This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect Virus [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:55:23 PM, on 12/11/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IDT\WDM\stacsv.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\SYSTEM32\DWRCS.EXE
C:\Program Files\Common Files\Rockwell\EventServer.exe
C:\Program Files\Microsoft Forefront\Client Security\Client\SSA\FcsSas.exe
C:\Program Files\Rockwell Software\RSCommon\RSOBSERV.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Rockwell\NmspHost.exe
C:\Program Files\Common Files\Rockwell\RdcyHost.exe
C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe
C:\PROGRA~1\ROCKWE~1\RSLinx\RSLINX.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
c:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
C:\Program Files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe
C:\Program Files\Common Files\Rockwell\RnaDirServer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\Rockwell\RNADirMultiplexor.exe
C:\WINDOWS\SYSTEM32\DWRCST.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Microsoft Lync\communicator.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe
C:\Program Files\Microsoft Lync\UcMapi.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://tranenettrn1/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=amproxy16:80;https=amproxy16:80;ftp=amproxy16:80;gopher=amproxy16:80;socks=
amproxy16:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 206.44.*;159.112.*;170.205.*;198.80.*;192.168.*;tlruscad01.am.corp.priv;tlruscad
02.am.corp.priv;*.corp.priv;*.corp.pub;*.na.trane.com;*.local;*.CORP.IRCO.COM;*.I
NGERRAND.COM;directory.netmeeting.microsoft.com;
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Lync add-on BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DellControlPoint] "c:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe"
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
O4 - HKLM\..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Communicator] "C:\Program Files\Microsoft Lync\communicator.exe" /fromrunkey
O4 - HKLM\..\Run: [Microsoft Forefront Client Security Antimalware Service] "C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [UsbCipHelper] C:\Program Files\Rockwell Automation\Rockwell Automation USB CIP Driver Package\UsbCipHelper\UsbCipHelper.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [DameWare MRC Agent] C:\WINDOWS\system32\DWRCST.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [Zqwzmrg] rundll32 "C:\WINDOWS\system32\wmipropf.dll",Gebl
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Dell ControlPoint System Manager.lnk = C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
O4 - Global Startup: TdmNotify.lnk = C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe
O4 - Global Startup: VPN Client.lnk = ?
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Lync\OCHelper.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.contactondemand.com
O15 - Trusted Zone: *.corio.com
O15 - Trusted Zone: *.corp
O15 - Trusted Zone: *.crmondemand.com
O15 - Trusted Zone: *.dell.com
O15 - Trusted Zone: *.eprintview.com
O15 - Trusted Zone: *.HODESIQ.COM
O15 - Trusted Zone: *.midicorp.com
O15 - Trusted Zone: *.oracle.com
O15 - Trusted Zone: *.safeway.com
O15 - Trusted Zone: *.skillsoft.com
O15 - Trusted Zone: http://*.stproject
O15 - Trusted IP range: http://10.80.9.118
O15 - Trusted IP range: http://216.115.165.51
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1283960409375
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1283960402968
O16 - DPF: {88DD90B6-C770-4CFF-B7A4-3AFD16BB8824} (Crystal Reports Print Control 12.0) - http://bdg-rv-cryrpt01/crystalreportviewer…rintControl.cab
O16 - DPF: {D5B680E5-9C5F-45E0-A97C-521D4F281173} (PJ12ENUC Class) - http://project.corp.irco.com/rshvac_pwa/_l…033/pjcintl.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E3089160-E8AD-4C5B-B47C-ADDF3DF660DD} (PjAdoInfo4 Class) - http://project.corp.irco.com/rshvac_pwa/_l…ts/pjclient.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CORP.IRCO.COM
O17 - HKLM\Software\..\Telephony: DomainName = corp.irco.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = CORP.IRCO.COM
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = CORP.IRCO.COM,INGERRAND.COM,MGDIR.IRCO.COM
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = CORP.IRCO.COM
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = CORP.IRCO.COM,INGERRAND.COM,MGDIR.IRCO.COM
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = CORP.IRCO.COM,INGERRAND.COM,MGDIR.IRCO.COM
O20 - Winlogon Notify: TPSvc - TPSvc.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Dell ControlPoint Button Service (buttonsvc32) - Dell Inc. - c:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Dell ControlPoint System Manager (dcpsysmgrsvc) - Dell Inc. - c:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
O23 - Service: dnWhoDisp - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSLINX\dnwhodisp.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DWRCS.EXE
O23 - Service: Rockwell Event Multiplexer (EventClientMultiplexer) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe
O23 - Service: Rockwell Event Server (EventServer) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\EventServer.exe
O23 - Service: FactoryTalk Activation Service - Acresso Software Inc. - C:\Program Files\Rockwell Software\FactoryTalk Activation\lmgrd.exe
O23 - Service: FactoryTalk Activation Helper (FTActivationBoost) - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe
O23 - Service: Harmony - Rockwell Automation, Inc. - C:\Program Files\Rockwell Software\RSCommon\RSOBSERV.EXE
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Rockwell Namespace Services (NmspHost) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\NmspHost.exe
O23 - Service: Rockwell Redundancy Services (RdcyHost) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RdcyHost.exe
O23 - Service: FactoryTalk Diagnostics Local Reader (RNADiagnosticsService) - Rockwell Automation Inc. - C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe
O23 - Service: FactoryTalk Diagnostics CE Receiver (RNADiagReceiver) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RNADiagReceiver.exe
O23 - Service: Rockwell Directory Server (RNADirectory) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RnaDirServer.exe
O23 - Service: Rockwell Directory Multiplexer (RNADirMultiplexor) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RNADirMultiplexor.exe
O23 - Service: RSLinx Classic (RSLinx) - Rockwell Automation, Inc. - C:\PROGRA~1\ROCKWE~1\RSLinx\RSLINX.EXE
O23 - Service: Rockwell Application Services (RsvcHost) - Rockwell Automation, Inc. - C:\Program Files\Common Files\Rockwell\RsvcHost.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\stacsv.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 14640 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

Also…are you aware your system is set to run from a proxy server? Do you use this system to connect to work/school?
