Hello Susan,
I have just now returned from a long weekend, so today I was able to generate the three logs that you suggested:
HJT, Combofix.exe, & Kaspersky
Step 1) HJT was run and I found that the O21 and O7 lines were removed after selecting ‘fixit’; however the O2 line remains after the HJT run and the O7 line returns upon reboot (hjt log file shown at bottom of this reply).
==================================================
==================================================
Step 2) combofix.exe successfully run and the log file is shown below:
peliades - 07-01-15 18:54:50.78 Service Pack 2
ComboFix 06.11.27 - Running from: "C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\Spyware_Malware"
((((((((((((((((((((((((((((((( Files Created from 2006-12-15 to 2007-01-15 ))))))))))))))))))))))))))))))))))
2007-01-12 13:13 d——– C:\Program Files\Common Files\Scanner
2007-01-12 13:13 d——– C:\Documents and Settings\All Users\Application Data\CA
2007-01-12 13:12 d——– C:\Program Files\CA
2007-01-12 12:59 73,728 –a—— C:\WINDOWS\system32\unacev2.dll
2007-01-12 12:59 40,960 –a—— C:\WINDOWS\system32\unrar.dll
2007-01-12 12:59 d——– C:\Program Files\PestPatrol
2007-01-12 10:17 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-01-11 16:39 d——– C:\Program Files\Spybot - Search & Destroy
2007-01-11 16:39 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-01-10 08:53 79,360 –a—— C:\WINDOWS\system32\swxcacls.exe
2007-01-10 08:53 6,052 –a—— C:\WINDOWS\system32\tmp.reg
2007-01-10 08:53 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-01-10 08:53 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-01-10 08:53 40,960 –a—— C:\WINDOWS\system32\swsc.exe
2007-01-10 08:53 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-01-10 08:53 135,168 –a—— C:\WINDOWS\system32\swreg.exe
2007-01-09 16:13 d——– C:\Program Files\Lavasoft
2007-01-09 16:13 d——– C:\Documents and Settings\peliades\Application Data\Lavasoft
2007-01-09 10:16 d——– C:\Program Files\Steganos Trace Destructor 6.5
2007-01-07 23:14 d——– C:\Program Files\Video ActiveX Object
2007-01-04 08:31 dr-h—– C:\Documents and Settings\peliades\Recent
2006-12-24 18:17 21,008 –a—— C:\WINDOWS\system\ctl3d.dll
2006-12-24 18:17 d——– C:\PSP
2006-12-24 18:17 d——– C:\Documents and Settings\peliades\WINDOWS
2006-12-18 22:16 d——– C:\Program Files\WinRAR
2006-12-17 17:14 d——– C:\Program Files\iPod
2006-12-17 17:13 d——– C:\Program Files\QuickTime
2006-12-17 17:13 d——– C:\Program Files\iTunes
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-15 18:40 ——– d——– C:\Program Files\Symantec AntiVirus
2007-01-15 08:14 ——– d——– C:\Program Files\Outlook Express
2007-01-15 08:14 ——– d——– C:\Program Files\Common Files\System
2007-01-15 08:13 ——– d——– C:\Program Files\Internet Explorer
2007-01-12 13:13 ——– d——– C:\Program Files\Common Files
2006-12-30 07:13 ——– d——– C:\Program Files\SlySoft
2006-12-29 03:58 40 —hs—- C:\Documents and Settings\peliades\Application Data\.zreglib
2006-12-17 17:14 ——– d——– C:\Documents and Settings\peliades\Application Data\Apple Computer
2006-12-17 11:37 ——– d—s—- C:\Documents and Settings\peliades\Application Data\Microsoft
