Seems that after Troj/Servu-Gen and Mal/Encpk-M infections found, clients (XP Pro) can no longer connect to internet but emails are working ok. The server also can connect to internet ok but I can no longer connect remotely via RDC.
The clients use DHCP and point to the server for DNS and gateway. The router is on a second NIC. I have tried putting the client on a static IP and pointing directly to the router for gateway and ISP's DNS addresses but no change.
AVG AntiSpyware 7.5 found the following infections:
Dropper.ServU
Trojan.Botspeedometer.A
Backdoor.Usirf.D
I ran HiJackThis and have included the log and startup list. Hope you can help.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:30:19, on 05/11/2007
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
E:\Virus\AD-Aware\aawservi
ce.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\APC\POWERC~1\a
gent\pbeag
ent.exe
C:\PROGRA~1\APC\POWERC~1\s
erver\PBES
ER~1.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\WINDOWS\system32\Dfssvc
.exe
C:\WINDOWS\System32\dns.ex
e
C:\WINDOWS\System32\svchos
t.exe
C:\compaq\hpdiags\hpdiags.
exe
C:\WINDOWS\system32\inetsr
v\inetinfo
.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn
\sqlservr.
exe
C:\Program Files\Microsoft SQL Server\MSSQL$SBSMONITORING
\Binn\sqls
ervr.exe
c:\Program Files\Microsoft SQL Server\MSSQL$SHAREPOINT\Bi
nn\sqlserv
r.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\s
qlservr.ex
e
C:\WINDOWS\system32\ntfrs.
exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService
.exe
C:\Program Files\Sophos Enterprise Manager\Library\bin\schdsr
vc.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.e
xe
C:\Program Files\Sophos\AutoUpdate\AL
svc.exe
C:\Program Files\Sophos\Enterprise Console\CertificationManag
erServiceN
T.exe
C:\Program Files\Sophos\Remote Management System\EMLibUpdateAgentNT.
exe
C:\Program Files\Sophos\Enterprise Console\MgntSvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SBSMONITORING
\Binn\sqla
gent.EXE
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\wins.e
xe
C:\WINDOWS\system32\CpqRcm
c.exe
C:\WINDOWS\system32\tcpsvc
s.exe
C:\Program Files\Exchsrvr\bin\exmgmt.
exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\
mssearch.e
xe
C:\WINDOWS\system32\sysdow
n.exe
C:\Program Files\Exchsrvr\bin\store.e
xe
C:\Program Files\Exchsrvr\bin\emsmta.
exe
C:\Program Files\Microsoft Windows Small Business Server\Networking\POP3\imb
service.ex
e
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cpqtea
m.exe
C:\Program Files\VERITAS\VxUpdate\VxT
askbarMgr.
exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Sophos\AutoUpdate\AL
Mon.exe
C:\WINDOWS\System32\svchos
t.exe
c:\windows\system32\inetsr
v\w3wp.exe
C:\WINDOWS\system32\sessmg
r.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Virus\HiJackThis.exe
C:\Program Files\Microsoft Windows Small Business Server\Networking\POP3\imb
downl.exe
C:\Program Files\Microsoft Windows Small Business Server\Networking\POP3\imb
dlvr.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = res://shdoclc.dll/hardAdmi
n.htm
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://companyweb/default.aspxR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d
ll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O4 - HKLM\..\Run: [CPQTEAM] cpqteam.exe
O4 - HKLM\..\Run: [DWPersistentQueuedReporti
ng] c:\PROGRA~1\COMMON~1\MICRO
S~1\DW\DWT
RIG20.EXE -a
O4 - HKLM\..\Run: [VxTaskbarMgr] C:\Program Files\VERITAS\VxUpdate\VxT
askbarMgr.
exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dump
rep 0 -u
O4 - HKLM\..\RunOnce: [OE_WMPWMPCodec_wmv8ax] C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\wmv8d
s32.ax"
O4 - HKLM\..\RunOnce: [OE_WMPWMPCodec_wmv8dmo] C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\wmv8d
mod.dll"
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_0] C:\WINDOWS\INF\unregmp2.ex
e /MigrateLibrary
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_1] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmp.dl
l
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_3] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\drmcli
en.dll
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_4] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\drmsto
r.dll
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_6] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\drmv2c
lt.dll
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_7] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\blackb
ox.dll
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_8] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmpshe
ll.dll
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_9] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmpasf
.dll
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_10] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmpdxm
.dll
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_11] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmpenc
en.dll
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_12] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmpsrc
wp.dll
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_13] C:\WINDOWS\system32\regsvr
32 /s "C:\Program Files\Windows Media Player\mpvis.dll"
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_14] C:\WINDOWS\system32\regsvr
32 /s "C:\Program Files\Windows Media Player\wmpband.dll"
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_15] C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\audiod
ev.dll
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_19] "C:\Program Files\Windows Media Player\WMPEnc.exe" /RegServer
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_20] C:\WINDOWS\INF\unregmp2.ex
e /Shortcuts /RegExts
O4 - HKLM\..\RunOnce: [OE_WMPWMP7_Install_21] "C:\Program Files\Windows Media Player\migrate.exe" /s
O4 - HKLM\..\RunOnce: [OE_WMPWPD_Install_2] C:\WINDOWS\system32\regsvr
32.exe /s "C:\WINDOWS\system32\wpdsp
.dll"
O4 - HKLM\..\RunOnce: [OE_WMPDRM_Install_1] C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\drmst
or.dll"
O4 - HKLM\..\RunOnce: [OE_WMPDRM_Install_2] C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\drmcl
ien.dll"
O4 - HKLM\..\RunOnce: [OE_WMPDRM_Install_4] C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\drmv2
clt.dll"
O4 - HKLM\..\RunOnce: [OE_WMPDRM_Install_5] C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\black
box.dll"
O4 - HKLM\..\RunOnce: [OE_WMPDRM_Install_6] C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\msnet
obj.dll"
O4 - HKLM\..\RunOnce: [OE_WMPDRM_Install_7] C:\WINDOWS\system32\drmupg
ds.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateMana
ger.exe AcRdB7_0_5
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
pgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
pgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
pgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscu
pgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\AL
Mon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_02\bin
\npjpi160_
02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_02\bin
\npjpi160_
02.dll
O14 - IERESET.INF: START_PAGE_URL=
http://companywebO15 - ESC Trusted Zone:
http://ardownload.adobe.comO15 - ESC Trusted Zone:
http://www.adobe.comO15 - ESC Trusted Zone:
http://www.bbc.co.ukO15 - ESC Trusted Zone:
http://dw.com.comO15 - ESC Trusted Zone:
http://i.d.com.comO15 - ESC Trusted Zone:
http://www.download.comO15 - ESC Trusted Zone:
http://www.getfreefonts.infoO15 - ESC Trusted Zone:
http://www.google-analytics.comO15 - ESC Trusted Zone:
http://www.google.co.ukO15 - ESC Trusted Zone:
http://pagead2.googlesyndication.comO15 - ESC Trusted Zone:
