Windows Server 2003 R2 SP2 32 bit
After a number of hours the box will fail to log anyone in, after submitting login credential the login dialog box disappears just leaving the blue background. Hard shutdown required to fix. Nothing in the event logs. Also, attempts to get to windowsupdate.microsoft.com fails. "Internet Explorer cannot display the webpage"
One last thing - Malwarebytes is blocking attempts (in the background) to connect to 91.212.226.67 & 94.228.209.201 - in Russia and Amsterdam respectively.
Ran TFC and ERUNT.
Malwarebytes log follows:
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org
Database version: 3933
Windows 5.2.3790 Service Pack 2
Internet Explorer 7.0.5730.11
3/30/2010 11:55:31 AM
mbam-log-2010-03-30 (11-55-31).txt
Scan type: Quick scan
Objects scanned: 627315
Time elapsed: 8 minute(s), 54 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
*******************
no GMER log - GMER crashes server to bluescreen - see http://www.geekstogo...03-t272790.html
*******************
OTL.txt follows:
OTL logfile created on: 3/30/2010 4:43:36 PM - Run 2
OTL by OldTimer - Version 3.1.37.1 Folder = C:\Documents and Settings\Administrator.IONALTD\Desktop
Windows Server 2003 Server 2003 R2 Edition Service Pack 2 (Version = 5.2.3790) - Type = NTServer
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 75.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): c:\pagefile.sys 4096 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 67.67 Gb Total Space | 24.73 Gb Free Space | 36.54% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: IONA-CTX
Current User Name: administrator
NOT logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/03/29 15:24:54 | 000,303,952 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/03/29 15:24:52 | 000,437,584 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2010/03/29 09:01:00 | 002,064,224 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/03/29 09:00:33 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/03/15 13:00:51 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator.IONALTD\Desktop\OTL.exe
PRC - [2010/03/10 14:22:21 | 000,836,888 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2010/03/10 14:22:21 | 000,710,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/03/10 14:22:21 | 000,617,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/03/10 14:22:21 | 000,508,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/03/10 14:22:21 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2009/10/01 16:31:35 | 000,116,032 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2009/10/01 16:31:29 | 000,378,176 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2009/08/23 01:00:00 | 000,091,432 | ---- | M] (Sage) -- C:\Program Files\winsim\ConnectionManager\Simply.SystemTrayIcon.exe
PRC - [2009/08/23 01:00:00 | 000,029,992 | ---- | M] (Sage) -- C:\Program Files\winsim\ConnectionManager\SimplyConnectionManager.exe
PRC - [2009/04/17 21:42:56 | 000,428,592 | ---- | M] (VMware, Inc.) -- C:\Program Files\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe
PRC - [2009/04/05 09:41:12 | 000,122,880 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\Citrix\Ima\ImaSrv.exe
PRC - [2009/04/05 09:07:48 | 000,320,832 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Common Files\Citrix\System32\CdfSvc.exe
PRC - [2009/04/04 21:31:14 | 000,020,480 | ---- | M] (Citrix Systems, Inc) -- C:\Program Files\Citrix\HealthMon\HCAService.exe
PRC - [2009/04/04 21:15:14 | 000,102,400 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\wfshell.exe
PRC - [2009/04/04 21:15:08 | 000,036,864 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\ctxactivesync.exe
PRC - [2009/04/04 21:11:10 | 000,031,744 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\ctxxmlss.exe
PRC - [2009/04/04 21:09:14 | 000,172,032 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\encsvc.exe
PRC - [2009/04/04 21:04:56 | 000,061,440 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\cdmsvc.exe
PRC - [2009/04/04 21:04:06 | 000,360,448 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\CpSvc.exe
PRC - [2009/04/04 21:02:10 | 000,421,888 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\mfcom.exe
PRC - [2009/04/03 18:01:56 | 000,147,456 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\Citrix\Ima\IMAAdvanceSrv.exe
PRC - [2009/03/17 18:59:08 | 001,836,400 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\Licensing\LicWMI\Citrix_GTLicensingProv.exe
PRC - [2009/03/17 18:58:58 | 000,033,112 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\Licensing\LS\CtxLSPortSvc.exe
