | M] () – C:\Documents and Settings\popop\Desktop\Japan_wiki.pdf
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 13:34:12 | 00,001,734 | —- | M] () – C:\Documents and Settings\popop\Desktop\HijackThis.lnk
[2009/04/06 13:15:50 | 00,769,566 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/06 13:15:50 | 00,621,526 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/06 13:15:50 | 00,132,946 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/06 10:23:37 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/03/31 15:49:19 | 34,927,8208 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2009/03/31 15:05:08 | 00,000,250 | —- | M] () – C:\WINDOWS\wcx_ftp.ini
[2009/03/31 10:16:46 | 00,917,320 | —- | M] () – C:\Documents and Settings\popop\Desktop\SPIEFolder.zip
[2009/03/31 09:56:01 | 00,981,744 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\popop\Desktop\SMIGRATE.exe
[2009/03/31 09:39:16 | 00,001,790 | -H– | M] () – D:\VovinDocuments\Default.rdp
[2009/03/30 09:53:08 | 00,718,869 | —- | M] () – C:\Documents and Settings\popop\Desktop\AuditUpdatePatchManagement.zip
[2009/03/27 12:08:51 | 01,212,516 | —- | M] () – C:\Documents and Settings\popop\Desktop\supergstunt_trial_v.zip
[2009/03/26 04:39:16 | 00,002,290 | —- | M] () – C:\Documents and Settings\popop\Desktop\Google Chrome.lnk
[2009/03/25 11:32:22 | 00,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/03/25 11:16:40 | 00,001,024 | —- | M] () – C:\.rnd
[2009/03/24 11:48:44 | 00,037,658 | —- | M] () – C:\Documents and Settings\popop\Desktop\duplicate_contact_manager-0.6-tb.xpi
[2009/03/24 11:48:20 | 00,054,164 | —- | M] () – C:\Documents and Settings\popop\Desktop\thunderbirthday-0.2.8.1-tb.xpi
[2009/03/24 11:48:04 | 00,110,142 | —- | M] () – C:\Documents and Settings\popop\Desktop\provider_for_google_calendar-0.5.1-tb+sb.xpi
[2009/03/24 11:47:50 | 00,713,752 | —- | M] () – C:\Documents and Settings\popop\Desktop\foxclocks-2.5.11-fx+tb+sb+sm.xpi
< End of report >



