Shiftlemac
Ah yes, apologies, this one should be correct:
ComboFix 10-04-21.01 - GB090455 22/04/2010 17:00:31.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1992.1442 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Client Firewall *disabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187}
FILE ::
"c:\windows\system32\msln.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\documents and settings\Administrator\Application Data\Ziwytu
c:\windows\system32\msln.exe
.
((((((((((((((((((((((((( Files Created from 2010-03-22 to 2010-04-22 )))))))))))))))))))))))))))))))
.
2010-04-22 11:39 . 2010-04-22 11:39 ——– d—–w- c:\program files\Recuva
2010-04-22 10:16 . 2010-04-22 11:39 ——– d—–w- c:\program files\NTFS Undelete
2010-04-18 20:10 . 2010-04-21 09:48 ——– d—–w- c:\program files\JDownloader
2010-04-18 16:56 . 2010-04-18 16:56 ——– d-sh–w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache
2010-04-18 16:52 . 2010-04-18 16:52 ——– d—–w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Google
2010-04-18 16:51 . 2010-04-18 17:02 ——– d—–w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft
2010-04-18 16:51 . 2005-04-04 17:56 ——– d-s—w- c:\documents and settings\NetworkService.NT AUTHORITY\UserData
2010-04-18 16:51 . 2010-04-18 16:56 ——– d-sh–w- c:\documents and settings\NetworkService.NT AUTHORITY
2010-04-16 11:49 . 2010-04-16 11:49 ——– d—–w- c:\documents and settings\Administrator\Application Data\No Company Name
2010-04-16 10:20 . 2010-04-16 10:21 ——– d—–w- c:\documents and settings\All Users\Application Data\SmartSound Software Inc
2010-04-16 10:20 . 2010-04-16 10:20 ——– d—–w- c:\program files\SmartSound Software
2010-04-15 21:04 . 2010-04-15 21:04 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\HandBrake
2010-04-15 21:04 . 2010-04-15 23:09 ——– d—–w- c:\documents and settings\Administrator\Application Data\HandBrake
2010-04-13 15:38 . 2010-04-13 15:38 ——– d—–w- c:\program files\TagRename
2010-04-13 10:06 . 2010-04-13 10:06 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-13 10:05 . 2010-04-13 10:10 ——– d—–w- c:\program files\SpywareBlaster
2010-04-13 01:46 . 2010-04-20 02:34 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-13 00:19 . 2010-04-13 00:19 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Flickr
2010-04-13 00:19 . 2010-04-13 00:19 ——– d—–w- c:\documents and settings\Administrator\Application Data\Flickr
2010-04-12 23:37 . 2010-04-12 23:37 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Geckofx
2010-04-12 23:37 . 2010-04-12 23:37 ——– d—–w- c:\documents and settings\Administrator\Application Data\Red Kawa
2010-04-12 22:52 . 2010-04-12 22:52 ——– d—–w- c:\program files\mp4UI
2010-04-12 22:45 . 2010-04-12 22:45 ——– d—–w- c:\program files\lame
2010-04-12 22:20 . 2010-04-12 22:24 ——– d—–w- c:\program files\Yamb
2010-04-12 22:06 . 2010-04-13 17:47 ——– d—–w- c:\documents and settings\Administrator\Application Data\avidemux
2010-04-12 22:06 . 2010-04-15 20:29 ——– d—–w- c:\program files\Avidemux 2.5
2010-04-12 22:00 . 2010-04-12 22:05 ——– d—–w- c:\program files\VirtualDub-1.9.9
2010-04-12 21:16 . 2010-04-12 22:04 ——– d—–w- c:\program files\GSpot270a
2010-04-12 17:40 . 2010-04-12 17:40 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2010-04-12 17:40 . 2010-04-12 17:40 ——– d-sh–w- c:\documents and settings\LocalService\IECompatCache
2010-04-12 11:35 . 2009-06-26 00:22 319000 —-a-w- c:\windows\system32\drivers\iastor.sys
2010-04-12 11:35 . 2009-06-26 00:22 319000 —-a-w- C:\iastor.sys
2010-04-07 09:30 . 2010-04-07 09:30 ——– d—–w- c:\program files\Trend Micro
2010-04-07 08:32 . 2010-04-07 08:33 3908515 —-a-r- c:\program files\ComboFix.exe
2010-04-07 07:20 . 2010-04-07 07:20 ——– d—–w- C:\RegBackup
2010-04-06 21:13 . 2010-04-06 21:13 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-06 19:52 . 2010-04-06 19:52 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-04-06 19:52 . 2010-03-29 23:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-06 19:52 . 2010-04-06 19:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-06 19:52 . 2010-03-29 23:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-06 19:52 . 2010-04-06 19:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-05 18:52 . 2010-04-05 18:52 ——– d—–w- c:\program files\BBC iPlayer Desktop