PRC - [2009/03/16 08:23:36 | 000,057,344 | ---- | M] (Apache Software Foundation) -- C:\Program Files\Citrix\Licensing\LMC\Tomcat\bin\tomcat6.exe
PRC - [2009/03/06 14:39:18 | 001,500,424 | ---- | M] (Acresso Software Inc.) -- C:\Program Files\Citrix\Licensing\LS\lmgrd.exe
PRC - [2009/03/06 14:39:00 | 001,631,568 | ---- | M] (Citrix Systems, Inc) -- C:\Program Files\Citrix\Licensing\LS\CITRIX.exe
PRC - [2008/11/24 23:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008/11/24 23:31:10 | 029,263,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
PRC - [2008/11/24 23:31:10 | 029,263,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
PRC - [2008/11/24 23:31:08 | 000,239,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2008/07/24 18:46:10 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2008/07/24 18:46:10 | 000,063,040 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2008/01/10 13:03:10 | 001,081,344 | ---- | M] (Accubid Systems) -- C:\Program Files\Accubid\Accubid Security\SecurityService2.exe
PRC - [2007/03/08 11:38:06 | 000,015,872 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\XTE\bin\XTE.exe
PRC - [2007/03/08 11:37:44 | 000,032,768 | ---- | M] (Citrix Systems Inc.) -- C:\Program Files\Citrix\Sma\SmaService.exe
PRC - [2007/03/08 11:37:26 | 000,032,144 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\ssonsvr.exe
PRC - [2007/03/07 22:31:24 | 000,737,872 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe
PRC - [2007/02/17 08:04:09 | 000,509,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\logon.scr
PRC - [2007/02/17 08:03:56 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rdpclip.exe
PRC - [2007/02/17 08:03:43 | 000,349,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\lserver.exe
PRC - [2007/02/17 08:03:42 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe
PRC - [2007/02/17 08:03:39 | 001,053,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/04/27 14:59:24 | 000,241,725 | ---- | M] (Microsoft Corporation) -- C:\Program Files\UPHClean\uphclean.exe
PRC - [2005/03/24 16:28:46 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ServerAppliance\appmgr.exe
PRC - [2005/03/24 16:28:46 | 000,079,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ServerAppliance\elementmgr.exe
PRC - [2003/03/24 23:10:10 | 000,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ServerAppliance\srvcsurg.exe
========== Modules (SafeList) ==========
MOD - [2010/03/15 13:00:51 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator.IONALTD\Desktop\OTL.exe
MOD - [2009/04/05 09:52:58 | 000,938,120 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\twnhook.dll
MOD - [2009/04/04 21:55:54 | 000,019,456 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\tzhook.dll
MOD - [2009/04/04 21:55:54 | 000,010,240 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\wdmaudhook.dll
MOD - [2009/04/04 21:55:52 | 000,122,880 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\scardhook.dll
MOD - [2009/04/04 21:55:52 | 000,069,632 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\mmhook.dll
MOD - [2009/04/01 17:30:14 | 000,251,208 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\mfaphook.dll
MOD - [2009/03/31 15:03:38 | 000,496,968 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\CtxSbxHook.DLL
MOD - [2007/03/08 11:37:58 | 000,008,192 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\System32\cxinjime.dll
MOD - [2007/02/18 00:26:08 | 001,051,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.3790.3959_x-ww_D8713E55\comctl32.dll
MOD - [2007/02/17 08:03:20 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winsta.dll
MOD - [2007/02/17 08:03:15 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\tsappcmp.dll
MOD - [2006/07/11 19:35:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcr71.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (gusvc)
SRV - File not found [On_Demand | Running] -- -- (CitrixXTEServer)
SRV - [2010/03/29 15:24:54 | 000,303,952 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/03/10 14:22:21 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2009/12/08 01:00:00 | 000,042,280 | ---- | M] (Sage) [On_Demand | Stopped] -- C:\Program Files\winsim\TransactionManager2010 - CDN\Sage_SA.TransactionManager.exe -- (Simply Accounting Transaction Manager 2010 - CDN)
SRV - [2009/10/01 16:31:35 | 000,116,032 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint)
SRV - [2009/08/23 01:00:00 | 000,029,992 | ---- | M] (Sage) [Auto | Running] -- C:\Program Files\winsim\ConnectionManager\SimplyConnectionManager.exe -- (Simply Accounting Database Connection Manager)