Yes, this is a work laptop. I compared the proxy settings with a desktop and they were identical. I not sure if the aswMBR finished scanning it hung up around 45 mins in.




dds.txt

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 22:00:34 on 2012-12-11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3510.2469 [GMT -5:00]
.
AV: Microsoft Forefront Client Security *Enabled/Outdated* {926A3D4F-E4E7-4F47-9902-4EDD55FFE1AF}
.
============== Running Processes ================
.
C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IDT\WDM\stacsv.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\SYSTEM32\DWRCS.EXE
C:\Program Files\Common Files\Rockwell\EventServer.exe
C:\Program Files\Microsoft Forefront\Client Security\Client\SSA\FcsSas.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Rockwell Software\RSCommon\RSOBSERV.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Rockwell\NmspHost.exe
C:\Program Files\Common Files\Rockwell\RdcyHost.exe
C:\Program Files\Common Files\Rockwell\RNADiagnosticsSrv.exe
C:\PROGRA~1\ROCKWE~1\RSLinx\RSLINX.EXE
C:\Program Files\Common Files\Rockwell\RsvcHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
c:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
C:\Program Files\Rockwell Software\FactoryTalk Activation\Tools\FTActivationBoost.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Rockwell\EventClientMultiplexer.exe
C:\Program Files\Common Files\Rockwell\RnaDirServer.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Rockwell\RNADirMultiplexor.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\SYSTEM32\DWRCST.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
C:\Program Files\Microsoft Lync\communicator.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k bthsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://tranenettrn1/
uProxyServer = hxxp=amproxy16:80;https=amproxy16:80;ftp=amproxy16:80;gopher=amproxy16:80;socks=
amproxy16:80
uProxyOverride = 206.44.*;159.112.*;170.205.*;198.80.*;192.168.*;tlruscad01.am.corp.priv;tlruscad
02.am.corp.priv;*.corp.priv;*.corp.pub;*.na.trane.com;*.local;*.CORP.IRCO.COM;*.I
NGERRAND.COM;directory.netmeeting.microsoft.com;
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - c:\program files\microsoft lync\OCHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [IAStorIcon] c:\program files\intel\intel® rapid storage technology\IAStorIcon.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe"
mRun: [USCService] c:\program files\dell\dell controlpoint\security manager\BcmDeviceAndTaskStatusService.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Communicator] "c:\program files\microsoft lync\communicator.exe" /fromrunkey
mRun: [Microsoft Forefront Client Security Antimalware Service] "c:\program files\microsoft forefront\client security\client\antimalware\MSASCui.exe" -hide
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [UsbCipHelper] c:\program files\rockwell automation\rockwell automation usb cip driver package\usbciphelper\UsbCipHelper.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [DameWare MRC Agent] c:\windows\system32\DWRCST.exe
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
mExplorerRun: [Zqwzmrg] rundll32 "c:\windows\system32\wmipropf.dll",Gebl
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autocad startup accelerator.lnk - c:\program files\common files\autodesk shared\acstart16.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\tdmnot~1.lnk - c:\program files\wave systems corp\trusted drive manager\TdmNotify.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpn client.lnk - c:\windows\installer\{b0bf7057-6869-4e4b-920c-ea2a58da07f0}\Icon3E5562ED7.ico
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-Explorer: NoSMConfigurePrograms = dword:1
uPolicies-Explorer: NoStartMenuMyMusic = dword:1
uPolicies-Explorer: ForceRunOnStartMenu = dword:1
uPolicies-Explorer: ForceStartMenuLogOff = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-System: dontdisplaylastusername = dword:1
mPolicies-System: legalnoticecaption = It Is An Offense To Continue Without Proper Authorization
mPolicies-System: legalnoticetext = Access to this system is restricted to authorized Ingersoll Rand employees or those individuals granted express permission by Ingersoll Rand. Unauthorized access is prohibited. Unauthorized login or attempts to circumvent this system's security may be recorded and used for prosecution.