2010-04-01 22:42 . 2010-04-01 22:43 ——– d—–w- c:\program files\MagicDisc
2010-04-01 22:42 . 2009-02-24 16:42 116736 —-a-w- c:\windows\system32\drivers\mcdbus.sys
2010-04-01 21:56 . 2010-04-01 21:56 ——– d—–w- c:\windows\system32\syncdb
2010-04-01 21:27 . 2010-04-01 21:27 ——– d—–w- c:\program files\Windows Installer Clean Up
2010-03-31 13:31 . 2009-05-18 11:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-03-31 13:31 . 2008-04-17 10:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-03-31 13:30 . 2010-03-31 13:30 ——– d—–w- c:\program files\iPod
2010-03-31 13:30 . 2010-03-31 13:31 ——– d—–w- c:\program files\iTunes
2010-03-31 13:30 . 2010-03-31 13:31 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-03-31 13:29 . 2010-03-31 13:29 ——– d—–w- c:\program files\QuickTime
2010-03-31 13:29 . 2010-04-15 02:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-03-31 13:27 . 2010-03-31 13:27 ——– d—–w- c:\program files\Apple Software Update
2010-03-31 13:27 . 2009-10-16 00:33 41472 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-03-31 13:27 . 2009-10-16 00:33 3003680 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-03-31 13:27 . 2010-03-31 13:27 ——– d—–w- c:\program files\Bonjour
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-22 15:59 . 2005-04-05 17:21 ——– d—–w- c:\program files\C4ebreg
2010-04-22 15:56 . 2007-03-05 22:09 40 —-a-w- c:\windows\system32\profile.dat
2010-04-22 13:00 . 2010-02-19 00:23 ——– d—–w- c:\documents and settings\Administrator\Application Data\vlc
2010-04-22 11:40 . 2006-01-24 00:45 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-04-22 11:14 . 2009-06-26 00:54 ——– d—–w- c:\program files\AT&T Network Client
2010-04-21 11:34 . 2009-08-22 15:57 ——– d—–w- c:\documents and settings\Administrator\Application Data\dvdcss
2010-04-19 19:03 . 2009-12-27 15:32 ——– d—–w- c:\documents and settings\Administrator\Application Data\Giqay
2010-04-19 12:30 . 2006-03-27 21:50 ——– d—–w- c:\program files\WST
2010-04-19 05:07 . 2009-02-11 21:17 23552 —-a-w- c:\windows\system32\drivers\abp480n5.sys
2010-04-18 23:10 . 2009-06-30 15:07 ——– d—–w- c:\program files\Foxit Reader
2010-04-17 14:44 . 2006-04-12 02:08 ——– d—–w- c:\program files\Common Files\Adobe
2010-04-16 10:26 . 2005-04-04 18:17 47168 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-15 21:04 . 2009-08-14 17:22 ——– d—–w- c:\program files\HandBrake
2010-04-15 17:30 . 2009-07-24 21:16 ——– d—–w- c:\program files\Google
2010-04-13 00:19 . 2009-11-22 19:11 ——– d—–w- c:\program files\Flickr Uploadr
2010-04-12 22:46 . 2009-10-16 20:37 ——– d—–w- c:\documents and settings\Administrator\Application Data\foobar2000
2010-04-12 17:37 . 2009-10-31 19:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-11 18:57 . 2010-01-30 12:28 ——– d—–w- c:\documents and settings\Administrator\Application Data\Apple Computer
2010-04-07 08:41 . 2009-08-14 17:43 ——– d—–w- c:\program files\T-Mobile Internet Manager
2010-04-07 06:42 . 2010-04-06 19:51 319000 —-a-w- c:\windows\system32\drivers\tsk29.tmp
2010-04-06 21:16 . 2009-10-31 20:35 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-06 21:16 . 2009-10-31 20:54 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-04-06 21:13 . 2009-10-31 19:49 ——– d—–w- c:\program files\Lavasoft
2010-04-05 18:50 . 2009-06-26 20:01 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-04-01 21:27 . 2007-10-10 15:20 ——– d—–w- c:\program files\MSECache
2010-03-31 13:30 . 2010-01-17 03:54 ——– d—–w- c:\program files\Common Files\Apple
2010-02-26 16:34 . 2009-10-07 10:07 6400 —-a-w- c:\windows\system32\drivers\isamfilter.sys
2010-02-26 13:11 . 2010-02-26 13:11 ——– d—–w- c:\documents and settings\Administrator\Application Data\Facebook
2010-02-25 18:11 . 2005-07-29 18:05 64792 —-a-w- c:\windows\isamunin.exe
2010-02-12 09:46 . 2010-02-12 09:46 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 09:46 . 2010-02-12 09:46 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-02-04 15:53 . 2009-10-31 20:35 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
.