2006-12-10 09:19 ——– d——– C:\Documents and Settings\peliades\Application Data\ArcSoft
2006-12-10 09:18 ——– d——– C:\Documents and Settings\peliades\Application Data\Sonic
2006-12-10 09:18 ——– d——– C:\Documents and Settings\peliades\Application Data\Leadertech
2006-12-10 09:01 ——– d——– C:\Program Files\HP DVD
2006-12-10 09:01 ——– d——– C:\Program Files\Hewlett-Packard
2006-12-10 09:00 ——– d——– C:\Program Files\Sonic
2006-12-10 08:59 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-12-10 08:59 ——– d——– C:\Program Files\PowerDVD
2006-12-10 08:59 ——– d——– C:\Program Files\CyberLink
2006-12-10 08:55 ——– d——– C:\Program Files\muvee autoProducer 3.0 - HPC
2006-12-10 08:55 ——– d——– C:\Program Files\Common Files\muvee Technologies
2006-12-10 08:55 ——– d——– C:\Program Files\Common Files\InstallShield
2006-12-10 08:53 ——– d——– C:\Program Files\ArcSoft
2006-12-10 08:52 ——– d——– C:\Program Files\Sonic_RecordNow
2006-12-10 08:52 ——– d——– C:\Program Files\Common Files\SureThing Shared
2006-12-10 08:52 ——– d——– C:\Program Files\Common Files\Sonic
2006-12-07 17:02 2174976 –a—— C:\WINDOWS\system32\wmvcore.dll
2006-12-07 06:20 ——– d——– C:\Program Files\MSXML 4.0
2006-11-28 15:34 ——– d——– C:\Program Files\Expert Choice
2006-11-28 15:33 ——– d——– C:\Program Files\Common Files\Software FX Shared
2006-11-28 15:33 ——– d——– C:\Program Files\Common Files\Data Dynamics
2006-11-21 06:33 ——– d——– C:\Program Files\Chevron
2006-11-18 18:44 60416 ——— C:\WINDOWS\system32\tzchange.exe
2006-11-08 12:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 –a—— C:\WINDOWS\system32\msxml4.dll
2006-11-02 05:46 88576 –a—— C:\WINDOWS\system32\hpf24r06.dll
2006-11-02 05:46 866816 –a—— C:\WINDOWS\system32\hpftbx06.exe
2006-11-02 05:46 78336 –a—— C:\WINDOWS\system32\hpfsrl06.dll
2006-11-02 05:46 7680 –a—— C:\WINDOWS\system32\hpfhrl06.dll
2006-11-02 05:46 68700 –a—— C:\WINDOWS\system32\hpfcom06.dll
2006-11-02 05:46 67380 –a—— C:\WINDOWS\system32\hpfpml06.dll
2006-11-02 05:46 56060 –a—— C:\WINDOWS\system32\hpfmem06.dll
2006-11-02 05:46 44856 –a—— C:\WINDOWS\system32\hpflpm06.dll
2006-11-02 05:46 29184 –a—— C:\WINDOWS\system32\hpfrsu06.dll
2006-11-02 05:46 27164 –a—— C:\WINDOWS\system32\hpfiop06.dll
2006-11-02 05:46 23040 –a—— C:\WINDOWS\system32\hpfhid06.exe
2006-11-02 05:46 195072 –a—— C:\WINDOWS\system32\hpfscp06.dll
2006-11-02 05:46 152064 –a—— C:\WINDOWS\system32\hpfdat06.dll
2006-11-02 05:46 134112 –a—— C:\WINDOWS\system32\hpfmlc06.dll
2006-11-02 05:46 125952 –a—— C:\WINDOWS\system32\hpfcfg06.exe
2006-11-02 05:46 1184768 –a—— C:\WINDOWS\system32\hpftrl06.dll
2006-11-02 05:46 115712 –a—— C:\WINDOWS\system32\hpflnk06.exe
2006-11-02 05:45 711168 –a—— C:\WINDOWS\system32\hpfimg06.dll
2006-11-02 05:45 33792 –a—— C:\WINDOWS\system32\hpfmon06.dll
2006-11-02 05:45 276992 –a—— C:\WINDOWS\system32\hpfcps06.dll
2006-11-02 05:45 260608 –a—— C:\WINDOWS\system32\hpfwin06.dll
2006-11-02 05:45 189440 –a—— C:\WINDOWS\system32\hpfmrl06.dll
2006-11-02 05:45 117760 –a—— C:\WINDOWS\system32\hpfrsa06.dll
2006-11-02 05:45 103936 –a—— C:\WINDOWS\system32\hpfcnt06.dll
2006-10-19 20:56 713216 –a—— C:\WINDOWS\system32\sxs.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Communicator"="\"C:\\Program Files\\Microsoft Office Communicator\\Communicator.exe\" /background"