mPolicies-Windows\System: AllowX-ForestPolicy-and-RUP = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - c:\program files\microsoft lync\OCHelper.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: mswsock.dll
Trusted Zone: authoria.net
Trusted Zone: contactondemand.com
Trusted Zone: corio.com
Trusted Zone: corp
Trusted Zone: crmondemand.com
Trusted Zone: dell.com
Trusted Zone: eprintview.com
Trusted Zone: hire.com
Trusted Zone: HODESIQ.COM
Trusted Zone: midicorp.com
Trusted Zone: oracle.com
Trusted Zone: safeway.com
Trusted Zone: skillsoft.com
Trusted Zone: stproject
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1283960409375
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1283960402968
DPF: {88DD90B6-C770-4CFF-B7A4-3AFD16BB8824} - hxxp://bdg-rv-cryrpt01/crystalreportviewers12/ActiveXControls/PrintControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {D5B680E5-9C5F-45E0-A97C-521D4F281173} - hxxp://project.corp.irco.com/rshvac_pwa/_layouts/pwa/objects/1033/pjcintl.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E3089160-E8AD-4C5B-B47C-ADDF3DF660DD} - hxxp://project.corp.irco.com/rshvac_pwa/_layouts/pwa/objects/pjclient.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{F7DACA41-CE85-45B1-B40F-EC89AB85E894} : DHCPNameServer = 192.168.1.1
Notify: igfxcui - igfxdev.dll
Notify: PCANotify - PCANotify.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 wvauth
.
============= SERVICES / DRIVERS ===============
.
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\drivers\stdcfltn.sys [2012-12-10 17648]
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\system32\drivers\dwvkbd.sys [2007-2-15 26624]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2009-11-20 278304]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2010-3-24 812448]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2010-3-24 27040]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2009-12-10 376608]
R2 FCSAM;Microsoft Forefront Client Security Antimalware Service;c:\program files\microsoft forefront\client security\client\antimalware\MsMpEng.exe [2011-1-8 16896]
R2 FcsSas;Microsoft Forefront Client Security State Assessment Service;c:\program files\microsoft forefront\client security\client\ssa\FcsSas.exe [2011-2-3 69528]
R2 FTActivationBoost;FactoryTalk Activation Helper;c:\program files\rockwell software\factorytalk activation\tools\FTActivationBoost.exe [2010-8-11 116072]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\intel\intel® rapid storage technology\IAStorDataMgrSvc.exe [2010-8-29 13336]
R2 NmspHost;Rockwell Namespace Services;c:\program files\common files\rockwell\NmspHost.exe [2010-11-1 224104]
R2 RdcyHost;Rockwell Redundancy Services;c:\program files\common files\rockwell\RdcyHost.exe [2010-11-1 224104]
R2 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [2010-8-29 59904]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [2010-12-13 43888]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2010-8-29 113664]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [2010-8-29 33832]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [2010-8-29 168616]
R3 EventServer;Rockwell Event Server;c:\program files\common files\rockwell\EventServer.exe [2010-11-1 250728]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-8-29 132480]
R3 IntcDAud;Intel® Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2010-8-29 260864]
R3 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-2-2 71296]
S1 VirtualBackplane;A-B Virtual Backplane;c:\windows\system32\drivers\virtualbackplane.sys –> c:\windows\system32\drivers\VirtualBackplane.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FactoryTalk Activation Service;FactoryTalk Activation Service;c:\program files\rockwell software\factorytalk activation\lmgrd.exe [2010-5-17 1122568]
S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2012-12-3 168232]
S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2011-6-2 11336]
S3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [2007-2-7 3712]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-25 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== File Associations ===============
.
FileExt: .scr: AutoCADScriptFile="c:\windows\system32\notepad.exe" "%1"
ShellExec: FRONTPG.EXE: edit=c:\progra~1\micros~3\office\FRONTPG.EXE
.
=============== Created Last 30 ================
.
2012-12-12 01:40:55 177496 —-a-w- c:\windows\system32\drivers\69971018.sys
2012-12-11 22:02:55 256904 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2012-12-11 20:01:17 81920 —-a-w- c:\windows\system32\igfxCoIn_v5408.dll
2012-12-11 19:54:31 ——– d—–w- c:\documents and settings\tradb\local settings\application data\Deployment
2012-12-11 18:16:25 ——– d—–w- c:\program files\SystemRequirementsLab
2012-12-11 16:15:27 177496 —-a-w- c:\windows\system32\drivers\91985902.sys
2012-12-11 16:12:53 ——– d—–w- C:\TDSSKiller_Quarantine
2012-12-11 15:12:57 177496 —-a-w- c:\windows\system32\drivers\95555706.sys
2012-12-11 04:44:57 ——– d—–w- c:\windows\pss
2012-12-11 03:36:56 17648 —-a-w- c:\windows\system32\drivers\stdcfltn.sys
2012-12-11 03:36:33 ——– d—–w- c:\program files\STMicroelectronics
2012-12-11 03:27:52 ——– d—–w- c:\documents and settings\tradb\local settings\application data\Threat Expert
2012-12-11 02:54:35 ——– d—–w- c:\documents and settings\tradb\application data\Registry Mechanic
2012-12-11 02:08:36 ——– d—–w- c:\documents and settings\tradb\application data\Product_RM