OTListIt Extras logfile created on: 4/22/2009 18:16:48 - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\popop\Desktop
Windows Server 2003 Standard Edition Service Pack 2 (Version = 5.2.3790) - Type = NTServer
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 2046;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.23 Gb Total Space | 34.57 Gb Free Space | 49.93% Space Free | Partition Type: NTFS
Drive D: | 117.07 Gb Total Space | 18.93 Gb Free Space | 16.17% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VOVIN
Current User Name: popop
NOT logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/10/12 14:23:32 | 00,121,392 | —- | M] (VMware, Inc.) – C:\Program Files\VMware\VMware Server\vmware-authd.exe:*:Enabled:VMware Authd
[2008/10/12 14:24:26 | 00,322,096 | —- | M] () – C:\Program Files\VMware\VMware Server\vmware-hostd.exe:*:Enabled:VMware Hostd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0143B068-21C6-4727-8B95-B496EA70F298}" = Network Recording Player
"{05EC21B8-4593-3037-A781-A6B5AFFCB19D}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools - enu
"{082BDF7B-4810-4599-BF0D-E3AC44EC8524}" = Microsoft ASP.NET 2.0 AJAX Extensions 1.0
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0B43A744-B1B8-4089-9BD1-9D41C7EC0AA3}" = Microsoft SQL Server 2005 Books Online (English)
"{0CBC9A39-5A64-446E-8D6B-0E75987D9425}" = ASUS ATI Driver
"{0DF3AE91-E533-3960-8516-B23737F8B7A2}" = Visual C++ 2008 x64 Runtime - (v9.0.30729)
"{0DF3AE91-E533-3960-8516-B23737F8B7A2}.vc_x64runtime_30729_01" = Visual C++ 2008 x64 Runtime - v9.0.30729.01
"{154CAED8-8A01-4488-B259-3AEF36FF78A9}" = IISGuard
"{1C56BD1C-F2A0-4D96-B68C-BBEA9DF9961C}" = grepWin
"{1CBE3804-20DF-48DA-B048-895C206E80A5}" = Microsoft SQL Server VSS Writer
"{22E23C71-C27A-3F30-8849-BB6129E50679}" = Visual C++ 2008 IA64 Runtime - (v9.0.30729)
"{22E23C71-C27A-3F30-8849-BB6129E50679}.vc_i64runtime_30729_01" = Visual C++ 2008 IA64 Runtime - v9.0.30729.01
"{23E5C72C-CC08-4EE0-9CC2-D925B232B331}" = Microsoft MSDN 2005 Express Edition - ENU
"{2515BF88-E42E-4AFA-A8E7-DF272762589B}" = Microsoft Office Live Meeting 2007
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{2CB71008-9610-48B3-AC43-05AEDA92EA8F}_is1" = SubSonic 2.1 Final
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Gamer OSD
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3A762A82-618D-3CAA-B847-D074ABFA0B2E}" = MSDN Library for Visual Studio 2008 - ENU
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{49C69876-0196-4620-B237-EA334C2E40B5}" = ActivePerl 5.10.0 Build 1002
"{4D2DFB70-AECB-47BF-A895-3B3AA544934F}" = Microsoft SQL Server 2005 Tools
"{4DC6EB24-629D-41D7-AB3E-E81872A8F9CC}" = TortoiseSVN 1.6.1.16129 (32 bit)
"{52B0D62A-860D-4136-9A8A-9FD877E8EE89}" = Microsoft SQL Server 2005 Analysis Services
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{64c5b887-b5ee-42b8-8596-78905a6b5f1f}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7D7E6D55-E338-4B4C-AD91-E750BFD2BA4C}" = Microsoft SQL Server 2005 Reporting Services
"{7F231232-C309-4401-964A-2A002B6E1ED9}" = Microsoft Baseline Security Analyzer 2.0.1
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{84F56ECD-CBA4-4853-92EE-97C931EDCFB3}_is1" = Cava Packager 1.3 Release 29 Build 686
"{8A7CAA24-7B23-410B-A7C3-F994B0944160}" = Microsoft Virtual PC 2007
"{8C62A94B-4AB6-485F-A111-93056684D340}" = SQLXML4
"{8E408A85-E0E5-4094-903F-8675707AC313}" = Microsoft SQL Server 2005 Integration Services
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}_VisualWebDeveloper_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}_PRJPROR_{75EC8FFC-B913-4991-B3A1-22576D2FC45D}" = Microsoft Office Project 2007 Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}_VisualWebDeveloper_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
"{91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{C1877F6E-C1C8-486D-A697-86431029690C}" = Microsoft Office Project 2007 Service Pack 1 (SP1)
"{91120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{92BD05AB-50DD-489D-BF5F-B3F009F693D5}" = VisualSVN Server 1.5.2
"{94160B78-D7C5-4706-8E03-9D8B3763C7DB}" = Microsoft Visual J# 2005 Express Edition - ENU
"{96327C3C-96BE-4C7A-A6F7-A71635E5949A}" = Microsoft SQL Server 2005 Backward compatibility
"{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone
"{96C267DA-0926-4C11-B4E7-4D3EF85130D0}" = Paint.NET v3.22
"{9862B19F-4CAD-4EED-920F-2F378D84393F}" = ATI Parental Control & Encoder
"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.3
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A689F084-B901-470F-AD24-9A83F7382B67}" = AnkhSVN 2.0.4757.115
"{AA467959-A1D6-4F45-90CD-11DC57733F32}" = Crystal Reports Basic for Visual Studio 2008
"{AB82EDB5-9F7B-3C3C-A678-28016363063C}" = Microsoft FxCop 1.36 RTM
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{AF08C71F-F822-4416-87A9-2BBF5A8A5F12}" = VMware Server