SRV - [2009/04/17 21:42:56 | 000,428,592 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe -- (vmware-converter-agent)
SRV - [2009/04/05 09:42:18 | 000,160,016 | ---- | M] (Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\Server Resource Management\CPU Utilization Management\bin\ctxcpusched.exe -- (ctxcpuSched)
SRV - [2009/04/05 09:42:08 | 000,053,520 | ---- | M] (Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\Server Resource Management\CPU Utilization Management\bin\ctxcpubal.exe -- (CTXCPUBal)
SRV - [2009/04/05 09:41:12 | 000,122,880 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Citrix\System32\Citrix\Ima\ImaSrv.exe -- (IMAService)
SRV - [2009/04/05 09:07:48 | 000,320,832 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Citrix\System32\CdfSvc.exe -- (CdfSvc)
SRV - [2009/04/04 21:31:14 | 000,020,480 | ---- | M] (Citrix Systems, Inc) [Auto | Running] -- C:\Program Files\Citrix\HealthMon\HCAService.exe -- (CitrixHealthMon)
SRV - [2009/04/04 21:26:40 | 000,139,264 | ---- | M] (Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\Server Resource Management\Memory Optimization Management\Program\CtxSFOSvc.exe -- (Citrix Virtual Memory Optimization)
SRV - [2009/04/04 21:15:08 | 000,036,864 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Citrix\System32\CtxActiveSync.exe -- (CtxActiveSync)
SRV - [2009/04/04 21:11:10 | 000,031,744 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Citrix\System32\ctxxmlss.exe -- (CtxHttp)
SRV - [2009/04/04 21:09:14 | 000,172,032 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Citrix\system32\encsvc.exe -- (Citrix Encryption Service)
SRV - [2009/04/04 21:04:56 | 000,061,440 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Citrix\System32\cdmsvc.exe -- (CdmService)
SRV - [2009/04/04 21:04:06 | 000,360,448 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Citrix\system32\CpSvc.exe -- (cpsvc)
SRV - [2009/04/04 21:02:10 | 000,421,888 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Citrix\System32\mfcom.exe -- (MFCom)
SRV - [2009/04/03 18:01:56 | 000,147,456 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Citrix\System32\Citrix\Ima\IMAAdvanceSrv.exe -- (IMAAdvanceSrv)
SRV - [2009/03/17 18:59:08 | 001,836,400 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Citrix\Licensing\LicWMI\Citrix_GTLicensingProv.exe -- (Citrix_GTLicensingProv)
SRV - [2009/03/17 18:58:58 | 000,033,112 | ---- | M] (Citrix Systems, Inc.) [Auto | Running] -- C:\Program Files\Citrix\Licensing\LS\CtxLSPortSvc.exe -- (CtxLSPortSvc)
SRV - [2009/03/16 08:23:36 | 000,057,344 | ---- | M] (Apache Software Foundation) [Auto | Running] -- C:\Program Files\Citrix\Licensing\LMC\Tomcat\bin\tomcat6.exe -- (CTXLMC)
SRV - [2009/03/06 14:39:18 | 001,500,424 | ---- | M] (Acresso Software Inc.) [Auto | Running] -- C:\Program Files\Citrix\Licensing\LS\lmgrd.exe -- (CitrixLicensing)
SRV - [2008/11/24 23:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008/11/24 23:31:10 | 029,263,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS)
SRV - [2008/11/24 23:31:10 | 029,263,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe -- (MSSQL$CITRIX_METAFRAME) SQL Server (CITRIX_METAFRAME)
SRV - [2008/11/24 23:31:08 | 000,239,968 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser)
SRV - [2008/11/24 23:31:08 | 000,045,408 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper)
SRV - [2008/08/20 23:23:00 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/07/24 18:46:10 | 000,063,040 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2008/01/10 13:03:10 | 001,081,344 | ---- | M] (Accubid Systems) [Auto | Running] -- C:\Program Files\Accubid\Accubid Security\SecurityService2.exe -- (AccubidSecurityServer2)
SRV - [2007/03/08 11:37:44 | 000,032,768 | ---- | M] (Citrix Systems Inc.) [Auto | Running] -- C:\Program Files\Citrix\Sma\SmaService.exe -- (Citrix SMA Service)
SRV - [2007/03/07 22:31:24 | 000,737,872 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe -- (BackupExecAgentAccelerator)
SRV - [2007/02/17 08:04:02 | 000,071,168 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\tssdis.exe -- (Tssdis)
SRV - [2007/02/17 08:03:58 | 000,067,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\rsopprov.exe -- (RSoPProv)
SRV - [2007/02/17 08:03:53 | 000,792,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\ntfrs.exe -- (NtFrs)
SRV - [2007/02/17 08:03:43 | 000,349,696 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\lserver.exe -- (TermServLicensing)
SRV - [2007/02/17 08:03:43 | 000,094,720 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\llssrv.exe -- (LicenseService)