2012-12-11 02:07:47 ——– d—–w- c:\documents and settings\tradb\application data\PC Tools
2012-12-11 02:03:25 ——– d—–w- c:\program files\PC Tools
2012-12-11 01:59:03 202280 —-a-w- c:\windows\system32\drivers\PCTSD.sys
2012-12-11 01:59:01 ——– d—–w- c:\program files\common files\PC Tools
2012-12-11 01:57:01 ——– d—–w- c:\documents and settings\all users\application data\PC Tools
2012-12-11 01:56:55 ——– d—–w- c:\documents and settings\tradb\application data\TestApp
2012-12-07 16:34:44 ——– d—–w- c:\documents and settings\tradb\.thumbnails
2012-12-07 16:33:35 ——– d—–w- c:\documents and settings\tradb\local settings\application data\fontconfig
2012-12-07 16:33:32 ——– d—–w- c:\documents and settings\tradb\.gimp-2.8
2012-12-07 16:33:31 ——– d—–w- c:\documents and settings\tradb\local settings\application data\gegl-0.2
2012-12-06 20:34:57 118784 –sha-r- c:\windows\system32\wmipropf.dll
2012-12-06 19:50:32 ——– d—–w- c:\documents and settings\tradb\.RFIDEnterpriseGateway
2012-12-06 19:48:53 ——– d—–w- c:\program files\Alien RFID
2012-12-06 18:38:54 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2012-12-06 18:38:54 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2012-12-06 18:38:54 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2012-12-06 18:38:54 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2012-12-06 18:38:54 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2012-12-06 18:38:54 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2012-12-06 18:38:54 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2012-12-05 19:52:55 ——– d—–w- c:\documents and settings\tradb\local settings\application data\Help
2012-12-05 18:34:31 ——– d—–w- c:\documents and settings\all users\EMP NS Connection
2012-12-05 18:34:25 19584 —-a-w- c:\windows\system32\drivers\EP_NSWD.sys
2012-12-05 18:34:25 10064 —-a-w- c:\windows\system32\EP_NSDG.dll
2012-12-05 18:34:16 ——– d—–w- c:\program files\EPSON NSConnection
2012-12-05 18:33:14 57344 —-a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\ctor.dll
2012-12-05 18:33:14 237568 —-a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iscript.dll
2012-12-05 18:33:14 155648 —-a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iuser.dll
2012-12-05 18:33:13 692224 —-a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iKernel.dll
2012-12-05 18:33:13 5632 —-a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\DotNetInstaller.exe
2012-12-05 18:32:49 282756 —-a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\setup.dll
2012-12-05 18:32:49 163972 —-a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iGdi.dll
2012-12-04 20:20:16 31048 —-a-w- c:\windows\system32\drivers\point32.sys
2012-12-04 20:19:17 ——– d—–w- c:\program files\Microsoft IntelliPoint
2012-12-03 22:47:18 25600 -c–a-w- c:\windows\system32\dllcache\hidbth.sys
2012-12-03 22:47:18 25600 —-a-w- c:\windows\system32\drivers\hidbth.sys
2012-12-03 22:46:13 101120 -c–a-w- c:\windows\system32\dllcache\bthpan.sys
2012-12-03 22:46:13 101120 —-a-w- c:\windows\system32\drivers\bthpan.sys
2012-12-03 22:46:00 59136 -c–a-w- c:\windows\system32\dllcache\rfcomm.sys
2012-12-03 22:46:00 59136 —-a-w- c:\windows\system32\drivers\rfcomm.sys
2012-12-03 22:45:59 28160 -c–a-w- c:\windows\system32\dllcache\irmon.dll
2012-12-03 22:45:59 28160 —-a-w- c:\windows\system32\irmon.dll
2012-12-03 22:45:59 17024 -c–a-w- c:\windows\system32\dllcache\bthenum.sys
2012-12-03 22:45:59 17024 —-a-w- c:\windows\system32\drivers\BthEnum.sys
2012-12-03 22:45:59 151552 -c–a-w- c:\windows\system32\dllcache\irftp.exe
2012-12-03 22:45:59 151552 —-a-w- c:\windows\system32\irftp.exe
2012-12-03 22:45:58 8192 -c–a-w- c:\windows\system32\dllcache\wshirda.dll
2012-12-03 22:45:58 8192 —-a-w- c:\windows\system32\wshirda.dll
2012-12-03 22:45:50 168232 —-a-r- c:\windows\system32\drivers\bcbtums.sys
2012-12-03 22:45:49 18944 -c–a-w- c:\windows\system32\dllcache\bthusb.sys
2012-12-03 22:45:49 18944 —-a-w- c:\windows\system32\drivers\BTHUSB.SYS
2012-11-30 16:09:24 137000 —-a-w- c:\windows\system32\MsMapi32.ocx
2012-11-30 16:09:23 89360 —-a-w- c:\windows\system32\Vb5db.dll
2012-11-30 16:09:21 570128 —-a-w- c:\program files\common files\microsoft shared\dao\DAO350.DLL
2012-11-29 18:13:06 388096 —-a-r- c:\documents and settings\tradb\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-11-29 18:13:04 ——– d—–w- c:\program files\Trend Micro
2012-11-29 16:06:36 ——– d—–w- c:\documents and settings\tradb\Lync Recordings
2012-11-29 00:13:20 73728 —-a-w- c:\windows\system32\javacpl.cpl
2012-11-29 00:13:20 477168 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-11-28 19:59:41 ——– d—–w- c:\documents and settings\tradb\local settings\application data\Adobe
2012-11-28 18:51:00 ——– d—–w- c:\documents and settings\tradb\application data\Symantec
2012-11-28 18:48:29 ——– d—–w- c:\program files\Symantec
2012-11-28 18:48:29 ——– d—–w- c:\documents and settings\all users\application data\Symantec
2012-11-28 17:25:29 ——– d—–w- c:\documents and settings\tradb\application data\Xerox
2012-11-28 15:09:04 ——– d—–w- c:\program files\Atlas Copco Tools AB
2012-11-28 14:50:24 77824 —-a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2012-11-28 14:50:24 32768 —-a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2012-11-28 14:50:24 225280 —-a-w- c:\program files\common files\installshield\iscript\iscript.dll
2012-11-28 14:50:24 176128 —-a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2012-11-28 14:50:23 614532 —-a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2012-11-28 14:13:56 3308624 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft forefront\client security\client\antimalware\definition updates\backup\mpengine.dll
