Hi there
this is the eset online scanner log:
C:\Documents and Settings\All Users\Application Data\Heidelberg\Licenses\Licenses$.exe
a variant of Win32/AutoRun.Agent.UD worm
C:\Documents and Settings\All Users\Application Data\Heidelberg\Licenses\ColorToolbox_3.0\ColorToolbox_3.0.scr a variant of Win32/AutoRun.Agent.UD worm
C:\Documents and Settings\All Users\Application Data\Heidelberg\Licenses\HighResRenderer\HighResRenderer.exe a variant of Win32/AutoRun.Agent.UD worm
C:\Documents and Settings\All Users\Application Data\Heidelberg\Licenses\LicSN\LicSN.bat a variant of Win32/AutoRun.Agent.UD worm
C:\Documents and Settings\All Users\Application Data\Heidelberg\Licenses\Logs\Logs.exe a variant of Win32/AutoRun.Agent.UD worm
C:\Documents and Settings\All Users\Application Data\Heidelberg\Licenses\MetaDimension\MetaDimension.bat a variant of Win32/AutoRun.Agent.UD worm
C:\Documents and Settings\All Users\Application Data\Heidelberg\Licenses\PDFToolbox\PDFToolbox.exe a variant of Win32/AutoRun.Agent.UD worm
C:\Documents and Settings\All Users\Application Data\Heidelberg\Licenses\Prinect Workflow\Workflow.bat a variant of Win32/AutoRun.Agent.UD worm
C:\Documents and Settings\All Users\Application Data\Heidelberg\Licenses\ProofRenderer\ProofRenderer.exe a variant of Win32/AutoRun.Agent.UD worm
C:\Documents and Settings\All Users\Application Data\Heidelberg\Licenses\Signa_Station-3-0\Signa_Station-3-0.exe a variant of Win32/AutoRun.Agent.UD worm
G:\HF_838\data.tmp\data.tmp.scr a variant of Win32/AutoRun.Agent.UD worm
========================================
this is from OTL:
extras.txt
OTL Extras logfile created on: 13.8.2010 г. 11:27:25 - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\prinect\Desktop
Windows Server 2003 Standard Edition Service Pack 2 (Version = 5.2.3790) - Type = NTServer
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000402 | Country: Bulgaria | Language: BGR | Date Format: dd.M.yyyy 'г.'
4,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 83,00% Memory free
10,00 Gb Paging File | 6,00 Gb Available in Paging File | 57,00% Paging File free
Paging file location(s): c:\pagefile.sys 6141 12192 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97,65 Gb Total Space | 68,47 Gb Free Space | 70,11% Space Free | Partition Type: NTFS
Drive D: | 200,43 Gb Total Space | 200,36 Gb Free Space | 99,96% Space Free | Partition Type: NTFS
Drive E: | 250,92 Gb Total Space | 205,96 Gb Free Space | 82,08% Space Free | Partition Type: NTFS
Drive F: | 214,84 Gb Total Space | 214,77 Gb Free Space | 99,97% Space Free | Partition Type: NTFS
Drive G: | 298,09 Gb Total Space | 248,05 Gb Free Space | 83,21% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive W: | 146,48 Gb Total Space | 131,77 Gb Free Space | 89,96% Space Free | Partition Type: NTFS
Drive X: | 132,40 Gb Total Space | -3,16 Gb Free Space | -2,39% Space Free | Partition Type: NTFS
Drive Y: | 255,34 Gb Total Space | 9,45 Gb Free Space | 3,70% Space Free | Partition Type: NTFS
Computer Name: XEON4
Current User Name: prinect
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UacDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
"" =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"49300:TCP" = 49300:TCP:*:Enabled:JDF Portal Port 49300
"31273:TCP" = 31273:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31273
"31274:TCP" = 31274:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31274
"31275:TCP" = 31275:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31275
"31276:TCP" = 31276:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31276
"31277:TCP" = 31277:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31277
"31278:TCP" = 31278:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31278
"31279:TCP" = 31279:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31279
"31280:TCP" = 31280:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31280
"31281:TCP" = 31281:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31281
"31282:TCP" = 31282:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31282
"31283:TCP" = 31283:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31283
"31284:TCP" = 31284:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31284
"31285:TCP" = 31285:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31285
"31286:TCP" = 31286:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31286
"31287:TCP" = 31287:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31287
"31288:TCP" = 31288:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31288
"31289:TCP" = 31289:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31289
"31290:TCP" = 31290:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31290
"31291:TCP" = 31291:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31291
"31292:TCP" = 31292:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31292
"31293:TCP" = 31293:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31293
"31294:TCP" = 31294:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31294
"31295:TCP" = 31295:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31295
"31296:TCP" = 31296:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31296
"31297:TCP" = 31297:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31297
"31298:TCP" = 31298:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31298
"31299:TCP" = 31299:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31299
"31300:TCP" = 31300:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31300
"31301:TCP" = 31301:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31301
"31302:TCP" = 31302:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31302
"31303:TCP" = 31303:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31303
"31304:TCP" = 31304:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31304
"31305:TCP" = 31305:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31305
"8080:TCP" = 8080:TCP:*:Enabled:Web Interface Port 8080
"139:TCP" = 139:TCP:*:Enabled

xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled

xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled

xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled

xpsp2res.dll,-22002
"6401:TCP" = 6401:TCP:*:Enabled:Heidelberg Prinect JDF Connector (6401)
"8888:TCP" = 8888:TCP:*:Enabled:Heidelberg Prinect JDF Connector Service (8888)
"6325:TCP" = 6325:TCP:*:Enabled:Heidelberg Prinect Master Data Service (6325)
"6329:TCP" = 6329:TCP:*:Enabled:Heidelberg Prinect Master Data Service (6329)
"49310:TCP" = 49310:TCP:*:Enabled:JDF Bridge Port 49310
"49311:TCP" = 49311:TCP:*:Enabled:JDF Bridge Port 49311
"49312:TCP" = 49312:TCP:*:Enabled:JDF Bridge Port 49312
"49313:TCP" = 49313:TCP:*:Enabled:JDF Bridge Port 49313
"49314:TCP" = 49314:TCP:*:Enabled:JDF Bridge Port 49314
"49315:TCP" = 49315:TCP:*:Enabled:JDF Bridge Port 49315
"49320:TCP" = 49320:TCP:*:Enabled

DF-PE JDF Portal Port 49320
"49321:TCP" = 49321:TCP:*:Enabled

DF-PE JDF Portal Port 49321
"49322:TCP" = 49322:TCP:*:Enabled

DF-PE JDF Portal Port 49322
"49323:TCP" = 49323:TCP:*:Enabled

DF-PE JDF Portal Port 49323
"49324:TCP" = 49324:TCP:*:Enabled

DF-PE JDF Portal Port 49324
"49325:TCP" = 49325:TCP:*:Enabled

DF-PE JDF Portal Port 49325
"4560:TCP" = 4560:TCP:*:Enabled:MetaDTVService Port 4560
"6351:TCP" = 6351:TCP:*:Enabled:Heidelberg Prinect JDF Connector Service (6351)
"6351:UDP" = 6351:UDP:*:Enabled:Heidelberg Prinect JDF Connector Service (6351)
"8889:TCP" = 8889:TCP:*:Enabled:Heidelberg Prinect JDF Connector Service (8889)
"8889:UDP" = 8889:UDP:*:Enabled:Heidelberg Prinect JDF Connector Service (8889)
"6315:TCP" = 6315:TCP:*:Enabled:Heidelberg Prinect JDF Storage Service (6315)
"6319:TCP" = 6319:TCP:*:Enabled:Heidelberg Prinect JDF Storage Service (6319)
"6335:TCP" = 6335:TCP:*:Enabled:Heidelberg Prinect JMF Message Service (6335)
"6339:TCP" = 6339:TCP:*:Enabled:Heidelberg Prinect JMF Message Service (6339)
"6362:TCP" = 6362:TCP:*:Enabled:Heidelberg Prinect Central Device Manager Service (6362)
"65002:UDP" = 65002:UDP:*:Enabled:Heidelberg Local Information Service Monitor (65002 UDP IN)
"6321:TCP" = 6321:TCP:*:Enabled:Heidelberg Master Data Service (6321 TCP IN)
"5353:UDP" = 5353:UDP:*:Enabled:Heidelberg Master Data Service (5353 UDP IN)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"31273:TCP" = 31273:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31273
"31274:TCP" = 31274:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31274
"31275:TCP" = 31275:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31275
"31276:TCP" = 31276:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31276
"31277:TCP" = 31277:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31277
"31278:TCP" = 31278:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31278
"31279:TCP" = 31279:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31279
"31280:TCP" = 31280:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31280
"31281:TCP" = 31281:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31281
"31282:TCP" = 31282:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31282
"31283:TCP" = 31283:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31283
"31284:TCP" = 31284:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31284
"31285:TCP" = 31285:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31285
"31286:TCP" = 31286:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31286
"31287:TCP" = 31287:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31287
"31288:TCP" = 31288:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31288
"31289:TCP" = 31289:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31289
"31290:TCP" = 31290:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31290
"31291:TCP" = 31291:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31291
"31292:TCP" = 31292:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31292
"31293:TCP" = 31293:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31293
"31294:TCP" = 31294:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31294
"31295:TCP" = 31295:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31295
"31296:TCP" = 31296:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31296
"31297:TCP" = 31297:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31297
"31298:TCP" = 31298:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31298
"31299:TCP" = 31299:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31299
"31300:TCP" = 31300:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31300
"31301:TCP" = 31301:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31301
"31302:TCP" = 31302:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31302
"31303:TCP" = 31303:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31303
"31304:TCP" = 31304:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31304
"31305:TCP" = 31305:TCP:*:Enabled:Heidelberg Prinect MetaDimension MDS Client API Port 31305
"139:TCP" = 139:TCP:LocalSubNet:Enabled

xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled

xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled

xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled

xpsp2res.dll,-22002
"6401:TCP" = 6401:TCP:*:Enabled:Heidelberg Prinect JDF Connector (6401)
"8888:TCP" = 8888:TCP:*:Enabled:Heidelberg Prinect JDF Connector Service (8888)
"123:UDP" = 123:UDP:*:Enabled:System Time (NTP) Port
"427:UDP" = 427:UDP:*:Enabled:AppleShare IP TCP Port 427
"548:UDP" = 548:UDP:*:Enabled:AppleShare IP TCP Port 548
"520:UDP" = 520:UDP:*:Enabled:Routing Information Protocol (RIP) Port
"6325:TCP" = 6325:TCP:*:Enabled:Heidelberg Prinect Master Data Service (6325)
"6329:TCP" = 6329:TCP:*:Enabled:Heidelberg Prinect Master Data Service (6329)
"6351:TCP" = 6351:TCP:*:Enabled:Heidelberg Prinect JDF Connector Service (6351)
"6351:UDP" = 6351:UDP:*:Enabled:Heidelberg Prinect JDF Connector Service (6351)
"8889:TCP" = 8889:TCP:*:Enabled:Heidelberg Prinect JDF Connector Service (8889)
"8889:UDP" = 8889:UDP:*:Enabled:Heidelberg Prinect JDF Connector Service (8889)
"6315:TCP" = 6315:TCP:*:Enabled:Heidelberg Prinect JDF Storage Service (6315)
"6319:TCP" = 6319:TCP:*:Enabled:Heidelberg Prinect JDF Storage Service (6319)
"6335:TCP" = 6335:TCP:*:Enabled:Heidelberg Prinect JMF Message Service (6335)
"6339:TCP" = 6339:TCP:*:Enabled:Heidelberg Prinect JMF Message Service (6339)
"6362:TCP" = 6362:TCP:*:Enabled:Heidelberg Prinect Central Device Manager Service (6362)
"65002:UDP" = 65002:UDP:*:Enabled:Heidelberg Local Information Service Monitor (65002 UDP IN)
"6321:TCP" = 6321:TCP:*:Enabled:Heidelberg Master Data Service (6321 TCP IN)
"5353:UDP" = 5353:UDP:*:Enabled:Heidelberg Master Data Service (5353 UDP IN)
========== Authorized Applications List ==========