SRV - [2007/02/17 08:03:42 | 000,040,448 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\ismserv.exe -- (IsmServ)
SRV - [2007/02/17 08:03:42 | 000,014,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (IISADMIN)
SRV - [2007/02/17 08:03:35 | 000,164,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\dfssvc.exe -- (Dfs)
SRV - [2007/02/17 08:02:54 | 000,216,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2006/09/02 16:36:33 | 002,528,960 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE -- (LiveUpdate)
SRV - [2005/04/27 14:59:24 | 000,241,725 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\UPHClean\uphclean.exe -- (UPHClean)
SRV - [2005/03/25 06:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\trksvr.dll -- (TrkSvr)
SRV - [2005/03/25 06:00:00 | 000,012,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\sacsvr.dll -- (sacsvr)
SRV - [2005/03/24 16:28:46 | 000,135,168 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\ServerAppliance\appmgr.exe -- (appmgr)
SRV - [2005/03/24 16:28:46 | 000,079,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\ServerAppliance\elementmgr.exe -- (elementmgr)
SRV - [2003/03/24 23:10:10 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\ServerAppliance\srvcsurg.exe -- (srvcsurg)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...m...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2009/05/24 12:08:44 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll File not found
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll File not found
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll File not found
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ConnectionManager] C:\Program Files\winsim\ConnectionManager\Simply.SystemTrayIcon.exe (Sage)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKCU..\Run: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ShowSuperHidden = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: microsoft.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] http in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell....iler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft....k/?linkid=67633 (Office Genuine Advantage Validation Tool)
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} http://fpdownload.ma...are/awswaxd.cab (Macromedia Authorware Web Player Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.aka...vex-2.2.4.6.cab (DLM Control)
O16 - DPF: {5685BC20-FBE6-11D2-885F-00A0243C2C64} https://pay.adp.ca/p...SpectrumRDC.cab (iVantage Remote Data Control)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.updat...b?1268370207709 (MUCatalogWebControl Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1235971580964 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1235971561415 (MUWebControl Class)
O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} https://pay.adp.ca/p...mmon/iemenu.cab (PopupMenu Object)
O16 - DPF: {8569D715-FF88-44BA-8D1D-AD3E59543DDE} https://ar.adp.ca/pa...mon/arview2.cab (ActiveReports Viewer2)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} http://www.pcpitstop.com/mhLbl.cab (mhLabel Class)
O16 - DPF: {A7A61128-0EAA-11D1-B22F-0000C08C00C4} https://pay.adp.ca/p...on/Ssdw3b32.cab (SSDBCombo Control 3.1 - A)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://accubid.webe...bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ionaltd.local
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (mfaphook.dll) - C:\Program Files\Citrix\system32\mfaphook.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (C:\WINDOWS\system32\ctxgina.dll) - C:\WINDOWS\system32\ctxgina.dll (Citrix Systems, Inc.)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - File not found
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\MetaFrame: DllName - ctxnotif.dll - C:\Program Files\Citrix\system32\ctxnotif.dll (Citrix Systems, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O30 - LSA: Security Packages - (ctxauth) - C:\WINDOWS\System32\ctxauth.dll (Citrix Systems, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/05/02 18:00:46 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\##itmnb-023#d\Shell - "" = AutoRun
O33 - MountPoints2\##itmnb-023#d\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\##itmnb-023#d\Shell\AutoRun\command - "" = Z:\autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007/09/26 21:22:02 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sacsvr - C:\WINDOWS\system32\sacsvr.dll (Microsoft Corporation)
NetSvcs: TrkSvr - C:\WINDOWS\system32\trksvr.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
SystemRestore not available.