2012-11-28 14:13:42 6812136 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft forefront\client security\client\antimalware\definition updates\{7f31add8-d3de-4355-9e82-02cb1a34baa2}\mpengine.dll
2012-11-28 12:23:04 ——– d—–w- c:\documents and settings\tradb\local settings\application data\Autodesk
2012-11-28 12:23:04 ——– d—–w- c:\documents and settings\tradb\application data\Autodesk
2012-11-28 12:21:26 ——– d—–w- c:\documents and settings\all users\application data\Minitab
2012-11-28 12:21:18 ——– d—–w- c:\documents and settings\tradb\Tracing
2012-11-28 12:09:40 ——– d—–w- c:\program files\common files\Minitab Shared
2012-11-28 12:04:51 ——– d—–w- c:\program files\Microsoft Lync
2012-11-28 12:04:42 ——– d—–w- c:\program files\OCSetup
2012-11-27 16:05:23 ——– d—–w- C:\_SMSTaskSequence
2012-11-27 14:55:15 ——– d—–w- C:\TRN_IristaWMS11 (NEW)
2012-11-27 14:55:15 ——– d—–w- C:\PFiles
2012-11-27 14:55:11 ——– d—–w- C:\MDE_Report
2012-11-27 14:55:11 ——– d—–w- C:\Legacy
2012-11-27 14:52:24 ——– d—–w- C:\Kessler
2012-11-27 14:52:22 ——– d—–w- C:\crystalreportviewers12
2012-11-27 14:52:21 ——– d—–w- C:\Application
2012-11-27 14:21:41 ——– d—–w- c:\program files\Minitab
2012-11-27 13:47:17 ——– d—–w- c:\program files\USMT
2012-11-27 13:35:06 ——– d—–w- C:\_Legacy
2012-11-27 13:26:16 ——– d—–w- c:\program files\USMT4
2012-11-13 13:20:29 ——– d—–w- C:\RSLogix 5000
2012-11-13 13:14:27 ——– d—–w- c:\program files\RSLogix 5000 Module Profiles
2012-11-13 13:12:53 ——– d—–w- c:\documents and settings\all users\application data\Rockwell
.
==================== Find3M ====================
.
2012-12-11 03:35:20 81008 —-a-w- c:\windows\system32\accelernco01.dll
2012-12-11 03:35:20 43888 —-a-w- c:\windows\system32\drivers\Accelern.sys
2012-12-07 12:55:53 697272 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-07 12:55:51 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-29 00:13:12 473072 —-a-w- c:\windows\system32\deployJava1.dll
2012-10-25 08:12:26 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2012-10-25 08:12:26 69632 —-a-w- c:\windows\system32\QuickTime.qts
.
============= FINISH: 22:02:02.12 ===============


attach.txt

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 9/8/2010 11:28:05 AM
System Uptime: 12/11/2012 9:50:54 PM (1 hours ago)
.
Motherboard: Dell Inc. | | 04373Y
Processor: Intel® Core™ i5 CPU M 520 @ 2.40GHz | CPU 1 | 2394/533mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 149 GiB total, 107.437 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
2007 Microsoft Office Suite Service Pack 1 (SP1)
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Adobe Reader X (10.1.4)
Alien RFID User's Kit
Apple Application Support
Apple Software Update
Autodesk DWF Viewer
Autodesk Mechanical Desktop 2006
BioAPI Framework
Bootstrapper
Cisco Systems VPN Client 5.0.07.0290
Compatibility Pack for the 2007 Office system
Configuration Manager Client
DameWare Mini Remote Control Client Agent Service
Dell Control Point
Dell ControlPoint Security Manager
Dell ControlPoint System Manager
Dell ControlVault Host Components Installer
Dell Embassy Trust Suite by Wave Systems
Dell Security Device Driver Pack
Dell System Detect
Dell Touchpad
Document Manager Lite
DW WLAN Card Utility
EMBASSY Security Center
EMBASSY Security Setup
EMP NS Connection
ESC Home Page Plugin
FactoryTalk Activation Manager 3.30 (CPR 9 SR 3)
FactoryTalk Diagnostics 2.30.01 (CPR 9 SR 3)
FactoryTalk Services Platform 2.30.01 (CPR 9 SR 3)
Gemalto
Google Chrome
Google Update Helper
HASP Device Drivers
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB953955)
Hotfix for Windows XP (KB954434)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB958347)
Hotfix for Windows XP (KB959252)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB967048-v2)
Hotfix for Windows XP (KB968764)
Hotfix for Windows XP (KB969084)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
ICS Connect
Intel® Network Connections [removed]
Intel® Processor Graphics
Intel® Rapid Storage Technology
Java Auto Updater
Java™ 6 Update 37
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2572067)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Forefront Client Security Antimalware Service
Microsoft Forefront Client Security State Assessment Service
Microsoft IntelliPoint 6.3
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Lync 2010
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Meeting 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Project 2007 Add-in for Outlook
Microsoft Office Project 2007 Service Pack 2 (SP2)
Microsoft Office Project MUI (English) 2007
Microsoft Office Project Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Minitab 16
Minitab16
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser (KB973685)
MSXML 6.0 Parser (KB927977)
NTRU TCG Software Stack
OGA Notifier 2.0.0048.0
Oracle Data Provider for .NET Help
Oracle Enterprise Single Sign-on Password Reset Client
Parker Isysnet Analog Module Profiles
Parker Isysnet ASCII Module Profile
Parker Isysnet ControlNet Adapter Module Profile
Parker Isysnet Discrete Module Profiles
Parker Isysnet Discrete Module Profiles 2
Parker Isysnet Discrete Module Profiles 3
Parker Isysnet Ethernet Adapter Module Profile
PowerDVD DX
Preboot Manager
Private Information Manager
QuickTime
RDC