((((((((((((((((((((((((((((( SnapShot_2010-04-19_11.20.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-22 15:59 . 2010-04-22 15:59 16384 c:\windows\Temp\Perflib_Perfdata_b0c.dat
+ 2004-08-04 05:00 . 2004-08-04 05:00 37888 c:\windows\system32\url.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 39424 c:\windows\system32\pngfilt.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 96256 c:\windows\system32\occache.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 56832 c:\windows\system32\mshtmler.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 29184 c:\windows\system32\mshta.exe
+ 2004-08-04 05:00 . 2004-08-04 05:00 22016 c:\windows\system32\licmgr10.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 16384 c:\windows\system32\jsproxy.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 96256 c:\windows\system32\inseng.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 35840 c:\windows\system32\imgutil.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 62976 c:\windows\system32\iesetup.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 48640 c:\windows\system32\iernonce.dll
+ 2009-06-29 15:09 . 2009-04-29 04:52 81920 c:\windows\system32\ieencode.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 34304 c:\windows\system32\ie4uinit.exe
+ 2004-08-04 05:00 . 2004-08-04 05:00 37888 c:\windows\system32\dllcache\url.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 39424 c:\windows\system32\dllcache\pngfilt.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 96256 c:\windows\system32\dllcache\occache.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 56832 c:\windows\system32\dllcache\mshtmler.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 29184 c:\windows\system32\dllcache\mshta.exe
+ 2004-08-04 05:00 . 2004-08-04 05:00 22016 c:\windows\system32\dllcache\licmgr10.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 16384 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 96256 c:\windows\system32\dllcache\inseng.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 35840 c:\windows\system32\dllcache\imgutil.dll
+ 2005-04-04 17:41 . 2004-08-04 05:00 93184 c:\windows\system32\dllcache\iexplore.exe
+ 2004-08-04 05:00 . 2004-08-04 05:00 62976 c:\windows\system32\dllcache\iesetup.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 48640 c:\windows\system32\dllcache\iernonce.dll
+ 2009-06-29 15:09 . 2009-04-29 04:52 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 34304 c:\windows\system32\dllcache\ie4uinit.exe
+ 2005-04-04 17:41 . 2004-08-04 05:00 38912 c:\windows\system32\dllcache\hmmapi.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 35328 c:\windows\system32\dllcache\corpol.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 99840 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 61440 c:\windows\system32\dllcache\admparse.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 35328 c:\windows\system32\corpol.dll
+ 2005-04-04 17:46 . 2010-04-22 15:51 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-04-04 17:46 . 2010-04-19 11:10 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-04-11 21:09 . 2010-04-19 11:10 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-04-19 11:30 . 2010-04-22 15:51 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2004-08-04 05:00 . 2004-08-04 05:00 99840 c:\windows\system32\advpack.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 61440 c:\windows\system32\admparse.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 659456 c:\windows\system32\wininet.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 276480 c:\windows\system32\webcheck.dll
+ 2004-08-04 05:00 . 2007-12-18 14:40 417792 c:\windows\system32\vbscript.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 616448 c:\windows\system32\urlmon.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 532480 c:\windows\system32\mstime.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 146432 c:\windows\system32\msrating.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 146432 c:\windows\system32\msls31.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 449024 c:\windows\system32\mshtmled.dll
+ 2004-08-04 05:00 . 2007-12-18 14:40 450560 c:\windows\system32\jscript.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 251392 c:\windows\system32\iepeers.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 323584 c:\windows\system32\iedkcs32.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 221184 c:\windows\system32\ieakui.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 216576 c:\windows\system32\ieaksie.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 139264 c:\windows\system32\ieakeng.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 205312 c:\windows\system32\dxtrans.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 357888 c:\windows\system32\dxtmsft.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 659456 c:\windows\system32\dllcache\wininet.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 276480 c:\windows\system32\dllcache\webcheck.dll
+ 2005-04-04 17:42 . 2007-06-26 15:13 851968 c:\windows\system32\dllcache\vgx.dll
+ 2004-08-04 05:00 . 2007-12-18 14:40 417792 c:\windows\system32\dllcache\vbscript.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 616448 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 532480 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 146432 c:\windows\system32\dllcache\msrating.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 146432 c:\windows\system32\dllcache\msls31.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 449024 c:\windows\system32\dllcache\mshtmled.dll
+ 2004-08-04 05:00 . 2007-12-18 14:40 450560 c:\windows\system32\dllcache\jscript.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 251392 c:\windows\system32\dllcache\iepeers.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 323584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 221184 c:\windows\system32\dllcache\ieakui.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 216576 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 139264 c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 205312 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 357888 c:\windows\system32\dllcache\dxtmsft.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 3060736 c:\windows\system32\mshtml.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 3060736 c:\windows\system32\dllcache\mshtml.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetSP - restore settings on power failure"="c:\program files\AT&T Network Client\NetSP.exe" [2007-01-13 24576]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-05-21 1134592]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-07-16 307768]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-03 135664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pmonmh"="c:\program files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.4.19" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"stgclean"="c:\sdwork\w32maing.exe" [2010-04-07 267776]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~2\SYMANT~2\VPTray.exe" [2006-09-27 125168]