========== Files/Folders - Created Within 14 Days ==========
[2010/03/30 13:03:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.IONALTD\Desktop\anti-malware logs
[2010/03/30 11:45:09 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 11:45:07 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/30 11:45:07 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/30 11:17:19 | 000,444,416 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator.IONALTD\Desktop\TFC.exe
[2010/03/10 14:18:10 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/10 14:18:10 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/03/10 14:18:09 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/03/10 14:18:09 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
========== Files - Modified Within 14 Days ==========
[2010/03/30 16:40:58 | 000,000,462 | RHS- | M] () -- C:\Documents and Settings\Administrator.IONALTD\ntuser.pol
[2010/03/30 16:04:09 | 000,778,110 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/30 16:04:09 | 000,625,618 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/03/30 16:04:09 | 000,136,082 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/03/30 15:59:43 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/03/30 15:59:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/03/30 15:57:57 | 006,029,312 | ---- | M] () -- C:\Documents and Settings\Administrator.IONALTD\NTUSER.DAT
[2010/03/30 15:57:57 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Administrator.IONALTD\ntuser.ini
[2010/03/30 15:57:56 | 003,774,394 | -H-- | M] () -- C:\Documents and Settings\Administrator.IONALTD\Local Settings\Application Data\IconCache.db
[2010/03/30 12:45:51 | 184,590,336 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2010/03/30 11:45:11 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/30 11:37:51 | 000,000,456 | ---- | M] () -- C:\Documents and Settings\Administrator.IONALTD\Desktop\Shortcut to it$ on env-cgy-fs001.lnk
[2010/03/30 05:36:19 | 058,253,661 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/29 15:24:58 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/29 15:24:46 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/21 14:37:34 | 000,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/03/19 18:24:37 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\SDMsgUpdate (TE).job
========== Files Created - No Company Name ==========
[2010/03/30 12:17:24 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Administrator.IONALTD\Desktop\gmer.exe
[2010/03/30 11:45:11 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/11/23 14:10:59 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS47.DLL
[2009/10/02 11:25:55 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\eST3snm.dll
[2009/10/02 11:22:30 | 000,423,936 | ---- | C] () -- C:\WINDOWS\System32\eST3snm6.dll
[2009/07/08 00:00:44 | 000,000,015 | ---- | C] () -- C:\WINDOWS\System32\drivers\dcesmwdm.sys
[2009/07/07 16:43:03 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\BiosMsg.dll
[2009/06/25 16:27:33 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\Administrator.IONALTD\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/04 22:27:20 | 000,004,592 | ---- | C] () -- C:\Program Files\Common Files\radecom.tlb
[2008/11/16 04:29:45 | 000,000,026 | ---- | C] () -- C:\WINDOWS\OutAboutOutlook.INI
[2008/09/10 14:49:40 | 000,229,376 | ---- | C] () -- C:\WINDOWS\System32\HPPCPR01.DLL
[2008/08/15 13:01:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\HPMProp.INI
[2008/07/15 17:57:46 | 000,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2008/06/07 18:05:15 | 000,561,160 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2008/06/07 16:32:32 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\AISAWFileMap.dll
[2008/05/08 15:57:55 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\HPP2800V.DLL
[2008/05/08 14:11:29 | 000,393,216 | ---- | C] () -- C:\WINDOWS\System32\eSTsnmp6.dll
[2008/05/08 13:23:47 | 000,018,560 | ---- | C] () -- C:\WINDOWS\System32\HPZuci12.dll
[2008/05/08 10:06:14 | 000,022,723 | ---- | C] () -- C:\WINDOWS\System32\sugg1l3.dll
[2008/05/06 12:02:03 | 000,000,144 | ---- | C] () -- C:\Documents and Settings\Administrator.IONALTD\Local Settings\Application Data\fusioncache.dat