http://www.hydrastore.co.ukO15 - ESC Trusted Zone:
http://download2.konicaminoltaeurope.comO15 - ESC Trusted Zone:
http://www.mailbigfile.comO15 - ESC Trusted Zone:
http://us.mcafee.comO15 - ESC Trusted Zone:
http://*.msmvps.comO15 - ESC Trusted Zone:
http://www.myspace.comO15 - ESC Trusted Zone:
http://x.myspace.comO15 - ESC Trusted Zone:
http://download.nai.comO15 - ESC Trusted Zone:
http://login.passport.comO15 - ESC Trusted Zone:
http://login.passport.netO15 - ESC Trusted Zone:
http://downloads.pcworld.comO15 - ESC Trusted Zone:
http://downloads.planetmirror.comO15 - ESC Trusted Zone:
http://public.planetmirror.comO15 - ESC Trusted Zone:
http://saboteur.planetmirror.comO15 - ESC Trusted Zone:
http://secure.planetmirror.comO15 - ESC Trusted Zone:
http://www.safer-networking.orgO15 - ESC Trusted Zone:
http://downloadcenter.samsung.comO15 - ESC Trusted Zone:
http://www.samsung.comO15 - ESC Trusted Zone:
http://downloads.sophos.comO15 - ESC Trusted Zone:
http://www.sophos.comO15 - ESC Trusted Zone:
http://entkb.symantec.comO15 - ESC Trusted Zone:
http://www.sysinternals.comO15 - ESC Trusted Zone:
http://www.telecom-plus-online.co.ukO15 - ESC Trusted Zone:
http://www.telecomplus.org.ukO15 - ESC Trusted Zone:
http://eventlookup.veritas.comO15 - ESC Trusted Zone:
http://seer.support.veritas.comO15 - ESC Trusted Zone:
http://softwareupdate.veritas.comO15 - ESC Trusted Zone:
http://support.veritas.comO15 - ESC Trusted Zone:
http://www.veritas.comO15 - ESC Trusted Zone:
http://www.veryfastsearch.comO15 - ESC Trusted Zone:
http://m.webtrends.comO15 - ESC Trusted Zone:
http://meta.wikimedia.orgO15 - ESC Trusted Zone:
http://en.wikipedia.orgO15 - ESC Trusted Zone:
http://www.windowsitpro.comO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124812338453O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124812362093O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = pioneer.local
O17 - HKLM\Software\..\Telephony
: DomainName = pioneer.local
O17 - HKLM\System\CCS\Services\T
cpip\..\{C
536480D-73
C6-4491-9B
0C-0199B1C
D671B}: NameServer = 192.168.16.2
O17 - HKLM\System\CCS\Services\T
cpip\..\{E
C56F592-A5
A7-45CE-BE
5A-56E4DD6
E6B20}: NameServer = 192.168.16.2
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = pioneer.local
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = pioneer.local
O18 - Protocol: hpapp - {24F45006-5BD9-41B7-9BD9-5
F8921C8EBD
1} - C:\Program Files\Compaq\Cpqacuxe\Bin\
hpapp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - E:\Virus\AD-Aware\aawservi
ce.exe
O23 - Service: APC PBE Agent (APCPBEAgent) - APC - C:\PROGRA~1\APC\POWERC~1\a
gent\pbeag
ent.exe
O23 - Service: APC PBE Server (APCPBEServer) - APC - C:\PROGRA~1\APC\POWERC~1\s
erver\PBES
ER~1.EXE
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerato
r) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaServ
ice) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Compaq Remote Monitor Service (CpqRcmc) - Compaq - C:\WINDOWS\system32\CpqRcm
c.exe
O23 - Service: DHCP Controller (dhcpcl) - Unknown owner - C:\WINDOWS\system32\dhcp\d
hcpcl.exe (file missing)
O23 - Service: HP Insight Diagnostics (hpdiags) - Unknown owner - C:\compaq\hpdiags\hpdiags.
exe
O23 - Service: Microsoft Internet Monitoring Service (MSIMonSrv) - Unknown owner - C:\windows\system32\inetse
rvice.exe (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService
.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Smart Card Updater (SCardUpd) - Unknown owner - C:\WINDOWS\system32\scardu
pd.exe (file missing)
O23 - Service: Sophos Enterprise Manager Scheduler (SEMScheduler) - Sophos Plc - C:\Program Files\Sophos Enterprise Manager\Library\bin\schdsr
vc.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Unknown owner - C:\WINDOWS\system32\inetse
rvice.exe (file missing)
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.e
xe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\AL
svc.exe
O23 - Service: Sophos Certification Manager - Sophos Plc. - C:\Program Files\Sophos\Enterprise Console\CertificationManag
erServiceN
T.exe
O23 - Service: Sophos EMLibUpdate Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\EMLibUpdateAgentNT.
exe
O23 - Service: Sophos Management Service - Sophos Plc. - C:\Program Files\Sophos\Enterprise Console\MgntSvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: HP ProLiant System Shutdown Service (sysdown) - Compaq Computer Corporation - C:\WINDOWS\system32\sysdow
n.exe
O23 - Service: Distributed Link Tracking Updater (TrkUpd) - Unknown owner - C:\WINDOWS\system32\trkupd
.exe (file missing)
--
End of file - 15019 bytes
StartupList report, 05/11/2007, 14:38:40
StartupList version: 1.52.2
Started from : E:\Virus\HiJackThis.EXE
Detected: Windows 2003 SP2 (WinNT 5.02.3790)
Detected: Internet Explorer v7.00 (7.00.6000.16544)
* Using default options
==========================
==========
==========
====
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
E:\Virus\AD-Aware\aawservi
ce.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\APC\POWERC~1\a
gent\pbeag
ent.exe
C:\PROGRA~1\APC\POWERC~1\s
erver\PBES
ER~1.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\WINDOWS\system32\Dfssvc
.exe
C:\WINDOWS\System32\dns.ex
e
C:\WINDOWS\System32\svchos
t.exe
C:\compaq\hpdiags\hpdiags.
exe
C:\WINDOWS\system32\inetsr
v\inetinfo
.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn
\sqlservr.
exe
C:\Program Files\Microsoft SQL Server\MSSQL$SBSMONITORING
\Binn\sqls
ervr.exe
c:\Program Files\Microsoft SQL Server\MSSQL$SHAREPOINT\Bi
nn\sqlserv
r.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\s
qlservr.ex
e
C:\WINDOWS\system32\ntfrs.
exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService
.exe
C:\Program Files\Sophos Enterprise Manager\Library\bin\schdsr
vc.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.e
xe
C:\Program Files\Sophos\AutoUpdate\AL
svc.exe
C:\Program Files\Sophos\Enterprise Console\CertificationManag
erServiceN
T.exe
C:\Program Files\Sophos\Remote Management System\EMLibUpdateAgentNT.
exe
C:\Program Files\Sophos\Enterprise Console\MgntSvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SBSMONITORING
\Binn\sqla
gent.EXE
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\wins.e
xe
C:\WINDOWS\system32\CpqRcm
c.exe
C:\WINDOWS\system32\tcpsvc
s.exe
C:\Program Files\Exchsrvr\bin\exmgmt.
exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\
mssearch.e
xe
C:\WINDOWS\system32\sysdow
n.exe
C:\Program Files\Exchsrvr\bin\store.e
xe
C:\Program Files\Exchsrvr\bin\emsmta.
exe
C:\Program Files\Microsoft Windows Small Business Server\Networking\POP3\imb
service.ex
e
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cpqtea
m.exe
C:\Program Files\VERITAS\VxUpdate\VxT
askbarMgr.
exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Sophos\AutoUpdate\AL
Mon.exe
C:\WINDOWS\System32\svchos
t.exe
c:\windows\system32\inetsr
v\w3wp.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Virus\HiJackThis.exe
--------------------------
----------
----------
----
Listing of startup folders:
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\AL
Mon.exe
--------------------------
----------
----------
----
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\W
indows NT\CurrentVersion\Winlogon
]
UserInit = C:\WINDOWS\system32\userin
it.exe,
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run
CPQTEAM = cpqteam.exe
DWPersistentQueuedReportin
g = c:\PROGRA~1\COMMON~1\MICRO
S~1\DW\DWT
RIG20.EXE -a
VxTaskbarMgr = C:\Program Files\VERITAS\VxUpdate\VxT
askbarMgr.
exe
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunOnce
OE_WMPWMPCodec_wmv8ax = C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\wmv8d
s32.ax"
OE_WMPWMPCodec_wmv8dmo = C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\wmv8d
mod.dll"
OE_WMPWMP7_Install_0 = C:\WINDOWS\INF\unregmp2.ex
e /MigrateLibrary
OE_WMPWMP7_Install_1 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmp.dl
l
OE_WMPWMP7_Install_3 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\drmcli
en.dll
OE_WMPWMP7_Install_4 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\drmsto
r.dll
OE_WMPWMP7_Install_6 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\drmv2c
lt.dll
OE_WMPWMP7_Install_7 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\blackb
ox.dll
OE_WMPWMP7_Install_8 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmpshe
ll.dll
OE_WMPWMP7_Install_9 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmpasf
.dll
OE_WMPWMP7_Install_10 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmpdxm
.dll
OE_WMPWMP7_Install_11 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmpenc
en.dll
OE_WMPWMP7_Install_12 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\wmpsrc
wp.dll
OE_WMPWMP7_Install_13 = C:\WINDOWS\system32\regsvr
32 /s "C:\Program Files\Windows Media Player\mpvis.dll"
OE_WMPWMP7_Install_14 = C:\WINDOWS\system32\regsvr
32 /s "C:\Program Files\Windows Media Player\wmpband.dll"
OE_WMPWMP7_Install_15 = C:\WINDOWS\system32\regsvr
32 /s C:\WINDOWS\system32\audiod
ev.dll
OE_WMPWMP7_Install_19 = "C:\Program Files\Windows Media Player\WMPEnc.exe" /RegServer
OE_WMPWMP7_Install_20 = C:\WINDOWS\INF\unregmp2.ex
e /Shortcuts /RegExts
OE_WMPWMP7_Install_21 = "C:\Program Files\Windows Media Player\migrate.exe" /s
OE_WMPWPD_Install_2 = C:\WINDOWS\system32\regsvr
32.exe /s "C:\WINDOWS\system32\wpdsp
.dll"
OE_WMPDRM_Install_1 = C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\drmst
or.dll"
OE_WMPDRM_Install_2 = C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\drmcl
ien.dll"
OE_WMPDRM_Install_4 = C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\drmv2
clt.dll"
OE_WMPDRM_Install_5 = C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\black
box.dll"
OE_WMPDRM_Install_6 = C:\WINDOWS\system32\regsvr
32 /s "C:\WINDOWS\system32\msnet
obj.dll"
OE_WMPDRM_Install_7 = C:\WINDOWS\system32\drmupg
ds.exe
--------------------------
----------
----------
----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run
ctfmon.exe = C:\WINDOWS\system32\ctfmon
.exe
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
updateMgr = C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateMana
ger.exe AcRdB7_0_5
--------------------------
----------
----------
----
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\sy
stem32\log
on.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------
----------
----------
----
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d
ll - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll - {53707962-6F74-2D53-2644-2
06D7942484
F}
--------------------------
----------
----------
----
Enumerating Task Scheduler jobs:
Collect Server Performance Data.job
Low Battery Alarm Program.job
New scan.job
RegCure Program Check.job
RegCure.job
ShadowCopyVolume{01a0c36e-
13eb-11da-
8681-806e6
f6e6963}.j
ob
--------------------------
----------
----------
----
Enumerating Download Program Files:
[WUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\wuweb.
dll
CODEBASE =
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124812338453[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.
dll
CODEBASE =
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124812362093--------------------------
----------
----------
----
Enumerating ShellServiceObjectDelayLoa
d items:
PostBootReminder: C:\WINDOWS\system32\SHELL3
2.dll
CDBurn: C:\WINDOWS\system32\SHELL3
2.dll
WebCheck: C:\WINDOWS\system32\webche
ck.dll
SysTray: C:\WINDOWS\system32\stobje
ct.dll
--------------------------
----------
----------
----
End of report, 8,944 bytes
Report generated in 0.094 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Start Free Trial