"Tpam.exe"="c:\program files\IBM\Personal Communications\tpam.exe" [2007-11-02 28672]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-06-26 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-06-26 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-06-26 141848]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592]
"TpShocks"="TpShocks.exe" [2008-06-06 181536]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2009-06-26 331776]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2009-06-26 208896]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-26 820520]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-06-26 60192]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-03-24 68464]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-08-15 143360]
"ipmcmu"="c:\program files\IBM\IPM Client Migration Utility\ipmcmu.exe" [2009-06-29 204800]
"ISSI Service"="c:\sdwork\issimsvc.exe" [2010-02-11 241392]
"C4EBReg"="c:\program files\c4ebreg\c4ebreg.exe" [2010-02-25 482584]
"Isamtray"="c:\program files\c4ebreg\isamtray.exe" [2010-02-25 285976]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-29 148888]
"UIExec"="c:\program files\T-Mobile Internet Manager\UIExec.exe" [2009-06-12 132608]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-25 142120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Check for TWS Updates.lnk - c:\jts\WiseUpdt.exe [2010-2-24 194775]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2009-10-02 128360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pcsinst]
2007-11-02 10:45 49152 —-a-w- c:\windows\system32\pcsinst.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 16:37 34344 —-a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2008-03-17 16:02 34080 —-a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\assistant2]
2006-10-20 09:01 2107392 —-a-w- c:\program files\VoiceRite\Client\Viewer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 16:44 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"IBMconfig"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AT&T Network Client\\NetClient.exe"=
"c:\\Program Files\\IBM\\Lotus\\Sametime Connect\\rcp\\eclipse\\plugins\\com.ibm.rcp.jcl.desktop.win32.x86_6.2.0.200810071032\\jre\\bin\\sametime80w.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [31/10/2009 21:35 64288]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [14/05/2008 17:21 19496]
R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [09/10/2009 04:45 169312]
R2 pdlndldl6;IBM Enterprise Extender (HPR/IPv6);c:\windows\system32\drivers\pdlndldl6.sys [02/11/2007 05:09 70656]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [26/06/2009 01:22 243856]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [04/09/2009 20:31 102448]
R3 IsamFilter;IsamFilter;c:\windows\system32\drivers\isamfilter.sys [07/10/2009 11:07 6400]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [24/07/2009 22:16 133104]
S3 csrcmds;csrcmds;c:\program files\IBM\Personal Communications\csrcmds.exe [02/11/2007 05:09 49152]
S3 cstrcser;IBM Command Line Trace;c:\windows\system32\drivers\cstrcser.exe [02/11/2007 05:09 36864]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [14/08/2009 18:43 9728]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [16/10/2009 22:12 721904]
— Other Services/Drivers In Memory —
*Deregistered* - BMLoad
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-04-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 21:15]
2010-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-24 21:16]
2010-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-24 21:16]
2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2869554992-1010074173-1580797646-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-03 08:21]
2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2869554992-1010074173-1580797646-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-03 08:21]
2010-04-22 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2009-06-26 00:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://w3.ibm.com/
uInternet Connection Wizard,ShellNext = hxxp://w3.ibm.com/
uInternet Settings,ProxyServer = proxy.emea.ibm.com:8080
uInternet Settings,ProxyOverride = localhost;127.0.0.1;*.local;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} - hxxp://
DPF: {9519B2A2-6592-4E41-8290-D0298459270C} - hxxp://w3.ibm.com/bluepages/scripts/lnwebassist.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff36\gears.dll
FF - plugin: c:\documents and settings\Administrator\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-22 17:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ipmcmu = c:\program files\IBM\IPM Client Migration Utility\ipmcmu.exe "c:\program files\IBM\IPM Client Migration Utility"?run key ipmcmu was set successfully?run key ipmcmu was not set successfully?Error, Windows run key not found?The service "Task Scheduler" is not ru
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: >>UNKNOWN [0x804D7000]<< >>UNKNOWN [0xF77EF000]<< >>UNKNOWN [0xF76B7000]<< >>UNKNOWN [0xF76A7000]<< >>UNKNOWN [0xF75A8000]<< >>UNKNOWN [0x806FF000]<< >>UNKNOWN [0xF7B0F000]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0xf76bbfc3
\Driver\ACPI -> 0xf75aecb8
\Driver\atapi -> 0xf746a814
\Driver\iaStor -> 0xf7b4b992
IoDeviceObjectType -> DeleteProcedure -> 0x805e4d69
ParseProcedure -> 0x8057950b
\Device\Harddisk0\DR0 -> DeleteProcedure -> 0x805e4d69
ParseProcedure -> 0x8057950b
NDIS: Intel® WiFi Link 5100 AGN -> SendCompleteHandler -> 0xba62dbb0
PacketIndicateHandler -> 0xba61ca0d
SendHandler -> 0xba630b40
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iastor]
"ImagePath"="system32\drivers\tsk29.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-2869554992-1010074173-1580797646-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,6e,02,39,19,25,c4,84,41,8d,4f,c0,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,fe,38,df,56,87,6c,4c,b5,1c,3e,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1052)
c:\program files\Lenovo\HOTKEY\tphklock.dll
c:\windows\system32\pcsinst.dll
.
Completion time: 2010-04-22 17:16:02
ComboFix-quarantined-files.txt 2010-04-22 16:16
ComboFix2.txt 2010-04-19 11:26
ComboFix3.txt 2010-04-07 09:28
Pre-Run: 2,719,248,384 bytes free
Post-Run: 2,677,514,240 bytes free
- - End Of File - - 5673D7875BE4C83874A39B6661F6A48B
ComboFix 10-04-21.01 - GB090455 22/04/2010 17:00:31.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1992.1442 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Client Firewall *disabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187}
FILE ::
"c:\windows\system32\msln.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\documents and settings\Administrator\Application Data\Ziwytu
c:\windows\system32\msln.exe
.