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Rockwell Automation 1440 XM Dynamic Measurement Module Profile
Rockwell Automation 1732 Discrete Module Profiles
Rockwell Automation 1732 Discrete Module Profiles 2
Rockwell Automation 1734 Analog Module Profiles
Rockwell Automation 1734 Analog Module Profiles 2
Rockwell Automation 1734 ASCII Module Profiles
Rockwell Automation 1734 ControlNet Adapter Module Profile
Rockwell Automation 1734 Discrete Module Profile, DeviceLogix
Rockwell Automation 1734 Discrete Module Profiles
Rockwell Automation 1734 Discrete Module Profiles 2
Rockwell Automation 1734 Discrete Module Profiles 4
Rockwell Automation 1734 Ethernet Adapter Module Profile
Rockwell Automation 1734 Ethernet Adapter,2-Port,Module Profile
Rockwell Automation 1734 Specialty Module Profiles
Rockwell Automation 1738 Analog Module Profiles
Rockwell Automation 1738 Analog Module Profiles 2
Rockwell Automation 1738 ASCII Module Profiles
Rockwell Automation 1738 ControlNet Adapter Module Profile
Rockwell Automation 1738 Discrete Module Profile, DeviceLogix
Rockwell Automation 1738 Discrete Module Profiles
Rockwell Automation 1738 Discrete Module Profiles 2
Rockwell Automation 1738 Discrete Module Profiles 3
Rockwell Automation 1738 Discrete Module Profiles 4
Rockwell Automation 1738 Ethernet Adapter Module Profile
Rockwell Automation 1738 Ethernet Adapter,2-Port,Module Profile
Rockwell Automation 1738 Specialty Module Profiles
Rockwell Automation 1756 CNet Comms Module Profiles
Rockwell Automation 1756 ENet Comms Module Profiles
Rockwell Automation 1756 Ethernet Bridge Module Profile
Rockwell Automation 1756 HART Module Profiles
Rockwell Automation 1756 Remote I/O Interface Module Profile
Rockwell Automation 1769 Analog Module Profiles
Rockwell Automation 1769 ASCII Module Profiles
Rockwell Automation 1769 Boolean Module Profiles
Rockwell Automation 1769 Controller Module Profiles
Rockwell Automation 1769 Discrete Module Profiles
Rockwell Automation 1769 Embedded Module Profiles
Rockwell Automation 1769 Specialty Module Profiles
Rockwell Automation 1783 Ethernet Managed Switch Module Profile
Rockwell Automation 1791DS Discrete Module Profiles
Rockwell Automation 1799 Embedded Discrete Module Profile
Rockwell Automation 2097 Kinetix Module Profiles
Rockwell Automation 48MS Vision Sensor Module Profiles
Rockwell Automation 5XRF RFID Reader Module Profiles
Rockwell Automation DIO DeviceNet Safety Module Profile
Rockwell Automation DIO DeviceNet Safety Module Profiles
Rockwell Automation DIO EtherNet Safety Module Profiles
Rockwell Automation Drives PowerFlex 4 Module Profiles
Rockwell Automation Drives PowerFlex 7 2 Module Profiles
Rockwell Automation Drives PowerFlex 7 3 Module Profiles
Rockwell Automation Drives PowerFlex 7 Module Profiles
Rockwell Automation Drives SCANport Module Profiles
Rockwell Automation EtherNet/IP Tap Family Module Profiles
Rockwell Automation Generic Safety Module Profiles
Rockwell Automation Kinetix CIP Motion Drive Module Profiles
Rockwell Automation PowerFlex CIP Motion Drive Module Profiles
Rockwell Automation Stratix 8000/8300 Module Profiles
Rockwell Windows Firewall Configuration Utility 1.00.05
RSLinx Classic 2.54.00 CPR 9 SR 1
RSLogix 5 English 7.30.10 (CPR 9)
RSLogix 500 English 8.10.00 (CPR 9)
RSLogix 5000 Module Profile Core
RSLogix 5000 Module Profile Core System Updates
RSLogix 5000 Module Profile Setup Utility
RSLogix 5000 Online Books v19.00.00
RSLogix 5000 Setup Installer
RSLogix 5000 Start Page Media v19.00.00
RSLogix 5000 System Updates
RSLogix 5000 v19.01.00 (CPR 9 SR 3)
Security Update for 2007 Microsoft Office System (KB2277947)
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office Outlook 2007 (KB980376)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office Publisher 2007 (KB982124)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2251419)
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2559049)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2183461)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2483614)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2536276)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982381)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Security Wizards
SquirrelView
Symantec pcAnywhere
System Requirements Lab for Intel
Tools Talk Power Focus
Trusted Drive Manager
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Project 2007 Help (KB963668)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Windows (KB971513)
Update for Outlook 2007 Junk Email Filter (KB2596560)
Update for Windows Internet Explorer 8 (KB2362765)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB982664)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2264107)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2492386)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2607712)
Update for Windows XP (KB898461)
Update for Windows XP (KB943729)
Update for Windows XP (KB951618-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB980182)
UPEK TouchChip Fingerprint Reader
VNC Free Edition 4.1.3
Wave Infrastructure Installer
Wave Support Software
WebFldrs XP
WIMGAPI
Windows Driver Package - Dell Inc. PBADRV System (09/11/2009 1.0.1.6)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live ID Sign-in Assistant
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows Rights Management Client Backwards Compatibility SP2
Windows Rights Management Client with Service Pack 2
XML Paper Specification Shared Components Pack 1.0
.