"RecordNow!"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"WiseUser"="C:\\Program Files\\Chevron\\WiseUser\\WiseUser.exe"
"GIL Application Manager"="C:\\Program Files\\Chevron\\GIL Tools\\GILAppMgr.exe"
"ScCertProp"="C:\\Program Files\\Schlumberger\\Smart Cards and Terminals\\ScCertProp\\CertDeprop.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"NewProf"="\"C:\\Program Files\\Chevron\\GIL Tools\\newprof.exe\""
"DiskeeperSystray"="\"C:\\Program Files\\Executive Software\\Diskeeper\\DkIcon.exe\""
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"TpShocks"="TpShocks.exe"
"TPHOTKEY"="C:\\PROGRA~1\\Lenovo\\PkgMgr\\HOTKEY\\TPHKMGR.exe"
"Synchronization Manager"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,\
73,74,65,6d,33,32,5c,6d,6f,62,73,79,6e,63,2e,65,78,65,20,2f,6c,6f,67,6f,6e,\
00
"SMS Logon Server Batch File"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,73,79,73,\
74,65,6d,33,32,5c,72,75,6e,71,75,69,65,74,2e,65,78,65,20,43,3a,5c,57,49,4e,\
44,4f,57,53,5c,73,79,73,74,65,6d,33,32,5c,63,6d,64,2e,65,78,65,20,2f,63,20,\
25,6c,6f,67,6f,6e,73,65,72,76,65,72,25,5c,6e,65,74,6c,6f,67,6f,6e,5c,73,6d,\
73,6c,73,2e,62,61,74,00
"pdfSaver3"=""
"MMReminderService"="C:\\Program Files\\Mindjet\\MindManager 6\\MMReminderService.exe"
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"Share-to-Web Namespace Daemon"="C:\\Program Files\\Hewlett-Packard\\HP Share-to-Web\\hpgs2wnd.exe"
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe\""
"DVDTray"="\"C:\\Program Files\\HP DVD\\Umbrella\\DVDTray.exe\""
"DVDBitSet"="\"C:\\Program Files\\HP DVD\\Umbrella\\DVDBitSet.exe\" /NOUI"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"PPMemCheck"="C:\\PROGRA~1\\PESTPA~1\\PPMemCheck.exe"
"CaISSDT"="\"C:\\Program Files\\CA\\eTrust Internet Security Suite\\caissdt.exe\""
"eTrustPPAP"="\"C:\\Program Files\\CA\\eTrust Internet Security Suite\\eTrust PestPatrol Anti-Spyware\\PPActiveDetection.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,10,03,00,00,1f,00,00,00,e0,00,00,00,d6,00,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"StartRunNoHOMEPATH"=dword:00000001
"NoRecentDocsNetHood"=dword:00000001
"NoDFSTab"=dword:00000001
"ForceStartMenuLogOff"=dword:00000001
"Intellimenus"=dword:00000001
"NoAutoTrayNotify"=dword:00000001
"NoDesktopCleanupWizard"=dword:00000001
"DisablePersonalDirChange"=dword:00000001
"NoAutoUpdate"=dword:00000000
"NoWindowsUpdate"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"disablecad"=dword:00000000
"LegalNoticeCaption"="Legal Notice:"
"LegalNoticeText"="WARNING TO USERS: This system is for use by authorized users only. Any individual using this system,by such use,acknowledges and consents to the right of the company to monitor,access,use,and disclose any information generated,received,or stored on the systems,and waives any right of privacy or expectation of privacy on the part of that individual in connection with his or her use of this system. Unauthorized and/or improper use of this system,as delineated by corporate policies,is not tolerated and the company may take formal action against such individuals."