((((((((((((((((((((((((( Files Created from 2010-03-22 to 2010-04-22 )))))))))))))))))))))))))))))))
.
2010-04-22 11:39 . 2010-04-22 11:39 ——– d—–w- c:\program files\Recuva
2010-04-22 10:16 . 2010-04-22 11:39 ——– d—–w- c:\program files\NTFS Undelete
2010-04-18 20:10 . 2010-04-21 09:48 ——– d—–w- c:\program files\JDownloader
2010-04-18 16:56 . 2010-04-18 16:56 ——– d-sh–w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache
2010-04-18 16:52 . 2010-04-18 16:52 ——– d—–w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Google
2010-04-18 16:51 . 2010-04-18 17:02 ——– d—–w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft
2010-04-18 16:51 . 2005-04-04 17:56 ——– d-s—w- c:\documents and settings\NetworkService.NT AUTHORITY\UserData
2010-04-18 16:51 . 2010-04-18 16:56 ——– d-sh–w- c:\documents and settings\NetworkService.NT AUTHORITY
2010-04-16 11:49 . 2010-04-16 11:49 ——– d—–w- c:\documents and settings\Administrator\Application Data\No Company Name
2010-04-16 10:20 . 2010-04-16 10:21 ——– d—–w- c:\documents and settings\All Users\Application Data\SmartSound Software Inc
2010-04-16 10:20 . 2010-04-16 10:20 ——– d—–w- c:\program files\SmartSound Software
2010-04-15 21:04 . 2010-04-15 21:04 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\HandBrake
2010-04-15 21:04 . 2010-04-15 23:09 ——– d—–w- c:\documents and settings\Administrator\Application Data\HandBrake
2010-04-13 15:38 . 2010-04-13 15:38 ——– d—–w- c:\program files\TagRename
2010-04-13 10:06 . 2010-04-13 10:06 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-13 10:05 . 2010-04-13 10:10 ——– d—–w- c:\program files\SpywareBlaster
2010-04-13 01:46 . 2010-04-20 02:34 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-13 00:19 . 2010-04-13 00:19 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Flickr
2010-04-13 00:19 . 2010-04-13 00:19 ——– d—–w- c:\documents and settings\Administrator\Application Data\Flickr
2010-04-12 23:37 . 2010-04-12 23:37 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Geckofx
2010-04-12 23:37 . 2010-04-12 23:37 ——– d—–w- c:\documents and settings\Administrator\Application Data\Red Kawa
2010-04-12 22:52 . 2010-04-12 22:52 ——– d—–w- c:\program files\mp4UI
2010-04-12 22:45 . 2010-04-12 22:45 ——– d—–w- c:\program files\lame
2010-04-12 22:20 . 2010-04-12 22:24 ——– d—–w- c:\program files\Yamb
2010-04-12 22:06 . 2010-04-13 17:47 ——– d—–w- c:\documents and settings\Administrator\Application Data\avidemux
2010-04-12 22:06 . 2010-04-15 20:29 ——– d—–w- c:\program files\Avidemux 2.5
2010-04-12 22:00 . 2010-04-12 22:05 ——– d—–w- c:\program files\VirtualDub-1.9.9
2010-04-12 21:16 . 2010-04-12 22:04 ——– d—–w- c:\program files\GSpot270a
2010-04-12 17:40 . 2010-04-12 17:40 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2010-04-12 17:40 . 2010-04-12 17:40 ——– d-sh–w- c:\documents and settings\LocalService\IECompatCache
2010-04-12 11:35 . 2009-06-26 00:22 319000 —-a-w- c:\windows\system32\drivers\iastor.sys
2010-04-12 11:35 . 2009-06-26 00:22 319000 —-a-w- C:\iastor.sys
2010-04-07 09:30 . 2010-04-07 09:30 ——– d—–w- c:\program files\Trend Micro
2010-04-07 08:32 . 2010-04-07 08:33 3908515 —-a-r- c:\program files\ComboFix.exe
2010-04-07 07:20 . 2010-04-07 07:20 ——– d—–w- C:\RegBackup
2010-04-06 21:13 . 2010-04-06 21:13 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-06 19:52 . 2010-04-06 19:52 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-04-06 19:52 . 2010-03-29 23:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-06 19:52 . 2010-04-06 19:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-06 19:52 . 2010-03-29 23:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-06 19:52 . 2010-04-06 19:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-05 18:52 . 2010-04-05 18:52 ——– d—–w- c:\program files\BBC iPlayer Desktop
2010-04-01 22:42 . 2010-04-01 22:43 ——– d—–w- c:\program files\MagicDisc