"{B268E9A1-04A9-40D0-9866-846BE2B74BA7}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Win32 Tools
"{B32E7732-B2FB-3FD0-81AC-6025B1104C66}" = Microsoft Device Emulator version 3.0 - ENU
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B9EEA623-5396-4489-B542-6E6606286DD6}" = ATI Catalyst Control Center
"{BB4CF220-E5D3-4BBC-AFEB-B75C398416BC}" = CommitMonitor
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0B81E26-F7D0-4E84-941A-21C438BC586D}" = Microsoft SQL Server 2005 Notification Services
"{C25EF637-BE7A-4761-9B45-9069989C319F}" = Microsoft Visual Studio 2005 Premier Partner Edition - ENU
"{C312AE09-3ED8-4A9B-9DE5-2B95DDF60FA0}" = Visual C# 2005 Code Snippets
"{C3763892-4535-4B42-B6E3-A40E1C07F489}" = Perforce P4Win Components
"{C3763892-4535-4B42-B6E3-A40E1C07F489}-Visible" = Perforce P4Win Components
"{C7EA29FC-78F2-4680-9D9B-22CA8191E63C}" = Microsoft Visual SourceSafe 2005 - ENU
"{C7F8BA7C-3ABC-4BBA-BCC1-BE5030E59439}" = ILMerge
"{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}" = AVIVO Codecs
"{CAA376AF-0DE8-4FCA-942E-C6AC579B94B3}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Tools
"{CC98E8B3-FAAA-4D09-A813-A44C9FA1A3EE}" = Enterprise Architect 6.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D7DAD1E4-45F4-3B2B-899A-EA728167EC4F}" = Microsoft Visual Studio 2008 Professional Edition - ENU
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DFAA3D2B-7087-464E-823B-738A23C29C27}" = Microsoft Visual J# 2.0 Redistributable Package - SE
"{E0AAD4E6-B126-4431-98AB-36687DC338C0}" = SKYPE Recorder V4.0
"{EB76B218-8FC5-41DF-9F1F-7FF3E0448383}" = Microsoft SQL Server 2005
"{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2
"{EF8B6B5D-A38C-431A-81FF-2C8E3215C6A2}" = VMware Converter
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}" = Microsoft SQL Server Native Client
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"ActiveTouchMeetingClient" = WebEx
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"All ATI Software" = ATI - Software Uninstall Utility
"Architag XRay XML Editor" = Architag XRay XML Editor
"ATI Display Driver" = ATI Display Driver
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"CamStudio" = CamStudio
"CCleaner" = CCleaner (remove only)
"CollabNet Subversion" = CollabNet Subversion 1.5.0
"CruiseControl.NET CCTray" = CruiseControl.NET CCTray 1.2.1
"DiffUtils-2.8.7_is1" = GnuWin32: DiffUtils version 2.8.7
"DPack2_2008_is1" = DPack 2.8.4 for Microsoft Visual Studio 2008
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EnterpriseAM" = Eracent's Enterprise Asset Managment
"EnterpriseEM" = Eracent's Enterprise Entitlements Management
"EnterpriseLM" = Eracent's Enterprise Lifecycle Managment
"Fiddler2" = Fiddler2
"FileZilla Client" = FileZilla Client 3.2.3
"Gadu-Gadu" = Gadu-Gadu 7.7
"Genshi-py2.5" = Python 2.5 Genshi-0.4.4
"getPlus®_ocx" = getPlus®_ocx
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Inkscape" = Inkscape 0.45
"Konnekt" = Konnekt
"Launchy_21344213_is1" = Launchy 2.1.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft MSDN 2005 Express Edition - ENU" = Microsoft MSDN 2005 Express Edition - ENU
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual J# 2.0 Redistributable Package - SE" = Microsoft Visual J# 2.0 Redistributable Package - SE
"Microsoft Visual J# 2005 Express Edition - ENU" = Microsoft Visual J# 2005 Express Edition - ENU
"Microsoft Visual SourceSafe 2005 - ENU" = Microsoft Visual SourceSafe 2005 - ENU
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Microsoft Visual Studio 2008 Professional Edition - ENU" = Microsoft Visual Studio 2008 Professional Edition - ENU
"MiKTeX 2.7" = MiKTeX 2.7
"Mozilla Firefox (3.0.9)" = Mozilla Firefox (3.0.9)
"Mozilla Thunderbird ([removed])" = Mozilla Thunderbird ([removed])
"MSDN Library for Visual Studio 2008 - ENU" = MSDN Library for Visual Studio 2008 - ENU
"MSI Live Update 3" = MSI Live Update 3
"MultipleIEs_is1" = MultipleIEs
"NeroMultiInstaller!UninstallKey" = Nero Suite
"Ninotech Path Copy" = Ninotech Path Copy 4.0
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notepad++" = Notepad++
"PRJPROR" = Microsoft Office Project Professional 2007
"pysqlite-py2.5" = Python 2.5 pysqlite-2.4.0
"RapidSVN-0.9.8_is1" = RapidSVN-0.9.8
"RealAlt_is1" = Real Alternative 1.9.0
"setuptools-py2.5" = Python 2.5 setuptools-0.6c7
"svn-python-py2.5" = Python 2.5 svn-python-1.5.0
"Trac-py2.5" = Python 2.5 Trac-0.11b2
"Ttf2Pt1-3.4.4_is1" = Ttf2Pt1-3.4.4 Complete package, except sources (GnuWin32)
"VISPROR" = Microsoft Office Visio Professional 2007
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"VSNet2008CmdHere" = VS.NET 2008 Command Prompt Here PowerToy
"WIC" = Windows Imaging Component
"WinMerge_is1" = WinMerge [removed]
"WinRAR archiver" = Archiwizator WinRAR
"winscp3_is1" = WinSCP 4.1.6
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"HexCmp" = Hex Comparison (remove only)
"WinDirStat" = WinDirStat 1.1.2

