#14
ComboFix 10-02-02.02 - Jakob Hansen 02-02-2010 23:39:15.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1455 [GMT -8:00]
Running from: c:\documents and settings\Jakob Hansen\Desktop\Banan.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-1583138493-2270468506-272251369-500
c:\windows\system32\BttnServ.exe
c:\windows\system32\drivers\vgkgx.sys
c:\windows\system32\drivers\vytjfuc.sys
c:\windows\system32\drivers\wgdybuo.sys
c:\windows\winst.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_lmfpyoj
-------\Service_sokamiiq
-------\Service_ujnonl
((((((((((((((((((((((((( Files Created from 2010-01-03 to 2010-02-03 )))))))))))))))))))))))))))))))
.
2010-02-03 04:09 . 2010-02-03 04:09 -------- d-----w- c:\documents and settings\Jakob Hansen\Application Data\Malwarebytes
2010-02-03 04:09 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-03 04:09 . 2010-02-03 04:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-03 04:09 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-03 04:09 . 2010-02-03 04:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-03 01:40 . 2010-02-03 01:40 -------- d-----w- c:\program files\CCleaner
2010-02-03 01:20 . 2001-08-18 06:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-02-03 01:20 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-02-03 01:20 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\dllcache\usbscan.sys
2010-02-03 01:20 . 2008-04-14 00:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-02-02 15:49 . 2009-08-13 15:16 512000 ------w- c:\windows\system32\dllcache\jscript.dll
2010-02-01 20:32 . 2008-04-13 18:45 26368 ----a-w- c:\windows\system32\dllcache\usbstor.sys
2010-02-01 18:46 . 2010-02-01 18:46 -------- d-----w- c:\documents and settings\Jakob Hansen\Application Data\AdobeUM
2010-02-01 18:46 . 2010-02-01 18:46 -------- d-----w- c:\documents and settings\Jakob Hansen\Local Settings\Application Data\Adobe
2010-02-01 18:30 . 2010-02-01 18:30 -------- d-----w- c:\windows\system32\scripting
2010-02-01 18:30 . 2010-02-01 18:30 -------- d-----w- c:\windows\l2schemas
2010-02-01 17:00 . 2010-02-01 17:00 -------- d-----w- c:\program files\Reference Assemblies
2010-02-01 17:00 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-02-01 17:00 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-02-01 17:00 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-02-01 17:00 . 2010-02-01 17:00 -------- d-----w- C:\316acc30ebd2c735bfca
2010-02-01 17:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-02-01 17:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-02-01 17:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-02-01 17:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-02-01 17:00 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-02-01 17:00 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-02-01 16:57 . 2010-02-01 16:57 -------- d-----w- c:\program files\MSXML 6.0
2010-02-01 09:38 . 2010-02-01 18:19 -------- d-----w- c:\windows\ServicePackFiles
2010-02-01 09:37 . 2010-02-01 09:37 -------- d-----w- c:\program files\MSXML 4.0
2010-02-01 09:05 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-02-01 09:05 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2010-02-01 09:05 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-02-01 09:02 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2010-02-01 09:02 . 2008-10-24 11:21 455296 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-02-01 09:02 . 2008-12-11 10:57 333952 ------w- c:\windows\system32\dllcache\srv.sys
2010-02-01 09:02 . 2008-05-01 14:33 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2010-02-01 09:02 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2010-02-01 09:01 . 2008-04-11 19:04 691712 ------w- c:\windows\system32\dllcache\inetcomm.dll
2010-02-01 09:01 . 2009-06-10 17:19 2066432 ------w- c:\windows\system32\dllcache\mstscax.dll
2010-02-01 09:01 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2010-02-01 09:01 . 2009-07-31 04:35 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2010-02-01 09:00 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-02-01 09:00 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2010-02-01 08:55 . 2010-02-01 08:55 0 ----a-w- c:\windows\nsreg.dat
2010-02-01 08:54 . 2010-02-01 08:54 -------- d-----w- c:\documents and settings\Jakob Hansen\Local Settings\Application Data\Mozilla
2010-02-01 08:52 . 2004-08-04 06:41 1041536 ------w- c:\windows\system32\drivers\hsfdpsp2.sys
2010-02-01 08:52 . 2004-08-04 06:41 685056 ------w- c:\windows\system32\drivers\hsfcxts2.sys
2010-02-01 08:52 . 2004-08-04 06:41 220032 ------w- c:\windows\system32\drivers\hsfbs2s2.sys
2010-02-01 08:36 . 2009-08-07 03:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-02-01 08:35 . 2010-02-01 08:35 -------- d-s---w- c:\documents and settings\Jakob Hansen\UserData
2010-02-01 08:33 . 2010-02-01 08:33 -------- d-----w- c:\program files\ESET
2010-02-01 08:33 . 2010-02-01 08:33 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2010-02-01 07:10 . 2010-02-03 07:43 3216 ----a-w- c:\windows\system32\encobject.dat
2010-02-01 07:10 . 2010-02-01 07:10 -------- d-----w- c:\windows\system32\Client Security Solution
2010-02-01 07:04 . 2010-02-01 06:58 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\ThinkVantage
2010-02-01 07:04 . 2010-02-01 06:58 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Lenovo
2010-02-01 07:04 . 2010-02-01 06:48 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Symantec
2010-02-01 06:58 . 2010-02-01 06:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\ThinkVantage
2010-02-01 06:58 . 2010-02-01 06:58 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Lenovo
2010-02-01 06:58 . 2010-02-01 06:58 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Lenovo
2010-02-01 06:58 . 2010-02-01 07:07 -------- d-----w- c:\documents and settings\Administrator\Application Data\Lenovo
2010-02-01 06:56 . 2010-02-01 06:56 -------- d-sh--r- C:\RRbackups
2010-02-01 06:55 . 2006-05-04 10:00 115880 ----a-w- c:\windows\system32\pxinsi64.exe
2010-02-01 06:55 . 2006-03-09 09:00 114856 ----a-w- c:\windows\system32\pxcpyi64.exe
2010-02-01 06:54 . 2010-02-01 06:55 5427 ----a-w- c:\windows\system32\EGATHDRV.SYS
2010-02-01 06:53 . 2010-02-01 06:53 -------- d-----w- c:\program files\SMI2
2010-02-01 06:53 . 2010-02-01 06:53 -------- d-----w- c:\program files\TVT SMBus
2010-02-01 06:53 . 2010-02-01 07:10 -------- d-----w- C:\SWSHARE
2010-02-01 06:53 . 2010-02-01 06:54 23552 ----a-w- c:\windows\system32\drivers\psasrv.exe
2010-02-01 06:53 . 2010-02-01 06:53 7012 ----a-w- c:\windows\system32\drivers\pmemnt.sys
2010-02-01 06:53 . 2006-11-08 23:06 583232 ----a-w- c:\windows\system32\tvt_gina.dll
2010-02-01 06:53 . 2006-11-08 23:06 288320 ----a-w- c:\windows\system32\tvt_gina_api.dll
2010-02-01 06:53 . 2006-01-13 08:33 6016 ----a-w- c:\windows\system32\drivers\IBMBLDID.sys
2010-02-01 06:53 . 2005-11-08 17:27 11520 ----a-w- c:\windows\system32\drivers\ANC.sys
2010-02-01 06:53 . 2010-02-01 06:53 -------- d-----w- c:\program files\Diskeeper Corporation
2010-02-01 06:52 . 2010-02-01 06:52 -------- d-----w- c:\windows\Downloaded Installations
2010-02-01 06:52 . 2005-07-07 16:06 114688 ----a-w- c:\windows\desktopset.exe
2010-02-01 06:49 . 2010-02-01 06:49 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Symantec
2010-02-01 06:49 . 2010-01-31 23:20 40 ----a-w- c:\windows\system32\profile.dat
2010-02-01 06:48 . 2010-02-01 06:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\Symantec
2010-02-01 06:48 . 2010-01-31 23:21 -------- d-----w- c:\program files\Symantec
2010-02-01 06:48 . 2010-01-31 23:24 -------- d-----w- c:\program files\Symantec Client Security
2010-02-01 06:48 . 2010-01-31 23:21 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-02-01 06:48 . 2010-01-31 23:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-02-01 06:47 . 2010-02-01 06:47 -------- d-----w- c:\program files\PCDR5
2010-02-01 06:45 . 2002-11-22 10:57 204800 ----a-w- c:\windows\system32\IVIresizeW7.dll
2010-02-01 06:45 . 2002-11-22 10:57 200704 ----a-w- c:\windows\system32\IVIresizeA6.dll
2010-02-01 06:45 . 2002-11-22 10:57 192512 ----a-w- c:\windows\system32\IVIresizeP6.dll
2010-02-01 06:45 . 2002-11-22 10:57 192512 ----a-w- c:\windows\system32\IVIresizeM6.dll
2010-02-01 06:45 . 2002-11-22 10:57 188416 ----a-w- c:\windows\system32\IVIresizePX.dll
2010-02-01 06:42 . 2010-02-01 06:42 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2010-02-01 06:42 . 2010-01-31 23:23 -------- d-----w- c:\program files\Google
2010-02-01 06:42 . 2006-07-25 06:17 139264 ----a-w- c:\windows\system32\igfxres.dll
2010-02-01 06:42 . 2010-02-01 06:42 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Intel
2010-02-01 06:39 . 2005-05-04 17:20 53248 ----a-w- c:\windows\system32\wdmioctl.dll
2010-02-01 06:38 . 2006-03-16 03:04 479232 ----a-w- c:\windows\system32\TpShCPL.dll
2010-02-01 06:36 . 2008-04-14 00:12 28672 ----a-w- c:\windows\system32\verclsid.exe
2010-02-01 06:36 . 2010-02-01 06:46 -------- d-----w- c:\program files\Common Files\Installshield
2010-02-01 06:36 . 2010-02-01 06:36 -------- d-----w- c:\program files\Windows Media Connect 2
2010-02-01 06:32 . 2010-02-01 06:39 -------- d-----w- c:\program files\Analog Devices
2010-02-01 06:32 . 2008-04-13 18:36 13952 ----a-w- c:\windows\system32\drivers\cmbatt.sys
2010-02-01 06:32 . 2008-04-13 18:36 10240 ----a-w- c:\windows\system32\drivers\compbatt.sys
2010-02-01 06:32 . 2008-04-13 18:36 14208 ----a-w- c:\windows\system32\drivers\battc.sys
2010-02-01 06:32 . 2008-04-14 00:11 7168 ----a-w- c:\windows\system32\hccoin.dll
2010-02-01 06:32 . 2008-04-13 18:45 30208 ----a-w- c:\windows\system32\drivers\usbehci.sys
2010-02-01 06:32 . 2001-08-17 21:51 19584 ----a-w- c:\windows\system32\drivers\rasirda.sys
2010-02-01 06:32 . 2008-04-14 00:12 151552 ----a-w- c:\windows\system32\irftp.exe
2010-02-01 06:32 . 2008-04-14 00:12 8192 ----a-w- c:\windows\system32\wshirda.dll
2010-02-01 06:32 . 2008-04-13 18:54 88192 ----a-w- c:\windows\system32\drivers\irda.sys
2010-02-01 06:31 . 2008-04-13 18:54 28672 ----a-w- c:\windows\system32\drivers\nscirda.sys
2010-02-01 06:25 . 2010-02-01 07:05 -------- d-----w- C:\SWTOOLS
2010-02-01 06:22 . 2010-02-01 07:06 -------- d---a-w- C:\I386
2010-01-31 23:18 . 2010-01-31 23:18 12328 ----a-w- c:\documents and settings\Jakob Hansen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-03 03:58 . 2010-02-01 06:44 -------- d-----w- c:\program files\Common Files\Java
2010-02-01 18:34 . 2006-04-30 07:12 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-01 17:48 . 2010-02-01 17:48 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-01 17:01 . 2010-02-01 17:01 -------- d-----w- c:\program files\MSBuild
2010-02-01 07:07 . 2010-02-01 07:05 -------- d-----w- c:\documents and settings\Jakob Hansen\Application Data\Lenovo
2010-02-01 07:07 . 2010-02-01 06:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Lenovo
2010-02-01 07:05 . 2010-02-01 07:05 50 ----a-w- c:\windows\system32\drivers\LENOVO_1952_WLL.MRK
2010-02-01 06:58 . 2010-02-01 07:05 -------- d-----w- c:\documents and settings\Jakob Hansen\Application Data\ThinkVantage
2010-02-01 06:55 . 2010-02-01 06:54 5427 ----a-w- c:\windows\EGATHDRV.TMP
2010-02-01 06:54 . 2010-02-01 06:46 -------- d-----w- c:\program files\Common Files\Lenovo
2010-02-01 06:54 . 2010-02-01 06:39 -------- d-----w- c:\program files\Lenovo
2010-02-01 06:53 . 2006-11-17 00:14 17536 ----a-w- c:\windows\system32\drivers\psadd.sys
2010-02-01 06:53 . 2010-02-01 06:38 -------- d-----w- c:\program files\ThinkPad
2010-02-01 06:53 . 2010-02-01 06:38 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-01 06:48 . 2010-02-01 07:05 -------- d-----w- c:\documents and settings\Jakob Hansen\Application Data\Symantec
2010-02-01 06:46 . 2010-02-01 06:46 -------- d-----w- c:\program files\Sonic Icons for Lenovo
2010-02-01 06:46 . 2010-02-01 06:46 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2010-02-01 06:46 . 2010-02-01 06:46 -------- d-----w- c:\program files\Common Files\SureThing Shared
2010-02-01 06:46 . 2010-02-01 06:46 -------- d-----w- c:\program files\Sonic
2010-02-01 06:46 . 2010-02-01 06:46 -------- d-----w- c:\program files\Multimedia Center for Think Offerings
2010-02-01 06:46 . 2010-02-01 06:45 -------- d-----w- c:\program files\Common Files\Sonic Shared
2010-02-01 06:45 . 2010-02-01 06:45 -------- d-----w- c:\program files\InterVideo
2010-02-01 06:45 . 2010-02-01 06:44 -------- d-----w- c:\program files\ThinkVantage
2010-02-01 06:45 . 2010-02-01 06:44 -------- d-----w- c:\program files\Java
2010-02-01 06:40 . 2010-02-01 06:40 -------- d-----w- c:\documents and settings\LocalService\Application Data\Intel
2010-02-01 06:40 . 2010-02-01 06:40 -------- d-----w- c:\program files\Digital Line Detect
2010-02-01 06:40 . 2010-02-01 06:40 -------- d-----w- c:\program files\NetWaiting
2010-02-01 06:40 . 2010-02-01 06:40 -------- d-----w- c:\program files\CONEXANT
2010-02-01 06:39 . 2010-02-01 06:39 0 ---ha-r- c:\windows\system32\drivers\IBM_1952_WLL_TP.MRK
2010-02-01 06:39 . 2010-02-01 06:39 21419 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-02-01 06:39 . 2010-02-01 06:39 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Intel
2010-02-01 06:39 . 2010-02-01 06:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2010-02-01 06:39 . 2010-02-01 06:39 -------- d-----w- c:\program files\Intel
2010-02-01 06:38 . 2010-02-01 06:38 -------- d-----w- c:\program files\Synaptics
2009-12-22 05:21 . 2006-04-30 06:56 667136 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:20 . 2006-04-30 06:55 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-11-21 15:51 . 2006-04-30 06:55 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-16 17:06 . 2009-11-16 17:06 96408 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2009-11-16 17:03 . 2009-11-16 17:03 108792 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-11-16 16:56 . 2009-11-16 16:56 116520 ----a-w- c:\windows\system32\drivers\eamon.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-05-25 151552]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-05-25 208896]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2006-02-14 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-02-14 512000]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2006-02-23 237568]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-03 856064]
"TpShocks"="TpShocks.exe" [2006-03-16 106496]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-07-25 94208]
"TP4EX"="tp4ex.exe" [2005-10-17 65536]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-07-25 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-07-25 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-07-25 118784]
"LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2006-07-04 110592]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-28 81920]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-08-16 69632]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-07-15 503808]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-19 196696]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2007-02-20 409600]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2007-02-20 110592]
"PDService.exe"="c:\program files\Lenovo\SafeGuard PrivateDisk\pdservice.exe" [2006-03-14 41472]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-15 2341632]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify]
2006-08-16 17:07 49152 ----a-w- c:\program files\Lenovo\AwayTask\AwayNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 14:45 28672 ----a-w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 11:16 24576 ----a-w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16-11-2009 09:03 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16-11-2009 09:06 96408]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16-11-2009 09:04 735960]
R2 PrivateDisk;PrivateDisk;c:\program files\Lenovo\SafeGuard PrivateDisk\privatediskm.sys [13-03-2006 16:05 58368]
R2 smi2;smi2;c:\program files\SMI2\smi2.sys [14-07-2006 15:55 3968]
.
Contents of the 'Scheduled Tasks' folder
2010-02-03 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2010-02-01 16:13]
2010-02-01 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2010-02-01 01:32]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.lenovo.com/welcome/thinkpaduInternet Connection Wizard,ShellNext =
hxxp://www.lenovo.com/welcome/thinkpaduInternet Settings,ProxyServer = 192.168.1.2:8080
uInternet Settings,ProxyOverride =
https://80.209.94.10*FF - ProfilePath - c:\documents and settings\Jakob Hansen\Application Data\Mozilla\Firefox\Profiles\56dridz9.default\
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "
chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "
chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Proxy - \\gg-fs1\sys\public\copyggxp.bat
HKLM-Run-(Default) - c:\windows\svchost.exe
Notify-ACNotify - ACNotify.dll
Notify-NavLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-02 23:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1348)
c:\windows\system32\tvt_gina.dll
c:\program files\Lenovo\Client Security Solution\css_gina_plugin.dll
c:\program files\Lenovo\Client Security Solution\css_wait_bar.dll
c:\program files\Lenovo\Client Security Solution\cssuserdatadispatcher.dll
c:\program files\Lenovo\Client Security Solution\csswait.dll
c:\program files\Common Files\Lenovo\tvt_banner.dll
c:\program files\Lenovo\Client Security Solution\cssdlgpwentry.dll
c:\program files\Lenovo\Client Security Solution\dlganswerprompt.dll
c:\program files\Lenovo\Client Security Solution\tvttsp.dll
c:\program files\Lenovo\Client Security Solution\tcsrpc.dll
c:\program files\Common Files\Lenovo\tvt_res.dll
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\tphklock.dll
c:\program files\Lenovo\AwayTask\AwayNotify.dll
- - - - - - - > 'explorer.exe'(3400)
c:\windows\system32\PROCHLP.DLL
c:\program files\Lenovo\Client Security Solution\tvtpwm_windows_hook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\lenovo\system update\suservice.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\System32\TPHDEXLG.EXE
c:\windows\system32\TpKmpSVC.exe
c:\program files\Lenovo\Client Security Solution\tvttcsd.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files\Lenovo\Rescue and Recovery\ADM\IUService.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\Lenovo\Logger\logmon.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\TpShocks.exe
c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\ThinkPad\UltraNav Wizard\UNavTray.EXE
c:\program files\Lenovo\Client Security Solution\tvtpwm_tray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-02-02 23:46:57 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-03 07:46
Pre-Run: 40.575.778.816 bytes free
Post-Run: 40.535.080.960 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 312D24C052F9C5DAF704E1415CF1ADEE