==== Event Viewer Messages From Past Week ========
.
12/6/2012 7:47:30 AM, error: FcsSas [10013] - Microsoft Update opt-in completed with errors. The Forefront Client Security State Assessment Service (FcsSas) failed to register the computer with Microsoft Update. Error Code: 0x80070424 Possible courses of action include: -Ensure the Windows Update Agent service (wuauserv) is enabled. -Manually opt-in to Microsoft Update through Windows Update.
12/6/2012 7:45:23 AM, error: DCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {24FF4FDC-1D9F-4195-8C79-0DA39248FF48} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
12/6/2012 7:42:29 AM, error: Service Control Manager [7034] - The FactoryTalk Activation Service service terminated unexpectedly. It has done this 1 time(s).
12/6/2012 7:42:26 AM, error: Service Control Manager [7000] - The DS1410D service failed to start due to the following error: The system cannot find the file specified.
12/6/2012 2:06:24 PM, error: NETLOGON [5719] - No Domain Controller is available for domain CORP due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
12/5/2012 7:42:48 AM, error: DCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {7E89FF0B-F649-4F9A-A9C3-F05DFAAA3DA1} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
12/11/2012 7:02:14 PM, error: Dhcp [1002] - The IP address lease 10.75.47.144 for the Network Card with network address C0CB380631F8 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
12/11/2012 5:57:51 PM, error: PlugPlayManager [11] - The device Root\LEGACY_TMCOMM\0000 disappeared from the system without first being prepared for removal.
12/11/2012 11:44:04 AM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address C0CB380631F8 has been denied by the DHCP server [removed] (The DHCP Server sent a DHCPNACK message).
12/10/2012 9:08:10 PM, error: PCTCore [280] -
12/10/2012 8:46:24 PM, error: ACPIEC [1] - \Device\ACPIEC: The embedded controller (EC) hardware didn't respond within the timeout period. This may indicate an error in the EC hardware or firmware, or possibly a poorly designed BIOS which accesses the EC in an unsafe manner. The EC driver will retry the failed transaction if possible.
12/10/2012 10:11:36 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
12/10/2012 10:02:58 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
.
==== End Of File ===========================


aswMBR


aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2012-12-11 22:05:40
—————————–
22:05:40.421 OS Version: Windows 5.1.2600 Service Pack 3
22:05:40.421 Number of processors: 4 586 0x2505
22:05:40.421 ComputerName: TRT-RL-4VWDVM1 UserName: tradb
22:05:41.234 Initialize success
22:06:52.109 AVAST engine defs: 12121101
22:07:15.640 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:07:15.640 Disk 0 Vendor: WDC_WD16 01.0 Size: 152627MB BusType: 8
22:07:15.656 Disk 0 MBR read successfully
22:07:15.656 Disk 0 MBR scan
22:07:15.703 Disk 0 Windows VISTA default MBR code
22:07:15.703 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
22:07:15.765 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152586 MB offset 80325
22:07:15.796 Disk 0 scanning sectors +312576705
22:07:15.906 Disk 0 scanning C:\WINDOWS\system32\drivers
22:07:38.562 Service scanning
22:08:24.781 Modules scanning
22:08:31.125 Disk 0 trace - called modules:
22:08:31.140 ntkrnlpa.exe CLASSPNP.SYS disk.sys stdcfltn.sys ACPI.sys hal.dll iaStor.sys
22:08:31.140 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b08d8a8]
22:08:31.140 3 CLASSPNP.SYS[b98e8fd7] -> nt!IofCallDriver -> [0x8b08de10]
22:08:31.140 5 stdcfltn.sys[b9cc9896] -> nt!IofCallDriver -> \Device\00000087[0x8b06a440]
22:08:31.140 7 ACPI.sys[b977f620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8b089028]
22:08:32.031 AVAST engine scan C:\WINDOWS
22:08:37.156 AVAST engine scan C:\WINDOWS\system32
22:15:22.296 AVAST engine scan C:\WINDOWS\system32\drivers
22:15:47.765 AVAST engine scan C:\Documents and Settings\tradb
22:18:48.406 AVAST engine scan C:\Documents and Settings\All Users
22:53:56.531 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\tradb\Desktop\MBR.dat"
22:53:56.531 The log file has been saved successfully to "C:\Documents and Settings\tradb\Desktop\aswMBR.txt"