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2372228490-329967842-557336892-1517\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"HexCmp" = Hex Comparison (remove only)
"WinDirStat" = WinDirStat 1.1.2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/22/2009 10:14:47 | Computer Name = VOVIN | Source = Apache Service | ID = 3299
Description = The Apache service named reported the following error: >>> [Wed Apr
22 16:14:47 2009] [notice] Disabled use of AcceptEx() WinSock2 API .

Error - 4/22/2009 10:36:48 | Computer Name = VOVIN | Source = Userenv | ID = 1053
Description = Windows cannot determine the user or computer name. (The specified
domain either does not exist or could not be contacted. ). Group Policy processing
aborted.

Error - 4/22/2009 10:37:10 | Computer Name = VOVIN | Source = Apache Service | ID = 3299
Description = The Apache service named reported the following error: >>> [Wed Apr
22 16:37:10 2009] [notice] Disabled use of AcceptEx() WinSock2 API .

Error - 4/22/2009 10:38:41 | Computer Name = VOVIN | Source = vmauthd | ID = 100
Description = Cannot connect to VMX: C:\Virtual Machines\W98\Windows 98.vmx

Error - 4/22/2009 10:38:43 | Computer Name = VOVIN | Source = vmauthd | ID = 100
Description = Cannot connect to VMX: D:\VMachines\EAM93\VEAM93.vmx

Error - 4/22/2009 11:51:58 | Computer Name = VOVIN | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Windows Application, SystemIndex Catalog

Details:
Unspecified
error (0x80004005)

Error - 4/22/2009 11:51:58 | Computer Name = VOVIN | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Windows Application, SystemIndex Catalog

Details:
Unspecified
error (0x80004005)

Error - 4/22/2009 11:51:59 | Computer Name = VOVIN | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Windows Application, SystemIndex Catalog

Details:
Unspecified
error (0x80004005)

Error - 4/22/2009 11:51:59 | Computer Name = VOVIN | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Windows Application, SystemIndex Catalog

Details:
Unspecified
error (0x80004005)

Error - 4/22/2009 12:16:22 | Computer Name = VOVIN | Source = Userenv | ID = 1006
Description = Windows cannot bind to eracent.pl domain. (Local Error). Group Policy
processing aborted.

[ System Events ]
Error - 4/22/2009 02:55:29 | Computer Name = VOVIN | Source = NETLOGON | ID = 5719
Description = This computer was not able to set up a secure session with a domain
controller
in domain ERACENT due to the following: %%1311 This may lead to authentication problems.
Make sure that this computer is connected to the network. If the problem persists,
please
contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller
for the specified domain, it sets up the secure session to the primary domain controller
emulator in the specified domain. Otherwise, this computer sets up the secure session
to any domain controller in the specified domain.

