DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 16:03:05.73 on Tue 03/23/2010 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_02 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1338 [GMT -4:00] AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} FW: Symantec Client Firewall *enabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187} ============== Running Processes =============== C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\system32\Drivers\trcboot.exe C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe C:\Program Files\IBM\SQLLIB\BIN\db2jds.exe C:\Program Files\IBM\SQLLIB\BIN\db2sec.exe C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe C:\Program Files\IBM\AgentController\bin\RAService.exe C:\Program Files\C4ebreg\c4ebreg.exe c:\sdwork\issimsvc.exe C:\notes\ntmulti.exe C:\Program Files\AT&T Network Client\NetCfgSv.EXE c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe C:\WINDOWS\System32\TPHDEXLG.EXE C:\WINDOWS\system32\TpKmpSVC.exe C:\qipV61\MessageService.exe C:\qipV61\SSLTService.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\Drivers\ldlcserv.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\TortoiseSVN\bin\TSVNCache.exe C:\Program Files\C4ebreg\isamtray.exe C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\TpShocks.exe C:\WINDOWS\system32\acs.exe C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe C:\Program Files\IBM\My Help\workspace\service\delayStart.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe C:\Program Files\IBM\Personal Communications\tpam.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.4.19\pmonmh.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~2\SYMANT~2\vptray.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe C:\Documents and Settings\Administrator\Local Settings\Application Data\ATT Connect\Participant\pull.exe C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090605-2002\soffice.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Documents and Settings\Administrator\Desktop\Removal\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://w3.ibm.com/ uLocal Page = c:\winnt\system32\blank.htm uInternet Connection Wizard,ShellNext = iexplore uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: IERationalEnabler Class: {1e9fb1c4-f40b-4e10-898e-d6209b122f6b} - c:\program files\ibm\rational\sdp\6.0\functionaltester\eclipse\plugins\com.rational.test.ft.wswplugin_6.1.0\RTXIEEnabler.dll BHO: EVoIpSessionCookie Class: {424b6ad1-785d-43e7-9c9b-ab96e77477d0} - c:\program files\attcv\programs\EVoIPAxCtrls.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_02\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [Push Client] "c:\documents and settings\administrator\local settings\application data\att connect\participant\pull.exe" uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [SODCPreLoad] c:\program files\ibm\lotus\symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090605-2002\preload.exe c:\docume~1\admini~1\ibm\lotus\symphony\.sodc\ mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [PHIME2002ASync] "c:\windows\system32\ime\tintlgnt\TINTSETP.EXE" /SYNC mRun: [PHIME2002A] "c:\windows\system32\ime\tintlgnt\TINTSETP.EXE" /IMEName mRun: [ISAMTray] "c:\program files\c4ebreg\isamtray.exe" mRun: [stgclean] "c:\sdwork\w32main2.exe" /cleanup mRun: [TPHOTKEY] "c:\progra~1\lenovo\pkgmgr\hotkey\TPHKMGR.exe" mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor mRun: [BMMLREF] "c:\program files\thinkpad\utilities\BMMLREF.EXE" mRun: [BMMMONWND] "rundll32.exe" c:\progra~1\thinkpad\utilit~1\BatInfEx.dll,BMMAutonomicMonitor mRun: [BLOG] "rundll32.exe" c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog mRun: [SynTPLpr] "c:\program files\synaptics\syntp\SynTPLpr.exe" mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe" mRun: [TP4EX] "tp4ex.exe" mRun: [TPKMAPHELPER] "c:\program files\thinkpad\utilities\TpKmapAp.exe" -helper mRun: [TpShocks] "TpShocks.exe" mRun: [ACTray] "c:\program files\thinkpad\connectutilities\ACTray.exe" mRun: [ACWLIcon] "c:\program files\thinkpad\connectutilities\ACWLIcon.exe" mRun: [MyHelpService] c:\program files\ibm\my help\workspace\service\delayStart.exe mRun: [dla] "c:\windows\system32\dla\tfswctrl.exe" mRun: [C4EBReg] "c:\program files\c4ebreg\c4ebreg.exe" /q mRun: [Tpam.exe] "c:\program files\ibm\personal communications\tpam.exe" mRun: [pmonmh] c:\program files\ibm\my help\plugins\\com.ibm.myhelp.common_1.4.19/pmonmh.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~2\symant~2\\vptray.exe mRun: [ISSI Service] "c:\sdwork\issimsvc.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe" mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe" mRun: [NPDTRAY] c:\progra~1\thinkpad\utilit~1\NPDTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\lotusq~1.lnk - c:\lotus\wordpro\ltsstart.exe uPolicies-explorer: NoDevMgrUpdate = 1 (0x1) IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_02\bin\ssv.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} - hxxps://gassl12.vpn.att.com/CACHE/stc/1/binaries/vpnweb.cab DPF: {705EC6D4-B138-4079-A307-EF13E4889A82} - hxxps://gassl12.vpn.att.com/CACHE/sdesktop/install/binaries/instweb.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {7A162288-DE78-473C-A6BA-23FF17F768E9} - hxxps://att.interwise.com/att/Application/EventEntry/AxWebInstaller.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {9519B2A2-6592-4E41-8290-D0298459270C} - hxxp://w3.ibm.com/bluepages/scripts/lnwebassist.cab DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} - hxxp://rnyenos8.rochny.ibm.com/viewer/activeXViewer/activexviewer.cab DPF: {CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2_13-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553518000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll Notify: pcsinst - pcsinst.dll Notify: tpfnf2 - notifyf2.dll Notify: tphotkey - tphklock.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\e24oiie0.default\ FF - prefs.js: browser.search.selectedEngine - Ask.com FF - prefs.js: browser.startup.homepage - hxxp://w3.ibm.com/ FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\e24oiie0.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\e24oiie0.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - plugin: c:\program files\ibm\java142\jre\bin\npjava11.dll FF - plugin: c:\program files\ibm\java142\jre\bin\npjava12.dll FF - plugin: c:\program files\ibm\java142\jre\bin\npjava13.dll FF - plugin: c:\program files\ibm\java142\jre\bin\npjava14.dll FF - plugin: c:\program files\ibm\java142\jre\bin\npjava32.dll FF - plugin: c:\program files\ibm\java142\jre\bin\NPJPI142.dll FF - plugin: c:\program files\ibm\java142\jre\bin\npoji610.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npstloader.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R1 SAVRT;SAVRT;c:\program files\symantec client security\symantec antivirus\savrt.sys [2006-9-6 337592] R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec client security\symantec antivirus\Savrtpel.sys [2006-9-6 54968] R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2006-5-18 16384] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-19 192160] R2 ccProxy;Symantec Network Proxy;c:\program files\common files\symantec shared\ccProxy.exe [2006-7-19 202400] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-19 169632] R2 IBM Rational Agent Controller;IBM Rational Agent Controller;c:\program files\ibm\agentcontroller\bin\RAService.exe [2007-1-17 77824] R2 SavRoam;SAVRoam;c:\program files\symantec client security\symantec antivirus\SavRoam.exe [2006-9-27 116464] R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec client security\symantec antivirus\Rtvscan.exe [2006-9-27 1813232] R2 VitalQIP Message Service;VitalQIP Message Service;c:\qipv61\MessageService.exe [2006-10-11 126976] R2 VitalQIP SSL Tunnel Service;VitalQIP SSL Tunnel Service;c:\qipv61\SSLTService.exe [2006-10-11 40960] R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2008-8-20 370872] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-27 102448] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100322.004\naveng.sys [2010-3-22 84912] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100322.004\navex15.sys [2010-3-22 1324720] S3 gwiopm;gwiopm;\??\c:\program files\wst\gwiopm.sys --> c:\program files\wst\gwiopm.sys [?] S3 IsamFilter;IsamFilter;c:\windows\system32\drivers\isamfilter.sys [2009-10-9 6400] =============== Created Last 30 ================ 2010-03-17 15:10:25 0 d-----w- c:\docume~1\alluse~1\applic~1\Cisco 2010-03-17 15:10:24 0 d-----w- c:\program files\Cisco 2010-03-17 15:09:12 0 d-----w- c:\docume~1\admini~1\applic~1\Cisco 2010-03-16 15:19:14 0 d-----w- c:\program files\ESET 2010-03-12 16:57:11 98816 ----a-w- c:\windows\sed.exe 2010-03-12 16:57:11 77312 ----a-w- c:\windows\MBR.exe 2010-03-12 16:57:11 261632 ----a-w- c:\windows\PEV.exe 2010-03-12 16:57:11 161792 ----a-w- c:\windows\SWREG.exe 2010-03-05 14:36:43 17920 -c----w- c:\windows\system32\dllcache\msyuv.dll 2010-03-05 14:35:02 8704 -c----w- c:\windows\system32\dllcache\tsbyuv.dll 2010-03-05 14:35:00 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll ==================== Find3M ==================== 2010-02-25 18:11:13 64792 ----a-w- c:\windows\isamunin.exe 2010-02-15 15:09:15 6400 ----a-w- c:\windows\system32\drivers\isamfilter.sys 2010-01-29 17:56:01 60088 ----a-w- c:\docume~1\admini~1\applic~1\GDIPFONTCACHEV1.DAT ============= FINISH: 16:04:29.47 ===============