[2008/01/16 15:17:10 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\VSHP2600.DLL
[2008/01/16 15:17:05 | 011,194,368 | ---- | C] () -- C:\WINDOWS\System32\ZHHP_RES.DLL
[2008/01/16 15:16:57 | 000,749,568 | ---- | C] () -- C:\WINDOWS\System32\AGISSI.DLL
[2007/10/02 13:56:38 | 000,002,296 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/09/25 10:21:51 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\setupnt.dll
[2007/09/13 14:28:21 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\eSTsnmp.dll
[2007/08/30 17:53:22 | 000,000,379 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/08/30 14:53:56 | 000,050,666 | ---- | C] () -- C:\WINDOWS\System32\w3ctrs.ini
[2007/08/30 14:53:56 | 000,011,435 | ---- | C] () -- C:\WINDOWS\System32\infoctrs.ini
[2007/08/30 14:53:56 | 000,010,793 | ---- | C] () -- C:\WINDOWS\System32\axperf.ini
[2007/08/17 23:31:55 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/08/17 23:12:10 | 000,000,439 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2007/08/06 11:07:30 | 000,008,784 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/05/18 00:00:00 | 000,017,920 | ---- | C] () -- C:\WINDOWS\System32\Implode.dll
[2007/03/05 13:34:28 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/01/12 12:14:56 | 000,022,720 | ---- | C] () -- C:\WINDOWS\System32\haspds_msi.dll
[2006/08/21 15:45:40 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\hppapr04.dll
[2005/05/02 17:46:18 | 000,179,577 | ---- | C] () -- C:\WINDOWS\System32\schema.ini
[2005/05/02 17:46:12 | 000,024,819 | ---- | C] () -- C:\WINDOWS\System32\ntdsctrs.ini
[2005/05/02 17:46:12 | 000,020,386 | ---- | C] () -- C:\WINDOWS\System32\ntfrsrep.ini
[2005/05/02 17:46:12 | 000,005,597 | ---- | C] () -- C:\WINDOWS\System32\ntfrscon.ini
[2005/05/02 17:46:00 | 000,011,030 | ---- | C] () -- C:\WINDOWS\System32\ipsecprf.ini
[2005/05/02 17:45:58 | 000,011,817 | ---- | C] () -- C:\WINDOWS\System32\iasperf.ini
========== LOP Check ==========
[2009/05/31 15:26:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.IONALTD\Application Data\Accubid
[2008/06/06 12:00:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.IONALTD\Application Data\Autodesk
[2010/03/10 20:51:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.IONALTD\Application Data\AVG9
[2009/07/01 00:02:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.IONALTD\Application Data\Citrix
[2007/09/07 15:44:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.IONALTD\Application Data\CitrixMMC
[2007/09/26 11:09:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.IONALTD\Application Data\ICAClient
[2010/02/01 17:38:14 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\Administrator.IONALTD\Application Data\lowsec
[2008/02/12 00:52:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.IONALTD\Application Data\ScanSoft
[2008/11/13 12:21:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.IONALTD\Application Data\webex
[2008/07/15 17:45:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Accubid
[2009/06/30 12:00:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
[2008/06/07 18:10:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2008/05/30 10:31:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avery
[2010/03/10 14:22:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2009/10/30 15:22:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-4AEB55CD
[2007/09/14 15:30:05 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/09/08 14:14:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2009/06/03 16:12:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2007/09/13 13:41:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sage Software
[2007/12/13 20:15:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zeon
[2007/08/30 17:54:01 | 000,000,428 | ---- | M] () -- C:\WINDOWS\Tasks\Memory Optimization Schedule.job
[2010/03/30 15:58:00 | 000,032,582 | ---- | M] () -- C:\WINDOWS\Tasks\SchedLgU.Txt
[2010/03/19 18:24:37 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\SDMsgUpdate (TE).job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2007/02/17 08:03:48 | 000,094,720 | ---- | M] (Microsoft Corporation) -- C:\msizap.exe
< MD5 for: AGP440.SYS >
[2005/03/25 06:00:00 | 014,191,965 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:AGP440.sys
[2007/09/26 21:20:01 | 019,481,285 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2005/03/25 06:00:00 | 014,191,965 | ---- | M] () .cab file -- C:\WINDOWS\i386\sp1.cab:AGP440.sys
[2007/09/26 21:20:01 | 019,481,285 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2007/02/16 23:58:53 | 000,044,032 | ---- | M] (Microsoft Corporation) MD5=B9985042687A43685FC64B282B627653 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2007/02/16 23:58:53 | 000,044,032 | ---- | M] (Microsoft Corporation) MD5=B9985042687A43685FC64B282B627653 -- C:\WINDOWS\system32\dllcache\agp440.sys
[2007/02/16 23:58:53 | 000,044,032 | ---- | M] (Microsoft Corporation) MD5=B9985042687A43685FC64B282B627653 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2005/03/25 06:00:00 | 014,191,965 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2007/09/26 21:20:01 | 019,481,285 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2005/03/25 06:00:00 | 014,191,965 | ---- | M] () .cab file -- C:\WINDOWS\i386\sp1.cab:atapi.sys
[2007/09/26 21:20:01 | 019,481,285 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2005/03/24 18:55:32 | 000,095,744 | ---- | M] (Microsoft Corporation) MD5=9CAB5B612E3AF65810F276BA051D56CD -- C:\WINDOWS\system32\ReinstallBackups\0021\DriverFiles\i386\atapi.sys
[2007/02/17 00:07:35 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=FF953A8F08CA3F822127654375786BBE -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2007/02/17 00:07:35 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=FF953A8F08CA3F822127654375786BBE -- C:\WINDOWS\system32\dllcache\atapi.sys
[2007/02/17 00:07:35 | 000,096,768 | ---- | M] (Microsoft Corporation) MD5=FF953A8F08CA3F822127654375786BBE -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2007/02/17 08:02:49 | 000,068,608 | ---- | M] (Microsoft Corporation) MD5=3AAB2418271343FE97F98AEF93F50E5F -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2007/02/17 08:02:49 | 000,068,608 | ---- | M] (Microsoft Corporation) MD5=3AAB2418271343FE97F98AEF93F50E5F -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2007/02/17 08:02:49 | 000,068,608 | ---- | M] (Microsoft Corporation) MD5=3AAB2418271343FE97F98AEF93F50E5F -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2007/02/17 08:03:02 | 000,430,592 | ---- | M] (Microsoft Corporation) MD5=451564B8F22461D90CF8ED3945637845 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2007/02/17 08:03:02 | 000,430,592 | ---- | M] (Microsoft Corporation) MD5=451564B8F22461D90CF8ED3945637845 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2007/02/17 08:03:02 | 000,430,592 | ---- | M] (Microsoft Corporation) MD5=451564B8F22461D90CF8ED3945637845 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2007/02/17 08:03:09 | 000,188,928 | ---- | M] (Microsoft Corporation) MD5=E7B7FD7D8907DADED4928E922608887F -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2007/02/17 08:03:09 | 000,188,928 | ---- | M] (Microsoft Corporation) MD5=E7B7FD7D8907DADED4928E922608887F -- C:\WINDOWS\system32\dllcache\scecli.dll
[2007/02/17 08:03:09 | 000,188,928 | ---- | M] (Microsoft Corporation) MD5=E7B7FD7D8907DADED4928E922608887F -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SYMMPI.SYS >
[2005/03/25 06:00:00 | 014,191,965 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:symmpi.sys
[2007/09/26 21:20:01 | 019,481,285 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:symmpi.sys
[2005/03/25 06:00:00 | 014,191,965 | ---- | M] () .cab file -- C:\WINDOWS\i386\sp1.cab:symmpi.sys
[2007/09/26 21:20:01 | 019,481,285 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:symmpi.sys
[2005/03/24 19:25:38 | 000,049,664 | ---- | M] (LSI Logic) MD5=868204832E011E2D64281D7EABEE572E -- C:\WINDOWS\ServicePackFiles\i386\symmpi.sys
[2005/03/24 19:25:38 | 000,049,664 | ---- | M] (LSI Logic) MD5=868204832E011E2D64281D7EABEE572E -- C:\WINDOWS\system32\dllcache\symmpi.sys
[2005/03/24 19:25:38 | 000,049,664 | ---- | M] (LSI Logic) MD5=868204832E011E2D64281D7EABEE572E -- C:\WINDOWS\system32\drivers\symmpi.sys
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005/05/02 17:50:38 | 000,090,112 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2005/05/02 17:50:38 | 000,741,376 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2005/05/02 17:50:38 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< End of report >