Error - 4/22/2009 02:55:40 | Computer Name = VOVIN | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 4/22/2009 02:57:06 | Computer Name = VOVIN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the VMware Host Agent service
to connect.

Error - 4/22/2009 02:57:06 | Computer Name = VOVIN | Source = Service Control Manager | ID = 7000
Description = The VMware Host Agent service failed to start due to the following
error: %%1053

Error - 4/22/2009 07:56:26 | Computer Name = VOVIN | Source = EventLog | ID = 6004
Description = A driver packet received from the I/O subsystem was invalid. The
data is the packet.

Error - 4/22/2009 10:13:24 | Computer Name = VOVIN | Source = NETLOGON | ID = 5719
Description = This computer was not able to set up a secure session with a domain
controller
in domain ERACENT due to the following: %%1311 This may lead to authentication problems.
Make sure that this computer is connected to the network. If the problem persists,
please
contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller
for the specified domain, it sets up the secure session to the primary domain controller
emulator in the specified domain. Otherwise, this computer sets up the secure session
to any domain controller in the specified domain.

Error - 4/22/2009 10:14:31 | Computer Name = VOVIN | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 4/22/2009 10:36:46 | Computer Name = VOVIN | Source = NETLOGON | ID = 5719
Description = This computer was not able to set up a secure session with a domain
controller
in domain ERACENT due to the following: %%1311 This may lead to authentication problems.
Make sure that this computer is connected to the network. If the problem persists,
please
contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller
for the specified domain, it sets up the secure session to the primary domain controller
emulator in the specified domain. Otherwise, this computer sets up the secure session
to any domain controller in the specified domain.

Error - 4/22/2009 10:37:08 | Computer Name = VOVIN | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 4/22/2009 11:44:00 | Computer Name = VOVIN | Source = TermServDevices | ID = 1111
Description = Driver HP Business Inkjet 2230/2280 required for printer HP Business
Inkjet 2230/2280 is unknown. Contact the administrator to install the driver before
you log in again.


< End of report >
Vovin,

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Tomk,

I have updated java as instructed and cleaned the java cache, then run antivirus:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
 Thursday, April 23, 2009
 Operating System: Microsoft Windows Server 2003, Standard Edition Service Pack 2 (build 3790)
 Kaspersky Online Scanner  version: 7.0.26.13
 Program database last update: Wednesday, April 22, 2009 18:26:24
 Records in database: 2069276
——————————————————————————–

Scan settings:
	Scan using the following database: extended
	Scan archives: yes
	Scan mail databases: yes

Scan area - My Computer:
	A:\
	C:\
	D:\
	E:\

Scan statistics:
	Files scanned: 822564
	Threat name: 6
	Infected objects: 11
	Suspicious objects: 0
	Duration of the scan: 08:43:21


File name / Threat name / Threats count
C:\Documents and Settings\popop\Application Data\Thunderbird\Profiles\oaac6gub.default\Mail\Local Folders\Archive Folders.sbd\Inbox	Infected: Trojan-PSW.Win32.Papras.w	1
C:\Documents and Settings\popop\Application Data\Thunderbird\Profiles\oaac6gub.default\Mail\Local Folders\Archive Folders.sbd\older	Infected: Trojan-Spy.HTML.Bayfraud.hc	1
C:\Documents and Settings\popop\Application Data\Thunderbird\Profiles\oaac6gub.default\Mail\Local Folders\Inbox	Infected: Trojan.Win32.Agent.bxge	1
C:\Documents and Settings\popop\Application Data\Thunderbird\Profiles\oaac6gub.default\Mail\Local Folders\Trash	Infected: Trojan.Win32.Agent.bxge	1
D:\Mail\_old2\my.pst	Infected: Trojan-Spy.HTML.Bayfraud.hc	1
D:\Mail\___old\my.pst	Infected: Trojan-Spy.HTML.Bayfraud.hc	1
D:\Programs\ipscan.exe	Infected: not-a-virus:NetTool.Win32.Portscan.c	1
D:\Programs\pstools\pskill.exe	Infected: not-a-virus:RiskTool.Win32.PsKill.k	1
D:\Programs\pstools\psshutdown.exe	Infected: not-a-virus:RiskTool.Win32.PsKill.au	1
D:\Programs\pstools\PsTools.zip	Infected: not-a-virus:RiskTool.Win32.PsKill.au	1
D:\Programs\pstools\PsTools.zip	Infected: not-a-virus:RiskTool.Win32.PsKill.k	1

The selected area was scanned.