"RunLogonScriptSync"=dword:00000000
"HideStartupScripts"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"=dword:00000000
"NoToolbarCustomize"=dword:00000000
"NoBandCustomize"=dword:00000000
"NoRemoteRecursiveEvents"=dword:00000001
"NoCDBurning"=dword:00000001
"NoWelcomeScreen"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"isamonitor.exe"="C:\\Program Files\\Video ActiveX Object\\isamonitor.exe"
"none"="C:\\Program Files\\Video ActiveX Object\\pmsngr.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Data
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Data\Logon Users
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts\System
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts\System\Logoff
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts\System\Logon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts\System\Shutdown
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts\System\StartShell
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts\System\Startup
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts\User
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts\User\Logoff
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts\User\Logon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Run Once Scripts\User\StartShell
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System\Lock
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System\Logoff
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System\Logon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System\LogonStartup
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System\Shutdown
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System\StartScreenSaver
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System\StartShell
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System\Startup
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System\StopScreenSaver
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\System\Unlock
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\User
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\User\Lock
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\User\Logoff
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\User\Logon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\User\LogonStartup
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\User\StartScreenSaver
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\User\StartShell
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\User\StopScreenSaver
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GILNotify\Scripts\User\Unlock
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
Completion time: 07-01-15 18:56:31.93
C:\ComboFix.txt … 07-01-15 18:56
C:\ComboFix2.txt … 07-01-12 09:49
==================================================
==================================================
Step 3) Launch Kaspersky Online Scanner
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, January 15, 2007 9:27:25 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 15/01/2007
Kaspersky Anti-Virus database records: 244033
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 100563
Number of viruses found: 4
Number of infected objects: 17 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:54:50
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\peliades\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\peliades\Local Settings\Application Data\ApplicationHistory\GSCE.exe.8b6c191d.ini.inuse Object is locked skipped
C:\Documents and Settings\peliades\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\peliades\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\peliades\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\peliades\Local Settings\History\History.IE5\MSHist012007011520070116\index.dat Object is locked skipped
C:\Documents and Settings\peliades\Local Settings\Temp\~DF6ECD.tmp Object is locked skipped
C:\Documents and Settings\peliades\Local Settings\Temp\~DF94FF.tmp Object is locked skipped
C:\Documents and Settings\peliades\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\backups\backup-20070112-091442-795.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\backups\backup-20070112-091847-233.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\backups\backup-20070112-091943-333.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\backups\backup-20070112-092008-109.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\backups\backup-20070112-094244-203.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\backups\backup-20070112-132222-342.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\backups\backup-20070112-132415-983.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\backups\backup-20070115-185000-376.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\backups\backup-20070115-185110-298.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\backups\backup-20070115-190509-797.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Documents and Settings\peliades\My Documents\Files2\Drmproj\Ggit\Reports\G&gp.doc Infected: Virus.MSWord.Concept skipped
C:\Documents and Settings\peliades\My Documents\Files2\Projects\Ggit\Reports\G&gp.doc Infected: Virus.MSWord.Concept skipped
C:\Documents and Settings\peliades\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\peliades\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\Chevron\GIL Tools\Guppe\Support.gup Object is locked skipped
C:\Program Files\Video ActiveX Object\isaddon.dll Infected: Trojan-Downloader.Win32.Zlob.bjo skipped
C:\Program Files\Video ActiveX Object\isamini.exe Infected: Trojan-Downloader.Win32.Zlob.bjj skipped
C:\Program Files\Video ActiveX Object\isamonitor.exe Infected: Trojan-Downloader.Win32.Zlob.bjj skipped
C:\Program Files\Video ActiveX Object\pmmon.exe Infected: Trojan-Downloader.Win32.Zlob.bke skipped
C:\Program Files\Video ActiveX Object\pmsngr.exe Infected: Trojan-Downloader.Win32.Zlob.bke skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\GSCEService.log Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\pfirewall.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\CcmExec.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\CertificateMaintenance.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\ClientIDManagerStartup.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\DataTransferService.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\execmgr.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\LocationServices.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\mtrmgr.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PatchInstall.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PatchUIMonitor.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PolicyAgent.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PolicyAgentProvider.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PolicyEvaluator.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\Scheduler.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\SrcUpdateMgr.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\StatusAgent.log Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\00000013.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\00000013.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\00000002.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\00000002.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\0000000A.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\0000000A.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\0000000H.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\0000000H.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\0000001A.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\0000001A.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\00000007.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\00000007.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000002.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000002.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\00000086.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\00000086.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\0000000M.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\0000000M.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\0000002B.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\0000002B.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\00000016.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\00000016.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\00000003.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\00000003.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000008.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000008.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_relayendpoint\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_relayendpoint\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000000K.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000000K.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\0000000E.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\0000000E.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\00000024.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\00000024.que Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\GILEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_350.dat Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_36c.dat Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_3b8.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
Scan process completed.