2010-04-01 22:42 . 2009-02-24 16:42 116736 —-a-w- c:\windows\system32\drivers\mcdbus.sys
2010-04-01 21:56 . 2010-04-01 21:56 ——– d—–w- c:\windows\system32\syncdb
2010-04-01 21:27 . 2010-04-01 21:27 ——– d—–w- c:\program files\Windows Installer Clean Up
2010-03-31 13:31 . 2009-05-18 11:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-03-31 13:31 . 2008-04-17 10:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-03-31 13:30 . 2010-03-31 13:30 ——– d—–w- c:\program files\iPod
2010-03-31 13:30 . 2010-03-31 13:31 ——– d—–w- c:\program files\iTunes
2010-03-31 13:30 . 2010-03-31 13:31 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-03-31 13:29 . 2010-03-31 13:29 ——– d—–w- c:\program files\QuickTime
2010-03-31 13:29 . 2010-04-15 02:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-03-31 13:27 . 2010-03-31 13:27 ——– d—–w- c:\program files\Apple Software Update
2010-03-31 13:27 . 2009-10-16 00:33 41472 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-03-31 13:27 . 2009-10-16 00:33 3003680 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-03-31 13:27 . 2010-03-31 13:27 ——– d—–w- c:\program files\Bonjour
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-22 15:59 . 2005-04-05 17:21 ——– d—–w- c:\program files\C4ebreg
2010-04-22 15:56 . 2007-03-05 22:09 40 —-a-w- c:\windows\system32\profile.dat
2010-04-22 13:00 . 2010-02-19 00:23 ——– d—–w- c:\documents and settings\Administrator\Application Data\vlc
2010-04-22 11:40 . 2006-01-24 00:45 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-04-22 11:14 . 2009-06-26 00:54 ——– d—–w- c:\program files\AT&T Network Client
2010-04-21 11:34 . 2009-08-22 15:57 ——– d—–w- c:\documents and settings\Administrator\Application Data\dvdcss
2010-04-19 19:03 . 2009-12-27 15:32 ——– d—–w- c:\documents and settings\Administrator\Application Data\Giqay
2010-04-19 12:30 . 2006-03-27 21:50 ——– d—–w- c:\program files\WST
2010-04-19 05:07 . 2009-02-11 21:17 23552 —-a-w- c:\windows\system32\drivers\abp480n5.sys
2010-04-18 23:10 . 2009-06-30 15:07 ——– d—–w- c:\program files\Foxit Reader
2010-04-17 14:44 . 2006-04-12 02:08 ——– d—–w- c:\program files\Common Files\Adobe
2010-04-16 10:26 . 2005-04-04 18:17 47168 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-15 21:04 . 2009-08-14 17:22 ——– d—–w- c:\program files\HandBrake
2010-04-15 17:30 . 2009-07-24 21:16 ——– d—–w- c:\program files\Google
2010-04-13 00:19 . 2009-11-22 19:11 ——– d—–w- c:\program files\Flickr Uploadr
2010-04-12 22:46 . 2009-10-16 20:37 ——– d—–w- c:\documents and settings\Administrator\Application Data\foobar2000
2010-04-12 17:37 . 2009-10-31 19:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-11 18:57 . 2010-01-30 12:28 ——– d—–w- c:\documents and settings\Administrator\Application Data\Apple Computer
2010-04-07 08:41 . 2009-08-14 17:43 ——– d—–w- c:\program files\T-Mobile Internet Manager
2010-04-07 06:42 . 2010-04-06 19:51 319000 —-a-w- c:\windows\system32\drivers\tsk29.tmp
2010-04-06 21:16 . 2009-10-31 20:35 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-06 21:16 . 2009-10-31 20:54 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-04-06 21:13 . 2009-10-31 19:49 ——– d—–w- c:\program files\Lavasoft
2010-04-05 18:50 . 2009-06-26 20:01 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-04-01 21:27 . 2007-10-10 15:20 ——– d—–w- c:\program files\MSECache
2010-03-31 13:30 . 2010-01-17 03:54 ——– d—–w- c:\program files\Common Files\Apple
2010-02-26 16:34 . 2009-10-07 10:07 6400 —-a-w- c:\windows\system32\drivers\isamfilter.sys
2010-02-26 13:11 . 2010-02-26 13:11 ——– d—–w- c:\documents and settings\Administrator\Application Data\Facebook
2010-02-25 18:11 . 2005-07-29 18:05 64792 —-a-w- c:\windows\isamunin.exe
2010-02-12 09:46 . 2010-02-12 09:46 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 09:46 . 2010-02-12 09:46 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-02-04 15:53 . 2009-10-31 20:35 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
.