Since I do not use outlook anymore, it is an option to delete pst files.
Vovin,

As you can see, you've got some contaminated email. They are several places: your inbox, your archived mail inbox, your archived mail "older", and your trash folder. Please go through each of those folders and delete everything you don't need/want/recognize. Odds are that the infected mail will have an attachment or at least a link. Don't open any attachments or click on any links.

Once you are done deleting, empty your trash folder.


If you don't need those .pst files, we'll just script them away.

Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTLI

:Files
D:\Mail\_old2\my.pst   
D:\Mail\___old\my.pst   
D:\Programs\ipscan.exe 

:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL2 log and a new HJT log.
Tomk,

OT2 Log:

========== PROCESSES ==========
Process explorer.exe killed successfully!
========== OTLISTIT ==========
========== FILES ==========
D:\Mail\_old2\my.pst moved successfully.
D:\Mail\___old\my.pst moved successfully.
D:\Programs\ipscan.exe moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\popop\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\vmware-temp\vmware-converter-2.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\hsperfdata_SYSTEM\3228 scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
 
OTListIt2 by OldTimer - Version 2.0.14.0 log created on 04232009_160102

Files moved on Reboot…
C:\WINDOWS\temp\vmware-temp\vmware-converter-2.log moved successfully.
File move failed. C:\WINDOWS\temp\hsperfdata_SYSTEM\3228 scheduled to be moved on reboot.