==================================================
==================================================
HJT Log after selecting and performing 'fixit' on O2, O7, and O21 lines
Logfile of HijackThis v1.99.1
Scan saved at 7:05:44 PM, on 1/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Altiris\eXpress\Credentials\AeXCredSvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
c:\navdef\gilgassv\gilgassv.exe
c:\program files\chevron\gil tools\gsce\gsceservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Chevron\GIL Tools\GILExec.exe
C:\Program Files\Altiris\eXpress\Credentials\AeXCredRun.exe
C:\Program Files\Video ActiveX Object\isamonitor.exe
C:\Program Files\Video ActiveX Object\pmsngr.exe
C:\Program Files\Video ActiveX Object\isamini.exe
C:\Program Files\Chevron\GIL Tools\GILAppMgr.exe
C:\Program Files\Video ActiveX Object\pmmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Mindjet\MindManager 6\MMReminderService.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Chevron\GILTOO~1\GSCE\GSCE.exe
C:\Documents and Settings\peliades\My Documents\Files\ZProgram Data\hjt\hjt3\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://myinside.chevron.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://myinside.chevron.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.oronite.com;*.chevroncreditcard.com;*.tengizchevroil.net;*.tengizchevroil.com;*.knowledgeplanet.com;*.*.texaco.com;*.chevrontexaco.net;*.chevrontexaco.com;*.chevron.net;*.chevron.com;*.bkk.unocal.com;*.ad.unocal.com;
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Program Files\Video ActiveX Object\isaddon.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: DeXa.Badge EPM IE SSO Module - {801BF87E-A000-11D3-81FE-00902741DE09} - C:\Program Files\Schlumberger\DeXa.Badge EPM\WebSSO.dll (file missing)
O2 - BHO: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [WiseUser] C:\Program Files\Chevron\WiseUser\WiseUser.exe
O4 - HKLM\..\Run: [GIL Application Manager] C:\Program Files\Chevron\GIL Tools\GILAppMgr.exe
O4 - HKLM\..\Run: [ScCertProp] C:\Program Files\Schlumberger\Smart Cards and Terminals\ScCertProp\CertDeprop.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NewProf] "C:\Program Files\Chevron\GIL Tools\newprof.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SMS Logon Server Batch File] C:\WINDOWS\system32\runquiet.exe C:\WINDOWS\system32\cmd.exe /c %logonserver%\netlogon\smsls.bat
O4 - HKLM\..\Run: [MMReminderService] C:\Program Files\Mindjet\MindManager 6\MMReminderService.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP DVD\Umbrella\DVDTray.exe"
O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: WorkPace 3.0.lnk = C:\Program Files\WorkPace 3.0\workpace.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Send to Mindjet MindManager - {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://myinside.chevron.com
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {8535D1E6-5BDD-4A29-B488-C0A553FAF29D} (ChvCITCOPLocal.OPLocal) -
http://gilop.chevrontexaco.com/ChvCITCOPLocal.CAB
O16 - DPF: {8FA85E15-012B-420F-A4E7-FF2B7AA9F9D6} (ChvCITCNetGILLocal.OPNetGIL) -
http://gilop.gap.chevrontexaco.com/ChvCITCNetGILLocal.CAB
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) -
http://h30155.www3.hp.com/ediags/dd/instal…edsolutions.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = bkkhq.chevrontexaco.net
O17 - HKLM\Software\..\Telephony: DomainName = bkkhq.chevrontexaco.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = bkkhq.chevrontexaco.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = bkkhq.chevrontexaco.net
O20 - Winlogon Notify: GILNotify - C:\Program Files\Chevron\GIL Tools\GILNotify.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O23 - Service: Altiris Credentials Service - Altiris Inc. - C:\Program Files\Altiris\eXpress\Credentials\AeXCredSvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: GIL Automated Signatures Service (GILGasSV) - - c:\navdef\gilgassv\gilgassv.exe
O23 - Service: GIL Security Compliance Enforcer (GSCEService) - ChevronTexaco - c:\program files\chevron\gil tools\gsce\gsceservice.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
Thanks for your help,
Regards,
–Phil