((((((((((((((((((((((((((((( SnapShot_2010-04-19_11.20.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-22 15:59 . 2010-04-22 15:59 16384 c:\windows\Temp\Perflib_Perfdata_b0c.dat
+ 2004-08-04 05:00 . 2004-08-04 05:00 37888 c:\windows\system32\url.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 39424 c:\windows\system32\pngfilt.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 96256 c:\windows\system32\occache.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 56832 c:\windows\system32\mshtmler.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 29184 c:\windows\system32\mshta.exe
+ 2004-08-04 05:00 . 2004-08-04 05:00 22016 c:\windows\system32\licmgr10.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 16384 c:\windows\system32\jsproxy.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 96256 c:\windows\system32\inseng.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 35840 c:\windows\system32\imgutil.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 62976 c:\windows\system32\iesetup.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 48640 c:\windows\system32\iernonce.dll
+ 2009-06-29 15:09 . 2009-04-29 04:52 81920 c:\windows\system32\ieencode.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 34304 c:\windows\system32\ie4uinit.exe
+ 2004-08-04 05:00 . 2004-08-04 05:00 37888 c:\windows\system32\dllcache\url.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 39424 c:\windows\system32\dllcache\pngfilt.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 96256 c:\windows\system32\dllcache\occache.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 56832 c:\windows\system32\dllcache\mshtmler.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 29184 c:\windows\system32\dllcache\mshta.exe
+ 2004-08-04 05:00 . 2004-08-04 05:00 22016 c:\windows\system32\dllcache\licmgr10.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 16384 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 96256 c:\windows\system32\dllcache\inseng.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 35840 c:\windows\system32\dllcache\imgutil.dll
+ 2005-04-04 17:41 . 2004-08-04 05:00 93184 c:\windows\system32\dllcache\iexplore.exe
+ 2004-08-04 05:00 . 2004-08-04 05:00 62976 c:\windows\system32\dllcache\iesetup.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 48640 c:\windows\system32\dllcache\iernonce.dll
+ 2009-06-29 15:09 . 2009-04-29 04:52 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 34304 c:\windows\system32\dllcache\ie4uinit.exe
+ 2005-04-04 17:41 . 2004-08-04 05:00 38912 c:\windows\system32\dllcache\hmmapi.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 35328 c:\windows\system32\dllcache\corpol.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 99840 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 61440 c:\windows\system32\dllcache\admparse.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 35328 c:\windows\system32\corpol.dll
+ 2005-04-04 17:46 . 2010-04-22 15:51 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-04-04 17:46 . 2010-04-19 11:10 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-04-11 21:09 . 2010-04-19 11:10 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-04-19 11:30 . 2010-04-22 15:51 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2004-08-04 05:00 . 2004-08-04 05:00 99840 c:\windows\system32\advpack.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 61440 c:\windows\system32\admparse.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 659456 c:\windows\system32\wininet.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 276480 c:\windows\system32\webcheck.dll
+ 2004-08-04 05:00 . 2007-12-18 14:40 417792 c:\windows\system32\vbscript.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 616448 c:\windows\system32\urlmon.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 532480 c:\windows\system32\mstime.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 146432 c:\windows\system32\msrating.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 146432 c:\windows\system32\msls31.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 449024 c:\windows\system32\mshtmled.dll
+ 2004-08-04 05:00 . 2007-12-18 14:40 450560 c:\windows\system32\jscript.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 251392 c:\windows\system32\iepeers.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 323584 c:\windows\system32\iedkcs32.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 221184 c:\windows\system32\ieakui.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 216576 c:\windows\system32\ieaksie.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 139264 c:\windows\system32\ieakeng.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 205312 c:\windows\system32\dxtrans.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 357888 c:\windows\system32\dxtmsft.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 659456 c:\windows\system32\dllcache\wininet.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 276480 c:\windows\system32\dllcache\webcheck.dll
+ 2005-04-04 17:42 . 2007-06-26 15:13 851968 c:\windows\system32\dllcache\vgx.dll
+ 2004-08-04 05:00 . 2007-12-18 14:40 417792 c:\windows\system32\dllcache\vbscript.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 616448 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 532480 c:\windows\system32\dllcache\mstime.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 146432 c:\windows\system32\dllcache\msrating.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 146432 c:\windows\system32\dllcache\msls31.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 449024 c:\windows\system32\dllcache\mshtmled.dll
+ 2004-08-04 05:00 . 2007-12-18 14:40 450560 c:\windows\system32\dllcache\jscript.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 251392 c:\windows\system32\dllcache\iepeers.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 323584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 221184 c:\windows\system32\dllcache\ieakui.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 216576 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-04 05:00 . 2004-08-04 05:00 139264 c:\windows\system32\dllcache\ieakeng.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 205312 c:\windows\system32\dllcache\dxtrans.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 357888 c:\windows\system32\dllcache\dxtmsft.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 3060736 c:\windows\system32\mshtml.dll
+ 2004-08-04 05:00 . 2009-04-29 04:52 3060736 c:\windows\system32\dllcache\mshtml.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetSP - restore settings on power failure"="c:\program files\AT&T Network Client\NetSP.exe" [2007-01-13 24576]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-05-21 1134592]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-07-16 307768]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-03 135664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pmonmh"="c:\program files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.4.19" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"stgclean"="c:\sdwork\w32maing.exe" [2010-04-07 267776]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~2\SYMANT~2\VPTray.exe" [2006-09-27 125168]
"Tpam.exe"="c:\program files\IBM\Personal Communications\tpam.exe" [2007-11-02 28672]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-06-26 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-06-26 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-06-26 141848]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592]
"TpShocks"="TpShocks.exe" [2008-06-06 181536]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2009-06-26 331776]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2009-06-26 208896]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-26 820520]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-06-26 60192]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-03-24 68464]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-08-15 143360]
"ipmcmu"="c:\program files\IBM\IPM Client Migration Utility\ipmcmu.exe" [2009-06-29 204800]
"ISSI Service"="c:\sdwork\issimsvc.exe" [2010-02-11 241392]
"C4EBReg"="c:\program files\c4ebreg\c4ebreg.exe" [2010-02-25 482584]
"Isamtray"="c:\program files\c4ebreg\isamtray.exe" [2010-02-25 285976]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-29 148888]
"UIExec"="c:\program files\T-Mobile Internet Manager\UIExec.exe" [2009-06-12 132608]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-25 142120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Check for TWS Updates.lnk - c:\jts\WiseUpdt.exe [2010-2-24 194775]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2009-10-02 128360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pcsinst]
2007-11-02 10:45 49152 —-a-w- c:\windows\system32\pcsinst.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 16:37 34344 —-a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2008-03-17 16:02 34080 —-a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\assistant2]
2006-10-20 09:01 2107392 —-a-w- c:\program files\VoiceRite\Client\Viewer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 16:44 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"IBMconfig"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AT&T Network Client\\NetClient.exe"=
"c:\\Program Files\\IBM\\Lotus\\Sametime Connect\\rcp\\eclipse\\plugins\\com.ibm.rcp.jcl.desktop.win32.x86_6.2.0.200810071032\\jre\\bin\\sametime80w.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [31/10/2009 21:35 64288]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [14/05/2008 17:21 19496]
R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [09/10/2009 04:45 169312]
R2 pdlndldl6;IBM Enterprise Extender (HPR/IPv6);c:\windows\system32\drivers\pdlndldl6.sys [02/11/2007 05:09 70656]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [26/06/2009 01:22 243856]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [04/09/2009 20:31 102448]
R3 IsamFilter;IsamFilter;c:\windows\system32\drivers\isamfilter.sys [07/10/2009 11:07 6400]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [24/07/2009 22:16 133104]
S3 csrcmds;csrcmds;c:\program files\IBM\Personal Communications\csrcmds.exe [02/11/2007 05:09 49152]
S3 cstrcser;IBM Command Line Trace;c:\windows\system32\drivers\cstrcser.exe [02/11/2007 05:09 36864]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [14/08/2009 18:43 9728]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [16/10/2009 22:12 721904]
— Other Services/Drivers In Memory —
*Deregistered* - BMLoad
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-04-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 21:15]
2010-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-24 21:16]
2010-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-24 21:16]
2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2869554992-1010074173-1580797646-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-03 08:21]
2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2869554992-1010074173-1580797646-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-03 08:21]
2010-04-22 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2009-06-26 00:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://w3.ibm.com/
uInternet Connection Wizard,ShellNext = hxxp://w3.ibm.com/
uInternet Settings,ProxyServer = proxy.emea.ibm.com:8080
uInternet Settings,ProxyOverride = localhost;127.0.0.1;*.local;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} - hxxp://
DPF: {9519B2A2-6592-4E41-8290-D0298459270C} - hxxp://w3.ibm.com/bluepages/scripts/lnwebassist.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff36\gears.dll
FF - plugin: c:\documents and settings\Administrator\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-22 17:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ipmcmu = c:\program files\IBM\IPM Client Migration Utility\ipmcmu.exe "c:\program files\IBM\IPM Client Migration Utility"?run key ipmcmu was set successfully?run key ipmcmu was not set successfully?Error, Windows run key not found?The service "Task Scheduler" is not ru
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: >>UNKNOWN [0x804D7000]<< >>UNKNOWN [0xF77EF000]<< >>UNKNOWN [0xF76B7000]<< >>UNKNOWN [0xF76A7000]<< >>UNKNOWN [0xF75A8000]<< >>UNKNOWN [0x806FF000]<< >>UNKNOWN [0xF7B0F000]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0xf76bbfc3
\Driver\ACPI -> 0xf75aecb8
\Driver\atapi -> 0xf746a814
\Driver\iaStor -> 0xf7b4b992
IoDeviceObjectType -> DeleteProcedure -> 0x805e4d69
ParseProcedure -> 0x8057950b
\Device\Harddisk0\DR0 -> DeleteProcedure -> 0x805e4d69
ParseProcedure -> 0x8057950b
NDIS: Intel® WiFi Link 5100 AGN -> SendCompleteHandler -> 0xba62dbb0
PacketIndicateHandler -> 0xba61ca0d
SendHandler -> 0xba630b40
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iastor]
"ImagePath"="system32\drivers\tsk29.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-2869554992-1010074173-1580797646-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,6e,02,39,19,25,c4,84,41,8d,4f,c0,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,fe,38,df,56,87,6c,4c,b5,1c,3e,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1052)
c:\program files\Lenovo\HOTKEY\tphklock.dll
c:\windows\system32\pcsinst.dll
.
Completion time: 2010-04-22 17:16:02
ComboFix-quarantined-files.txt 2010-04-22 16:16
ComboFix2.txt 2010-04-19 11:26
ComboFix3.txt 2010-04-07 09:28
Pre-Run: 2,719,248,384 bytes free
Post-Run: 2,677,514,240 bytes free
- - End Of File - - 5673D7875BE4C83874A39B6661F6A48B