Registry entries deleted on Reboot…


and HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:03:14, on 4/23/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Eracent\EAS\EracentAuditSyncService.exe
c:\Eracent\EDA\EracentEDAService.exe
c:\EracentCli\EPA\EracentEPAService.exe
c:\EracentCli\EPM\EracentEPMService.exe
c:\EracentCli\EUA\EracentEUAService.exe
C:\Eracent\EMQS\EracentMQService.exe
c:\EracentCli\SUM\EracentSUMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\iisgSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Troxo\IISGuard\iisgWS.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\VMware\VMware Server\tomcat\bin\Tomcat6.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Eracent\EEDS\EracentEDService.exe
C:\Eracent\EEPAC\EracentEPACollector.exe
C:\Eracent\EEPMC\EracentEPMCollector.exe
C:\Eracent\ESUMC\EracentSUMCollector.exe
C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE
C:\Program Files\VMware\VMware Server\vmware-authd.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\EracentCli\EPM\epm.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\notepad.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\CCTray\cctray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
c:\windows\system32\inetsrv\w3wp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gmail.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = w3cache.icm.edu.pl:8080
O1 - Hosts: 209.85.137.125 gmail.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - Startup: CCTray.lnk = C:\Program Files\CCTray\cctray.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Program Files\Fiddler2\Fiddler.exe" (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware server\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware server\vsocklib.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233223353043
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233219652264
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eracent.pl
O17 - HKLM\Software\..\Telephony: DomainName = eracent.pl
O17 - HKLM\System\CCS\Services\Tcpip\..\{7C5877BA-9134-4104-80D1-BA4833DFFA4E}: NameServer = 192.168.0.16
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eracent.pl
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: EnterpriseEMTaskService - Unknown owner - C:\Inetpub\wwwroot\EnterpriseEM\EnterpriseEMTaskService\EnterpriseEMTaskService.exe
O23 - Service: EracentAuditProcessor - Eracent Corporation - C:\Eracent\EAP\EracentAuditProcessor.exe
O23 - Service: EracentAuditSyncService - Eracent Corporation - C:\Eracent\EAS\EracentAuditSyncService.exe
O23 - Service: EracentCMPService - Eracent Corporation - C:\Eracent\ECMP\EracentCMPService.exe
O23 - Service: EracentDTCService - Eracent Corporation - C:\Eracent\EDTC\EracentDTCService.exe
O23 - Service: EracentEDAService - Eracent Corporation - c:\Eracent\EDA\EracentEDAService.exe
O23 - Service: EracentEDService - Eracent Corporation - C:\Eracent\EEDS\EracentEDService.exe
O23 - Service: EracentEPACollector - Eracent Corporation - C:\Eracent\EEPAC\EracentEPACollector.exe
O23 - Service: EracentEPACollector8Legacy - Eracent Corporation - C:\Eracent\EEPAC8L\EracentEPACollector8L.exe
O23 - Service: EracentEPAService - Eracent Corporation - c:\EracentCli\EPA\EracentEPAService.exe
O23 - Service: EracentEPMBucketProcessor - Eracent Corporation - C:\Eracent\EBP\EracentEPMBucketProcessor.exe
O23 - Service: EracentEPMCollector - Eracent Corporation - C:\Eracent\EEPMC\EracentEPMCollector.exe
O23 - Service: EracentEPMCollector8L - Eracent Corporation - C:\Eracent\EEPMC8L\EracentEPMCollector8L.exe
O23 - Service: EracentEPMService - Eracent Corporation - c:\EracentCli\EPM\EracentEPMService.exe
O23 - Service: EracentEUAService - Eracent Corporation - c:\EracentCli\EUA\EracentEUAService.exe
O23 - Service: EracentMQService - Eracent Corporation - C:\Eracent\EMQS\EracentMQService.exe
O23 - Service: EracentNetworkProbe - Eracent Corporation - C:\Eracent\ENP\EracentNetworkProbe.exe
O23 - Service: EracentSUMCollector - Eracent Corporation - C:\Eracent\ESUMC\EracentSUMCollector.exe
O23 - Service: EracentSUMService - Eracent Corporation - c:\EracentCli\SUM\EracentSUMService.exe
O23 - Service: EracentTaskScheduler - Eracent Corporation - C:\Eracent\ETS\EracentTaskScheduler.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IISGuard Service (IISGuardSVC) - Troxo - C:\WINDOWS\system32\iisgSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: VMware Converter Service (ufad-p2v) - VMware, Inc. - C:\Program Files\VMware\VMware Converter\vmware-ufad.exe
O23 - Service: VisualSVN Server (VisualSVNServer) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: VMware Host Agent (VMwareHostd) - Unknown owner - C:\Program Files\VMware\VMware Server\vmware-hostd.exe
O23 - Service: VMware Server Web Access (VMwareServerWebAccess) - Apache Software Foundation - C:\Program Files\VMware\VMware Server\tomcat\bin\Tomcat6.exe
O23 - Service: VMware VSS Writer (vmwriter) - VMware, Inc. - C:\Program Files\VMware\VMware Server\vmVssWriter.exe

–
End of file - 10339 bytes
Vovin,

Log looks good. :D


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Tomk,

the original problem is still outstanding, Malaware reports a trojan and it does not delete it during reboot:


Malwarebytes' Anti-Malware 1.36
Database version: 2024
Windows 5.2.3790 Service Pack 2

4/24/2009 08:36:31
mbam-log-2009-04-24 (08-36-31).txt

Scan type: Quick Scan
Objects scanned: 94967
Time elapsed: 2 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\a (Trojan.Agent) -> Delete on reboot.

After reboot:

Malwarebytes' Anti-Malware 1.36
Database version: 2024
Windows 5.2.3790 Service Pack 2

4/24/2009 08:50:20
mbam-log-2009-04-24 (08-50-20).txt

Scan type: Quick Scan
Objects scanned: 94948
Time elapsed: 2 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\a (Trojan.Agent) -> Delete on reboot.
Tomk, one very interesting thing about this is that C:\a is a directory not a file. I renamed directory to C:\ab, run the scan one more time and Trojan was not reported. I renamed it back to C:\a and trojan was reported back again. Also checked when emptied the directory, and looks like trojan is still being detected. What would you advise?
Tomk, Last discovery lead me to perform the check on my laptop. I created folder C:\a and run malaware. It reported a trojan, so looks like this is false positive. thanks a lot for your time and help!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI