Okay, I did as you suggested on the laptop. After booting into Safe Mode,
I ran:
sc delete srosaI found and deleted
C:\WINDOWS\system32\drivers\
downldI did not find:
C:\autorun.inf
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mdelk.exe
I did find and delete:
C:\WINDOWS\system32\drivers\
mdelk.exeThen I ran DSS (first pointing it to HiJackThis.exe, which I could now install). Here is the log:
Deckard's System Scanner v20071014.68
Run by Mr. Admin on 2008-04-11 19:51:05
Computer is in Normal Mode.
--------------------------------------------------------------------------------
System Drive C: has 6.11 GiB (less than 15%) free.-- HijackThis (run as Mr. Admin.exe) -------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:52:08 PM, on 4/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\Logi_MwX.Exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system\wcdvtray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Documents and Settings\Mr. Admin\Desktop\dss.exe
C:\DOCUME~1\MR8AF5~1.ADM\Desktop\Mr. Admin.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = htp://www.law.uoregon.edu/students/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Program Files\Power Translator 11\Applications\LEC IE Translation Extension.dll
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [OWCWebCamDV] C:\WINDOWS\system\wcdvtray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Qwest QuickNetworking.lnk = C:\Program Files\QwestQuickNetworking\WebWorks.exe
O4 - Global Startup: 2Wire Wireless Client Manager.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: SysTray.lnk = ?
O8 - Extra context menu item: Add to &Teleport - C:\Program Files\Teleport Pro\teleport.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MasterCook: Select Image - C:\Program Files\MasterCook 9\Web\MCIEContext.hta
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MasterCook Web Import Bar - {E6EF5071-7647-4E85-9785-87B6CF5CB561} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Program Files\Power Translator 11\LogoMedia TranslateDotNet Server.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RadClock - Unknown owner - C:\WINDOWS\system32\RadClock.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
--
End of file - 8063 bytes
-- Files created between 2008-03-11 and 2008-04-11 -----------------------------
2008-04-11 19:49:32 0 d-------- C:\WINDOWS\system32\drivers\downld
2008-04-11 17:25:10 0 d-------- C:\Program Files\2Wire Wireless
2008-04-11 16:41:04 0 d-------- C:\Program Files\QwestQuickNetworking
2008-04-11 16:09:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Support.com
2008-04-10 20:45:10 11254 --a------ C:\WINDOWS\system32\locate.com
2008-04-10 20:43:35 0 d-------- C:\ISeeYouXP
2008-04-10 16:35:29 0 drahs---- C:\autorun.inf
2008-04-10 14:14:33 2560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-04-10 10:55:25 0 d-------- C:\New Folder
2008-04-10 10:06:32 68096 --a------ C:\WINDOWS\zip.exe
2008-04-10 10:06:32 49152 --a------ C:\WINDOWS\VFind.exe
2008-04-10 10:06:32 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-04-10 10:06:32 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-04-10 10:06:32 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-04-10 10:06:32 98816 --a------ C:\WINDOWS\sed.exe
2008-04-10 10:06:32 80412 --a------ C:\WINDOWS\grep.exe
2008-04-10 10:06:32 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-04-10 09:16:47 0 dr-hs---- C:\cmdcons
2008-04-10 09:01:08 0 d-------- C:\WINDOWS\setup.pss
2008-04-09 09:19:01 0 d-------- C:\Program Files\Trend Micro
2008-04-08 16:34:09 0 d-------- C:\Documents and Settings\Mr. Admin\.housecall6.6
2008-04-08 13:57:54 0 d-------- C:\Program Files\TimeLine Maker
2008-04-08 11:34:48 0 d-------- C:\Documents and Settings\Mr. Admin\System
2008-04-08 11:34:48 0 d-------- C:\Documents and Settings\Mr. Admin\Application Data\SmartDraw
2008-04-08 11:25:30 0 d-------- C:\Program Files\SmartDraw 2008
2008-04-08 11:17:56 0 d-------- C:\Documents and Settings\Mr. Admin\Application Data\Progeny
2008-04-08 11:00:26 20569 --a------ C:\WINDOWS\system32\pxc25pm.dll <Not Verified; Tracker Software; PDF-XChange Port Monitor>
2008-04-08 11:00:17 0 d-------- C:\Program Files\Common Files\Progeny
2008-04-08 10:58:23 952 --ahs---- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
2008-04-08 10:58:23 88 -r-hs---- C:\Documents and Settings\All Users\Application Data\16D83DFFEA.sys
2008-04-05 16:03:31 0 d-------- C:\Program Files\iPod
2008-04-05 16:02:51 0 d-------- C:\Program Files\iTunes
2008-03-30 14:13:57 0 d-------- C:\Program Files\Smead Viewables
2008-03-29 07:57:33 0 d-------- C:\Documents and Settings\Mr. Admin\Application Data\HP
2008-03-29 07:24:38 117655 --a------ C:\WINDOWS\hpoins11.dat
2008-03-29 06:38:51 0 d-------- C:\Documents and Settings\LocalService\Application Data\Kinko's
2008-03-22 11:57:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-22 08:38:01 6144 --a------ C:\WINDOWS\system32\DVKSPA01.dll <Not Verified; David C. Olsson; Created by MSKLC 1.4>
2008-03-22 08:14:51 6144 --a------ C:\WINDOWS\system32\DVKSWE01.dll <Not Verified; David C. Olsson; Created by MSKLC 1.4>
2008-03-22 07:54:48 0 d-------- C:\Program Files\Microsoft Keyboard Layout Creator 1.4
2008-03-20 15:23:39 0 d-------- C:\Program Files\CandleWorks
2008-03-20 13:37:17 0 d-------- C:\Program Files\Gecko Software
2008-03-20 13:37:17 0 d-------- C:\Documents and Settings\All Users\Application Data\TNT-HF
2008-03-18 08:15:34 38160 --a------ C:\WINDOWS\system32\LMRTREND.dll <Not Verified; Microsoft Corporation; Microsoft® Windows Operating System>
2008-03-18 08:15:26 182032 --a------ C:\WINDOWS\system32\dxtmsft3.dll <Not Verified; Microsoft Corporation; Microsoft® Windows Operating System>
2008-03-18 08:15:16 63488 --a------ C:\WINDOWS\system32\unam4ie.exe <Not Verified; Microsoft Corporation; DirectShow>
2008-03-18 08:15:08 10240 --a------ C:\WINDOWS\system32\vidx16.dll
2008-03-18 08:15:07 194320 --a------ C:\WINDOWS\system32\qcut.dll <Not Verified; Microsoft Corporation; DirectShow>
2008-03-18 08:15:02 4608 --a------ C:\WINDOWS\system32\w95inf32.dll <Not Verified; Microsoft Corporation; Microsoft® Plus! for Windows® 95>
2008-03-18 08:15:02 2272 --a------ C:\WINDOWS\system32\w95inf16.dll <Not Verified; Microsoft Corporation; Microsoft® Plus! for Windows® 95>
2008-03-18 07:34:27 0 d-------- C:\Program Files\Auralog
2008-03-15 13:44:36 0 d-------- C:\Program Files\Common Files\xing shared
2008-03-15 08:08:25 0 d-------- C:\Program Files\Power Translator 11
2008-03-14 21:18:45 0 d-------- C:\Program Files\Power Translator 11 Professional Multilanguage
2008-03-14 13:18:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Transparent
-- Find3M Report ---------------------------------------------------------------
2008-04-11 17:25:10 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-11 15:29:57 0 d-------- C:\Program Files\Systran
2008-04-10 17:20:00 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-10 17:19:54 0 d-------- C:\Program Files\Lavasoft
2008-04-10 14:01:59 0 d-------- C:\Documents and Settings\Mr. Admin\Application Data\SUPERAntiSpyware.com
2008-04-10 14:01:12 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-04-08 13:57:43 0 d-------- C:\Program Files\TLKGAMES
2008-04-08 11:00:17 0 d-------- C:\Program Files\Common Files
2008-04-06 12:26:22 1324 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-05 15:59:30 0 d-------- C:\Program Files\QuickTime
2008-03-29 07:45:52 0 d-------- C:\Program Files\HP
2008-03-22 11:53:57 0 d-------- C:\Documents and Settings\Mr. Admin\Application Data\Lavasoft
2008-03-16 09:18:59 1 --a------ C:\Documents and Settings\Mr. Admin\Application Data\FrontEndCD.ini
2008-03-15 13:44:24 0 d-------- C:\Program Files\Common Files\Real
2008-03-15 13:26:55 0 d-------- C:\Program Files\TeLLmeMore
2008-03-14 13:18:24 0 d-------- C:\Program Files\Transparent
2008-03-02 10:54:17 0 d-------- C:\Program Files\thriXXX
2008-02-22 16:54:42 0 d-------- C:\Documents and Settings\Mr. Admin\Application Data\Adobe
2008-02-21 16:25:16 0 d-------- C:\Program Files\Bonjour
2008-02-21 16:20:10 0 d-------- C:\Program Files\Common Files\Apple
2008-01-20 20:57:26 50 --a------ C:\WINDOWS\mscpt.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [02/02/2004 01:32 PM]
"Logitech Utility"="Logi_MwX.Exe" [06/30/2003 02:50 AM C:\WINDOWS\LOGI_MWX.EXE]
"AtiPTA"="atiptaxx.exe" [11/30/2004 06:10 PM C:\WINDOWS\SYSTEM32\atiptaxx.exe]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe" [06/25/2004 05:32 PM]
"SM1BG"="C:\WINDOWS\SM1BG.EXE" [08/27/2003 02:20 PM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/19/2006 02:41 AM]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe" [11/28/2005 02:02 PM]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [11/28/2005 02:02 PM]
"OWCWebCamDV"="C:\WINDOWS\system\wcdvtray.exe" [05/20/2004 09:59 AM]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 01:50 PM]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [04/10/2008 04:48 PM]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [04/10/2008 04:48 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 02:11 AM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"PRISMSVR.EXE"="C:\WINDOWS\system32\PRISMSVR.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [05/26/2006 02:01 AM]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [03/30/2006 04:45 PM]
C:\Documents and Settings\Mr. Admin\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [10/4/2004 1:12:18 AM]
DESKTOP.INI [3/20/2004 10:58:38 AM]
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [10/20/2005 1:04:08 PM]
Qwest QuickNetworking.lnk - C:\Program Files\QwestQuickNetworking\WebWorks.exe [4/11/2008 4:41:16 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
2Wire Wireless Client Manager.lnk - C:\Program Files\2Wire Wireless\Client Manager\CMTWO.EXE [4/11/2008 5:25:12 PM]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [10/4/2004 1:12:18 AM]
DESKTOP.INI [3/20/2004 10:58:38 AM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2/19/2006 4:21:22 AM]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [12/17/2002 5:23:32 PM]
SysTray.lnk - C:\WINDOWS\Installer\{8F156C85-23F2-4F13-89A6-B0B286D1B4CD}\NewShortcut1_5221CCAB553E4E63B6FD56674A376D04_1.exe [10/13/2005 11:51:23 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
"EnableLUA"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{35B2861B-2B26-4691-9FF0-09083722C736}"= C:\WINDOWS\system32\RadExe.dll [02/02/2005 05:58 AM 212992]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
-- End of Deckard's System Scanner: finished at 2008-04-11 19:52:35 ------------
I think that mdelk may have been something bad--it had an icon of evil-looking crossed swords.
I am going to post this, then give you the results of a an online scan I ran on the workPC, in a separate post.
Thanks,
D