I allowed the aswMBR scan to complete overnight. aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2012-12-11 22:05:40 —————————– 22:05:40.421 OS Version: Windows 5.1.2600 Service Pack 3 22:05:40.421 Number of processors: 4 586 0x2505 22:05:40.421 ComputerName: TRT-RL-4VWDVM1 UserName: tradb 22:05:41.234 Initialize success 22:06:52.109 AVAST engine defs: 12121101 22:07:15.640 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 22:07:15.640 Disk 0 Vendor: WDC_WD16 01.0 Size: 152627MB BusType: 8 22:07:15.656 Disk 0 MBR read successfully 22:07:15.656 Disk 0 MBR scan 22:07:15.703 Disk 0 Windows VISTA default MBR code 22:07:15.703 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 22:07:15.765 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152586 MB offset 80325 22:07:15.796 Disk 0 scanning sectors +312576705 22:07:15.906 Disk 0 scanning C:\WINDOWS\system32\drivers 22:07:38.562 Service scanning 22:08:24.781 Modules scanning 22:08:31.125 Disk 0 trace - called modules: 22:08:31.140 ntkrnlpa.exe CLASSPNP.SYS disk.sys stdcfltn.sys ACPI.sys hal.dll iaStor.sys 22:08:31.140 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b08d8a8] 22:08:31.140 3 CLASSPNP.SYS[b98e8fd7] -> nt!IofCallDriver -> [0x8b08de10] 22:08:31.140 5 stdcfltn.sys[b9cc9896] -> nt!IofCallDriver -> \Device\00000087[0x8b06a440] 22:08:31.140 7 ACPI.sys[b977f620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8b089028] 22:08:32.031 AVAST engine scan C:\WINDOWS 22:08:37.156 AVAST engine scan C:\WINDOWS\system32 22:15:22.296 AVAST engine scan C:\WINDOWS\system32\drivers 22:15:47.765 AVAST engine scan C:\Documents and Settings\tradb 22:18:48.406 AVAST engine scan C:\Documents and Settings\All Users 22:53:56.531 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\tradb\Desktop\MBR.dat" 22:53:56.531 The log file has been saved successfully to "C:\Documents and Settings\tradb\Desktop\aswMBR.txt" aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2012-12-11 22:58:13 —————————– 22:58:13.406 OS Version: Windows 5.1.2600 Service Pack 3 22:58:13.406 Number of processors: 4 586 0x2505 22:58:13.406 ComputerName: TRT-RL-4VWDVM1 UserName: tradb 22:58:14.812 Initialize success 22:58:31.375 AVAST engine defs: 12121101 22:58:33.015 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 22:58:33.015 Disk 0 Vendor: WDC_WD16 01.0 Size: 152627MB BusType: 8 22:58:33.031 Disk 0 MBR read successfully 22:58:33.031 Disk 0 MBR scan 22:58:33.093 Disk 0 Windows VISTA default MBR code 22:58:33.093 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 22:58:33.140 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152586 MB offset 80325 22:58:33.171 Disk 0 scanning sectors +312576705 22:58:33.312 Disk 0 scanning C:\WINDOWS\system32\drivers 22:59:04.234 Service scanning 22:59:51.312 Modules scanning 23:00:16.734 Disk 0 trace - called modules: 23:00:16.765 ntkrnlpa.exe CLASSPNP.SYS disk.sys stdcfltn.sys ACPI.sys hal.dll iaStor.sys 23:00:17.093 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b08d8a8] 23:00:17.093 3 CLASSPNP.SYS[b98e8fd7] -> nt!IofCallDriver -> [0x8b08de10] 23:00:17.093 5 stdcfltn.sys[b9cc9896] -> nt!IofCallDriver -> \Device\00000087[0x8b06a440] 23:00:17.093 7 ACPI.sys[b977f620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8b089028] 23:00:18.109 AVAST engine scan C:\WINDOWS 23:00:34.265 AVAST engine scan C:\WINDOWS\system32 23:10:35.812 AVAST engine scan C:\WINDOWS\system32\drivers 23:11:42.578 AVAST engine scan C:\Documents and Settings\tradb 23:16:41.125 AVAST engine scan C:\Documents and Settings\All Users 00:01:04.000 Scan finished successfully 06:26:26.296 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\tradb\Desktop\MBR.dat" 06:26:26.296 The log file has been saved successfully to "C:\Documents and Settings\tradb\Desktop\aswMBR.txt"
Hi,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Yes, this is a work laptop

Per our Terms of Use

We offer free computer help and tech support for home and personal use. We are not here to support others that work for profit, or to support/replace your company's IT department.

I would recommend that since this is a business computer, it might probably be in your best interest (and that of your clients) to just back up everything and reformat your system.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI