This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help Please

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My problem started earlier this week when my computer was not working after I got a virus. I managed to get rid of most of the viruses using Avast Antivirus' boot time scan. However i am still infected with Trojan.DNSChanger. I have googled all around and cannot find any specific instructions on how to remove it so i thought someone here might be able to help. I have tried using Malwarebytes Anti Malware but the virus keeps coming back after I reboot. My HJT log is posted below. I also renamed HijackThis to mike.exe because i read something about viruses being able to detect it.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:26:59, on 12/21/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Boot mode: Safe mode with network support



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\Explorer.EXE

C:\Documents and Settings\100371322\Desktop\mike.exe



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uoit.ca/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll

O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash

O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW

O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe

O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor

O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog

O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r

O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper

O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"

O4 - HKLM\..\Run: [TpShocks] TpShocks.exe

O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray

O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe

O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe

O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE

O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\100371322\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [\\delorean\EPSON Stylus CX9400Fax Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICFA.EXE /FU "C:\DOCUME~1\100371~1\LOCALS~1\Temp\E_S1C4.tmp" /EF "HKCU"

O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit…b?1227373676390

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1207683156375

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1207850411078

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\Software\..\Telephony: DomainName = oncampus.local

O17 - HKLM\System\CCS\Services\Tcpip\..\{C4F038DD-B4A9-4754-93A7-CAD04541065D}: NameServer = 85.255.113.125;85.255.112.92

O17 - HKLM\System\CCS\Services\Tcpip\..\{F2549569-56CB-4FBA-B76A-5723382520C8}: NameServer = 85.255.113.125;85.255.112.92

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.113.125;85.255.112.92

O17 - HKLM\System\CS5\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.125;85.255.112.92

O20 - Winlogon Notify: xxywUOHW - xxywUOHW.dll (file missing)

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Intel® Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: LANDesk® Management Agent (CBA8) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\Shared Files\residentagent.exe

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe

O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure\FSAUA\program\fsaua.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe

O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE

O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe

O23 - Service: Intel Local Scheduler Service - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\LocalSch.EXE

O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe

O23 - Service: LANDesk Targeted Multicast (Intel Targeted Multicast) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\tmcsvc.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE

O23 - Service: LANDesk Remote Control Service (ISSUSER) - LANDesk Software, Ltd. - C:\PROGRA~1\LANDesk\LDClient\issuser.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: LANDesk Policy Invoker - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\policy.client.invoker.exe

O23 - Service: LANDesk® Out-of-Band Monitor Service - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\amtmon.exe

O23 - Service: Intel® Active Management Technology Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe

O23 - Service: MaxiVista_service_D - Unknown owner - C:\Program Files\MaxiVista Demo Viewer\MaxiVistaDemoViewer.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

O23 - Service: LANDesk® Software Monitoring Service (Softmon) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\softmon.exe

O23 - Service: SSIRuntimeService - Unknown owner - C:\Program Files\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe

O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe

O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe

O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe

O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

O23 - Service: TVT Windows Update Monitor (TVT_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe

O23 - Service: Intel® Active Management Technology User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\AMT\UNS.exe

O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe

O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe

O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe

O23 - Service: Web Update Wizard Service V4 (WebUpdate4) - Data Perceptions / PowerProgrammer - C:\WINDOWS\system32\WebUpdateSvc4.exe



–

End of file - 15030 bytes
Hello and Welcome to the forum.

Click: Start > All Programs> Accessories
Open Notepad, click on Format and uncheck Word Wrap.


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
I think that did it. The problem that I was experiencing was that my DNS was being changed in my internet connections to another DNS (Which was located i believe in Russia, and I am in Canada). However, I kept my wireless switch off at all times just to be safe. Any posting or downloading i have done is from my other computer. My Logs are as shown below:

Combofix:

ComboFix 08-12-21.02 - 100371322 2008-12-21 17:18:06.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2030.1317 [GMT -5:00]

Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe

* Resident AV is active





WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.



C:\autorun.inf

c:\windows\system32\404Fix.exe

c:\windows\system32\drivers\msqpdxrvdckfkl.sys

c:\windows\system32\drivers\msqpdxserv.sys

c:\windows\system32\dumphive.exe

c:\windows\system32\IEDFix.C.exe

c:\windows\system32\IEDFix.exe

c:\windows\system32\msqpdxreaturxb.dll

c:\windows\system32\o4Patch.exe

c:\windows\system32\Process.exe

c:\windows\system32\SrchSTS.exe

c:\windows\system32\VACFix.exe

c:\windows\system32\VCCLSID.exe

c:\windows\system32\WS2Fix.exe

c:\windows\Tasks\skiqqgqh.job

D:\Autorun.inf

D:\resycled

d:\resycled\boot.com



.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.



——-\Service_MSQPDXSERV.SYS

——-\Legacy_MSQPDXSERV.SYS

——-\Legacy_icf





((((((((((((((((((((((((( Files Created from 2008-11-21 to 2008-12-21 )))))))))))))))))))))))))))))))

.



2008-12-21 13:26 . 2008-12-21 13:26 d——– c:\program files\Trend Micro

2008-12-21 13:06 . 2008-12-21 13:24 d——– C:\fixwareout

2008-12-21 13:04 . 2008-12-21 13:04 d——– C:\VundoFix Backups

2008-12-20 14:42 . 2008-12-20 14:42 236 –a—— C:\sqmdata19.sqm

2008-12-20 14:42 . 2008-12-20 14:42 200 –a—— C:\sqmnoopt19.sqm

2008-12-20 14:39 . 2008-12-20 14:39 d——– c:\documents and settings\100371322\Application Data\Malwarebytes

2008-12-20 14:28 . 2008-12-20 14:28 d——– c:\program files\Malwarebytes' Anti-Malware

2008-12-20 14:28 . 2008-12-20 14:28 d——– c:\documents and settings\Mobile\Application Data\Malwarebytes

2008-12-20 14:28 . 2008-12-20 14:28 d——– c:\documents and settings\All Users\Application Data\Malwarebytes

2008-12-20 14:28 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys

2008-12-20 14:28 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys

2008-12-20 14:22 . 2008-12-20 14:22 236 –a—— C:\sqmdata18.sqm

2008-12-20 14:22 . 2008-12-20 14:22 200 –a—— C:\sqmnoopt18.sqm

2008-12-20 14:20 . 2008-12-12 00:57 78,336 –a—— c:\windows\system32\Agent.OMZ.Fix.exe

2008-12-19 22:37 . 2008-12-19 22:37 236 –a—— C:\sqmdata17.sqm

2008-12-19 22:37 . 2008-12-19 22:37 200 –a—— C:\sqmnoopt17.sqm

2008-12-19 19:45 . 2008-12-19 19:45 236 –a—— C:\sqmdata16.sqm

2008-12-19 19:45 . 2008-12-19 19:45 200 –a—— C:\sqmnoopt16.sqm

2008-12-19 19:24 . 2007-06-13 08:26 1,033,216 –a—— c:\windows\explorer.exe

2008-12-19 19:24 . 2004-08-03 19:56 14,336 –a—— c:\windows\system32\svchost.exe

2008-12-19 12:58 . 2008-12-19 12:58 236 –a—— C:\sqmdata15.sqm

2008-12-19 12:58 . 2008-12-19 12:58 200 –a—— C:\sqmnoopt15.sqm

2008-12-18 22:58 . 2008-12-18 22:58 d——– c:\program files\Alwil Software

2008-12-18 22:26 . 2008-12-18 22:26 236 –a—— C:\sqmdata14.sqm

2008-12-18 22:26 . 2008-12-18 22:26 200 –a—— C:\sqmnoopt14.sqm

2008-12-18 21:32 . 2008-12-18 21:32 236 –a—— C:\sqmdata13.sqm

2008-12-18 21:32 . 2008-12-18 21:32 200 –a—— C:\sqmnoopt13.sqm

2008-12-18 00:15 . 2008-12-18 00:15 d——– c:\documents and settings\Mobile\Application Data\DivX

2008-12-16 22:52 . 2008-12-16 22:52 103,936 –a—— c:\windows\system32\tysphj.0ll

2008-12-16 22:52 . 2008-12-16 22:52 103,936 –a—— c:\windows\system32\adijnndx.0ll

2008-12-16 22:08 . 2008-12-16 22:08 135,168 –a—— C:\pyfypodg.0xe

2008-12-16 22:08 . 2008-12-16 22:08 119,296 –a—— C:\bufy.0xe

2008-12-16 22:08 . 2008-12-16 22:08 93,420 –a—— c:\windows\system32\drivers\809d8e6b.0ys

2008-12-16 22:08 . 2008-12-16 22:08 2 –a—— C:\-131037151

2008-12-16 22:06 . 2008-12-16 22:06 70,144 –a—— c:\windows\system32\ljJBurro.0ll

2008-12-16 22:06 . 2008-12-16 22:06 36,864 –a—— c:\windows\system32\xxywUOHW.dll.bak

2008-12-16 22:06 . 2005-05-09 20:08 33,792 –a—— c:\windows\system32\drivers\cledx.sys

2008-12-16 22:06 . 2002-11-25 05:46 16,896 –a—— c:\windows\system32\drivers\synasUSB.sys

2008-12-16 22:04 . 2007-12-04 13:38 550,912 –a—— c:\windows\system32\OLEAUT32.DLL

2008-12-16 22:04 . 2004-08-04 06:00 83,456 –a—— c:\windows\system32\OLEPRO32.DLL

2008-12-16 22:04 . 2008-12-16 22:05 83,375 –a—— c:\program files\Common Files\insta.exe

2008-12-16 22:04 . 2004-08-04 06:00 65,024 –a—— c:\windows\system32\ASYCFILT.DLL

2008-12-16 22:04 . 2004-08-04 06:00 17,920 –a—— c:\windows\system32\STDOLE2.TLB

2008-12-16 22:04 . 2004-08-04 06:00 3,584 –a—— c:\windows\system32\COMCAT.DLL

2008-12-16 18:23 . 2006-11-29 13:06 3,426,072 –a—— c:\windows\system32\d3dx9_32.dll

2008-12-16 17:20 . 2008-12-18 20:08 d——– c:\program files\VstPlugins

2008-12-16 17:20 . 2008-12-16 17:20 d——– c:\program files\Outsim

2008-12-16 17:20 . 2002-07-07 17:14 1,294,336 –a—— c:\windows\system32\vorbis.acm

2008-12-16 17:20 . 2006-06-20 03:56 225,280 –a—— c:\windows\system32\rewire.dll

2008-12-16 17:18 . 2008-12-18 20:09 d——– c:\program files\Image-Line

2008-12-16 17:14 . 2008-12-16 17:14 0 –ah—– c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf

2008-12-16 17:14 . 2008-12-16 17:14 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_xusb20_01001.Wdf

2008-12-16 17:13 . 2008-12-18 20:09 d——– c:\program files\Drum Machine

2008-12-16 17:13 . 2006-10-04 18:46 1,418,720 –a—— c:\windows\system32\WdfCoInstaller01001.dll

2008-12-16 17:13 . 2007-04-04 17:53 81,768 –a—— c:\windows\system32\xinput1_3.dll

2008-12-16 17:13 . 2006-10-13 14:48 50,048 –a—— c:\windows\system32\drivers\xusb20.sys

2008-12-15 15:19 . 2008-12-15 15:19 236 –a—— C:\sqmdata12.sqm

2008-12-15 15:19 . 2008-12-15 15:19 200 –a—— C:\sqmnoopt12.sqm

2008-12-15 14:16 . 2008-12-15 14:16 1,409 –a—— c:\windows\QTFont.for

2008-12-11 19:46 . 2008-12-21 17:30 54,156 –ah—– c:\windows\QTFont.qfn

2008-12-10 16:50 . 2008-12-10 16:50 d——– c:\program files\Winamp Toolbar

2008-12-10 16:50 . 2008-12-10 16:51 d——– c:\program files\Winamp

2008-12-10 16:50 . 2008-12-10 16:50 d——– c:\documents and settings\All Users\Application Data\Winamp Toolbar

2008-12-10 16:50 . 2008-12-10 16:51 d——– c:\documents and settings\100371322\Application Data\Winamp

2008-12-09 16:29 . 2008-12-09 16:30 d——– c:\program files\iPhone Configuration Utility

2008-12-09 16:21 . 2008-12-09 16:33 d——– c:\windows\SxsCaPendDel

2008-12-07 18:08 . 2008-12-07 18:46 31 –a—— c:\documents and settings\100371322\jagex_runescape_preferences.dat

2008-12-06 17:44 . 2008-12-18 20:08 d——– c:\program files\Big Rigs Racing

2008-12-02 20:31 . 2008-12-02 20:31 d——– C:\ICO

2008-12-02 20:27 . 2008-09-21 20:09 47,815 –a—— C:\nes.png

2008-12-02 20:27 . 2008-09-21 20:09 17,359 –a—— C:\controller.png

2008-12-01 09:39 . 2008-12-01 09:51 d——– c:\program files\Spybot - Search & Destroy

2008-12-01 09:39 . 2008-12-01 09:51 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2008-12-01 09:20 . 2008-12-16 22:08 d——– c:\documents and settings\100371322\Application Data\FrostWire

2008-12-01 09:06 . 2008-12-01 09:06 d——– C:\Batch

2008-12-01 09:03 . 2008-12-01 09:03 d——– C:\NirCMD

2008-12-01 08:58 . 2008-12-01 09:20 d——– c:\program files\FrostWire

2008-12-01 08:31 . 2008-12-01 08:32 d——– c:\program files\ApexDC++

2008-11-25 23:00 . 2008-11-30 19:48 d——– c:\documents and settings\100371322\Application Data\Thinstall

2008-11-21 16:20 . 2008-11-21 16:20 d——– c:\program files\SC



.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-21 22:30 ——— d—–w c:\program files\Steam

2008-12-21 18:48 ——— d—–w c:\documents and settings\All Users\Application Data\vulScan

2008-12-17 03:08 ——— d—–w c:\documents and settings\100371322\Application Data\Azureus

2008-12-15 20:14 ——— d—–w c:\program files\Common Files\Research In Motion

2008-12-15 20:02 ——— d—–w c:\documents and settings\100371322\Application Data\Research In Motion

2008-12-12 04:04 ——— d—–w c:\documents and settings\100371322\Application Data\FileZilla

2008-12-09 21:40 ——— d—–w c:\documents and settings\All Users\Application Data\VMware

2008-12-09 21:36 ——— d—–w c:\documents and settings\NetworkService\Application Data\VMware

2008-12-05 12:49 ——— d—–w c:\program files\Vuze

2008-12-01 15:21 ——— d—–w c:\documents and settings\All Users\Application Data\SoftwareSecure

2008-12-01 15:01 ——— d—–w c:\program files\Project64 1.6

2008-12-01 15:00 ——— d—–w c:\program files\YuGiOh Virtual Desktop

2008-12-01 15:00 ——— d—–w c:\program files\PTDD Group

2008-12-01 13:51 ——— d—–w c:\documents and settings\100371322\Application Data\LimeWire

2008-12-01 13:28 ——— d—–w c:\program files\DC++

2008-11-28 00:11 ——— d—–w c:\program files\Minefield

2008-11-21 02:11 ——— d–h–w c:\program files\InstallShield Installation Information

2008-11-21 02:11 ——— d—–w c:\program files\Logitech

2008-11-21 02:11 ——— d—–w c:\program files\Common Files\Remote Control Software Common

2008-11-21 02:10 ——— d—–w c:\program files\Common Files\Remote Control USB Driver

2008-11-17 15:24 ——— d—–w c:\documents and settings\100371322\Application Data\vlc

2008-11-07 22:35 ——— d—–w c:\documents and settings\100371322\Application Data\Sibelius Software

2008-11-07 22:34 ——— d—–w c:\program files\Musicnotes

2008-11-03 22:54 ——— d—–w c:\documents and settings\100371322\Application Data\VMware

2008-11-01 19:22 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help

2008-11-01 18:41 ——— d—–w c:\documents and settings\100371322\Application Data\GrabIt

2008-10-30 19:19 ——— d—–w c:\documents and settings\100371322\Application Data\Red Alert 3

2008-10-29 23:51 ——— d—–w c:\program files\JFK Reloaded

2008-10-27 15:04 70,992 —-a-w c:\windows\system32\XAPOFX1_2.dll

2008-10-27 15:04 514,384 —-a-w c:\windows\system32\XAudio2_3.dll

2008-10-27 15:04 235,856 —-a-w c:\windows\system32\xactengine3_3.dll

2008-10-27 15:04 23,376 —-a-w c:\windows\system32\X3DAudio1_5.dll

2008-10-23 18:43 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft

2008-10-23 18:41 ——— d—–w c:\program files\Lavasoft

2008-10-23 18:41 ——— d—–w c:\program files\Common Files\Wise Installation Wizard

2008-10-23 18:33 ——— d—–w c:\program files\Windows Live

2008-10-23 18:31 ——— d—–w c:\program files\Microsoft

2008-10-23 18:27 ——— d—–w c:\program files\Common Files\Windows Live

2008-10-22 00:08 ——— d—–w c:\program files\Duke Nukem 3D

2008-10-20 13:46 50,546 —-a-w c:\windows\system32\wuwuninst.exe

2008-10-10 09:52 452,440 —-a-w c:\windows\system32\d3dx10_40.dll

2008-10-10 09:52 4,379,984 —-a-w c:\windows\system32\D3DX9_40.dll

2008-10-10 09:52 2,036,576 —-a-w c:\windows\system32\D3DCompiler_40.dll

2008-10-08 00:05 64,971 —-a-w c:\windows\BricoPackUninst.cmd

2008-10-08 00:05 6,120 —-a-w c:\windows\BricoPackFoldersDelete.cmd

2008-10-01 00:58 410,976 —-a-w c:\windows\system32\deploytk.dll

.



——- Sigcheck ——-



2007-10-30 11:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys

2004-08-04 06:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB941644$\tcpip.sys

2008-09-07 13:41 360064 8283a4d489b207991efdc8328733d0bc c:\windows\system32\dllcache\TCPIP.SYS

2008-09-07 13:41 360064 8283a4d489b207991efdc8328733d0bc c:\windows\system32\drivers\TCPIP.SYS

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4



[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2008-09-08 3513344]

"Google Update"="c:\documents and settings\100371322\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-04 133104]

"Steam"="c:\program files\Steam\Steam.exe" [2008-10-07 1410296]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]

"\\delorean\EPSON Stylus CX9400Fax Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICFA.EXE" [2007-03-23 182272]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"F-Secure Manager"="c:\program files\F-Secure\Common\FSM32.EXE" [2006-12-05 176177]

"F-Secure TNB"="c:\program files\F-Secure\FSGUI\TNBUtil.exe" [2007-01-08 724992]

"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2007-12-05 122880]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-05 524288]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-10 8495104]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-10 81920]

"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-01-24 66928]

"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-04-27 243248]

"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2008-01-11 294912]

"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2008-01-11 208896]

"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-12-20 60704]

"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352]

"atchk"="c:\program files\Intel\AMT\atchk.exe" [2007-09-07 408088]

"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-12-11 1044480]

"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2008-01-11 144728]

"LPMailChecker"="c:\progra~1\THINKV~2\PrdCtr\LPMLCHK.exe" [2008-01-11 124248]

"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2007-12-05 487424]

"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-07-29 185896]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-09-30 144792]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-09-12 36352]

"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696]

"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

"VMware hqtray"="c:\program files\VMware\VMware Player\hqtray.exe" [2008-03-03 55856]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-19 267048]

"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]

"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]

"nwiz"="nwiz.exe" [2007-12-10 c:\windows\system32\nwiz.exe]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]

"TpShocks"="TpShocks.exe" [2007-11-22 c:\windows\system32\TpShocks.exe]



c:\documents and settings\All Users\Start Menu\Programs\Startup\

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-04-09 50688]



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"AllowMultipleTSSessions"= 1 (0x1)

"SynchronousMachineGroupPolicy"= 0 (0x0)

"SynchronousUserGroupPolicy"= 0 (0x0)



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoWelcomeScreen"= 1 (0x1)



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"ForceStartMenuLogOff"= 1 (0x1)

"NoWelcomeScreen"= 1 (0x1)

"NoAutoUpdate"= 0 (0x0)

"NoStartMenuNetworkPlaces"= 1 (0x1)

"NoSecurityTab"= 1 (0x1)



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]

2007-08-14 14:54 89600 c:\windows\system32\psqlpwd.dll



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]

2006-09-06 15:37 34344 c:\program files\Lenovo\HOTKEY\notifyf2.dll



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]

2007-12-14 15:36 28672 c:\program files\Lenovo\HOTKEY\tphklock.dll



[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Notification Packages REG_MULTI_SZ scecli psqlpwd



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1644491937-682003330-725345543-231014\Scripts\Logon\0\0]

"Script"=\\oncampus.local\SysVol\oncampus.local\scripts\javaupdate\javaupd.bat



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1644491937-682003330-725345543-231014\Scripts\Logon\1\0]

"Script"=\\oncampus.local\NETLOGON\AcademicIntegrity\stu\icon.bat



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1644491937-682003330-725345543-231014\Scripts\Logon\2\0]

"Script"=\\oncampus.local\NETLOGON\IE6SiteAddition.bat



[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"Bonjour Service"=2 (0x2)



[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)



[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=

"c:\\Program Files\\FrostWire\\FrostWire.exe"=

"c:\\Program Files\\LANDesk\\Shared Files\\residentagent.exe"=



R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2008-04-08 50240]

R0 Shockprf;Shockprf;c:\windows\system32\DRIVERS\Apsx86.sys [2007-10-16 103472]

R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\DRIVERS\ApsHM86.sys [2007-10-16 19504]

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-18 111184]

R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\Tppwrif.sys [2008-04-09 4442]

R1 tvtumon;tvtumon;c:\windows\system32\DRIVERS\tvtumon.sys [2007-12-05 46656]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-18 20560]

R2 CBA8;LANDesk® Management Agent;"c:\program files\LANDesk\Shared Files\residentagent.exe" [2008-06-02 155648]

R2 LANDesk Policy Invoker;LANDesk Policy Invoker;"c:\program files\LANDesk\LDClient\policy.client.invoker.exe" [2008-09-04 118784]

R2 LANDesk® Out-of-Band Monitor Service;LANDesk® Out-of-Band Monitor Service;c:\program files\LANDesk\LDClient\amtmon.exe [2008-09-04 987136]

R2 smihlp;SMI Helper Driver (smihlp);\??\c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-08-14 10896]

R2 Softmon;LANDesk® Software Monitoring Service;"c:\program files\LANDesk\LDClient\softmon.exe" [2008-09-04 331776]

R2 SSIRuntimeService;SSIRuntimeService;"c:\program files\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe" [2007-09-11 45056]

R2 TVT Backup Protection Service;TVT Backup Protection Service;"c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe" [2007-12-05 520192]

R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2007-12-05 249856]

R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Intel\AMT\UNS.exe [2008-04-09 1464856]

R2 WebUpdate4;Web Update Wizard Service V4;c:\windows\system32\WebUpdateSvc4.exe [2007-05-18 229856]

R3 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\c:\program files\F-Secure\Anti-Virus\minifilter\fsgk.sys [2008-04-08 51712]

R3 ldblank;Screen Blanking driver for Remote Control;c:\windows\system32\DRIVERS\ldblank.sys [2008-09-04 11904]

R3 ldmirror;ldmirror;c:\windows\system32\DRIVERS\ldmirror.sys [2008-09-04 3328]

R3 mirrorflt;Mirror Filter Driver for Uninstall;c:\windows\system32\DRIVERS\mirrorflt.sys [2008-09-04 3712]

R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2007-05-22 30336]

S2 MaxiVista_service_D;MaxiVista_service_D;"c:\program files\MaxiVista Demo Viewer\MaxiVistaDemoViewer.exe" -service []

S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\DRIVERS\xusb20.sys [2008-12-16 50048]

S4 F-Secure Filter;F-Secure File System Filter;\??\c:\program files\F-Secure\Anti-Virus\Win2K\FSfilter.sys [2008-04-08 33024]

S4 F-Secure Recognizer;F-Secure File System Recognizer;\??\c:\program files\F-Secure\Anti-Virus\Win2K\FSrec.sys [2008-04-08 18432]

S4 msvsmon80;Visual Studio 2005 Remote Debugger;"c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 [2006-12-02 2805000]



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com c:

\Shell\Open\command - resycled\boot.com c:



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com d:

\Shell\Open\command - d:\resycled\boot.com d:



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a9d78a89-8cae-11dd-8d68-005056c00008}]

\Shell\AutoRun\command - H:\LaunchU3.exe -a

.

Contents of the 'Scheduled Tasks' folder



2008-12-21 c:\windows\Tasks\GoogleUpdateTaskUser.job

- c:\documents and settings\100371322\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 14:37]



2008-12-21 c:\windows\Tasks\PMTask.job

- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-01-11 00:30]

.

- - - - ORPHANS REMOVED - - - -



HKLM-Run-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe

HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

Notify-xxywUOHW - xxywUOHW.dll





.

——- Supplementary Scan ——-

.

uStart Page = hxxp://uoit.ca/

uInternet Settings,ProxyOverride = *.local

IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\100371322\Application Data\Mozilla\Firefox\Profiles\hzklqdrv.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - component: c:\documents and settings\100371322\Application Data\Mozilla\Firefox\Profiles\hzklqdrv.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np32asw.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np32dsw.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npnul32.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\NPOFF12.DLL

FF - plugin: c:\program files\Mozilla Firefox\plugins\nppl3260.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin4.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin5.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin6.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\nprjplug.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\nprpjplug.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npsibelius.dll

FF - plugin: c:\program files\Opera\program\plugins\npsibelius.dll



ATTENTION: FIREFOX POLICES IS IN FORCE

c:\program files\Minefield\greprefs\all.js - pref("browser.display.focus_ring_style", 1);

c:\program files\Minefield\greprefs\all.js - pref("gfx.color_management.mode", 2);

c:\program files\Minefield\greprefs\all.js - pref("gfx.color_management.rendering_intent", 0);

c:\program files\Minefield\greprefs\all.js - pref("gfx.downloadable_fonts.enabled", true);

c:\program files\Minefield\greprefs\all.js - pref("gfx.downloadable_fonts.enforce_same_site_origin", true);

c:\program files\Minefield\greprefs\all.js - pref("view_source.editor.args", "");

c:\program files\Minefield\greprefs\all.js - pref("javascript.options.jit.content", false);

c:\program files\Minefield\greprefs\all.js - pref("javascript.options.jit.chrome", false);

c:\program files\Minefield\greprefs\all.js - pref("layout.css.visited_links_enabled", true);

c:\program files\Minefield\greprefs\all.js - pref("ui.panel.default_level_parent", false);

c:\program files\Minefield\greprefs\all.js - pref("image.cache.size", 5242880);

c:\program files\Minefield\greprefs\all.js - pref("image.cache.timeweight", 500);

c:\program files\Minefield\defaults\pref\channel-prefs.js - pref("app.update.channel", "nightly");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("startup.homepage_override_url","http://www.mozilla.org/projects/%APP%/%VERSION%/whatsnew/");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("startup.homepage_welcome_url","http://www.mozilla.org/projects/%APP%/%VERSION%/firstrun/");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.mozilla.org/products/%APP%/");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("app.update.url.details", "http://www.mozilla.org/projects/%APP%/");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("app.releaseNotesURL", "http://www.mozilla.org/projects/%APP%/%VERSION%/releasenotes/");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-f-CN", "");

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.urlbar.restrict.history", "^");

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.urlbar.restrict.tag", "+");

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.urlbar.match.title", "#");

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.urlbar.match.url", "@");

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.search.cache.enabled", true);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.tabs.autoHide", false);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.tabs.closeWindowWithLastTab", true);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.ctrlTab.mostRecentlyUsed", true);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.ctrlTab.recentlyUsedLimit", 7);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.ctrlTab.smoothScroll", true);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.sessionstore.max_resumed_crashes", 1);

.



**************************************************************************



catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-21 17:28:06

Windows 5.1.2600 Service Pack 2 NTFS



scanning hidden processes …



scanning hidden autostart entries …



scanning hidden files …



scan completed successfully

hidden files: 0



**************************************************************************

.

——————— DLLs Loaded Under Running Processes ———————



- - - - - - - > 'winlogon.exe'(888)

c:\windows\system32\vrlogon.dll

c:\windows\system32\psqlpwd.dll

c:\program files\ThinkVantage Fingerprint Software\homefus2.dll

c:\program files\ThinkVantage Fingerprint Software\infra.dll

c:\program files\ThinkVantage Fingerprint Software\homepass.dll

c:\program files\ThinkVantage Fingerprint Software\bio.dll

c:\program files\ThinkVantage Fingerprint Software\ps2css.dll

c:\program files\ThinkVantage Fingerprint Software\crypto.dll

c:\program files\ThinkVantage Fingerprint Software\pscssint.dll

c:\program files\ThinkVantage Fingerprint Software\remote.dll

c:\program files\Lenovo\HOTKEY\tphklock.dll

c:\windows\system32\netprovcredman.dll



- - - - - - - > 'lsass.exe'(944)

c:\windows\system32\psqlpwd.dll

c:\program files\ThinkVantage Fingerprint Software\homefus2.dll

c:\program files\ThinkVantage Fingerprint Software\infra.dll



- - - - - - - > 'explorer.exe'(4176)

c:\windows\system32\nview.dll

c:\progra~1\WINDOW~2\wmpband.dll

.

———————— Other Running Processes ————————

.

c:\windows\system32\ibmpmsvc.exe

c:\program files\Intel\Wireless\Bin\S24EvMon.exe

c:\program files\Lavasoft\Ad-Aware\aawservice.exe

c:\program files\Alwil Software\Avast4\aswUpdSv.exe

c:\program files\Alwil Software\Avast4\ashServ.exe

c:\windows\system32\IPSSVC.EXE

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Intel\AMT\atchksrv.exe

c:\program files\Intel\Wireless\Bin\EvtEng.exe

c:\program files\F-Secure\Anti-Virus\fsgk32st.exe

c:\program files\F-Secure\common\FSMA32.EXE

c:\program files\F-Secure\Anti-Virus\fsgk32.exe

c:\program files\LANDesk\LDClient\LocalSch.EXE

c:\program files\F-Secure\common\FSMB32.EXE

c:\windows\system32\cba\pds.exe

c:\program files\LANDesk\LDClient\tmcsvc.exe

c:\progra~1\LANDesk\LDClient\issuser.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\F-Secure\common\FCH32.EXE

c:\program files\Intel\AMT\LMS.exe

c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

c:\windows\system32\nvsvc32.exe

c:\program files\Intel\Wireless\Bin\RegSrvc.exe

c:\progra~1\LANDesk\LDClient\collector.exe

c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe

c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

c:\windows\system32\TPHDEXLG.exe

c:\windows\system32\TpKmpSvc.exe

c:\program files\Lenovo\Rescue and Recovery\rrservice.exe

c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe

c:\program files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe

c:\program files\Common Files\Lenovo\Logger\logmon.exe

c:\program files\F-Secure\common\FAMEH32.EXE

c:\program files\F-Secure\Anti-Virus\fsqh.exe

c:\program files\Alwil Software\Avast4\ashMaiSv.exe

c:\progra~1\LANDesk\LDClient\rcgui.exe

c:\program files\Alwil Software\Avast4\ashWebSv.exe

c:\windows\system32\msiexec.exe

c:\program files\F-Secure\Anti-Virus\fssm32.exe

c:\program files\F-Secure\FSAUA\program\fsaua.exe

c:\program files\F-Secure\common\FNRB32.exe

c:\program files\F-Secure\FWES\program\fsdfwd.exe

c:\program files\F-Secure\common\FIH32.exe

c:\program files\F-Secure\Anti-Virus\fsav32.exe

c:\windows\system32\rundll32.exe

c:\windows\system32\rundll32.exe

c:\windows\system32\rundll32.exe

c:\program files\Lenovo\HOTKEY\TPONSCR.exe

c:\program files\F-Secure\FSGUI\fsguidll.exe

c:\program files\Lenovo\ZOOM\TpScrex.exe

c:\windows\system32\rundll32.exe

c:\program files\iPod\bin\iPodService.exe

c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

.

**************************************************************************

.

Completion time: 2008-12-21 17:34:27 - machine was rebooted

ComboFix-quarantined-files.txt 2008-12-21 22:34:18



Pre-Run: 21,624,995,840 bytes free

Post-Run: 21,467,738,112 bytes free



469 — E O F — 2008-10-29 23:37:28


HijackThis:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 17:35, on 2008-12-21

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Boot mode: Normal



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\ibmpmsvc.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\IPSSVC.EXE

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Intel\AMT\atchksrv.exe

C:\Program Files\LANDesk\Shared Files\residentagent.exe

C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe

C:\Program Files\F-Secure\Common\FSMA32.EXE

C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE

C:\Program Files\LANDesk\LDClient\LocalSch.EXE

C:\Program Files\F-Secure\Common\FSMB32.EXE

C:\WINDOWS\system32\CBA\pds.exe

C:\Program Files\LANDesk\LDClient\tmcsvc.exe

C:\PROGRA~1\LANDesk\LDClient\issuser.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\LANDesk\LDClient\policy.client.invoker.exe

C:\Program Files\LANDesk\LDClient\amtmon.exe

C:\Program Files\F-Secure\Common\FCH32.EXE

C:\Program Files\Intel\AMT\LMS.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

C:\Program Files\LANDesk\LDClient\softmon.exe

C:\PROGRA~1\LANDesk\LDClient\collector.exe

C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

C:\Program Files\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe

C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

C:\WINDOWS\System32\TPHDEXLG.exe

C:\WINDOWS\system32\TpKmpSVC.exe

C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe

C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe

C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe

C:\Program Files\Intel\AMT\UNS.exe

C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe

C:\Program Files\Common Files\Lenovo\Logger\logmon.exe

C:\WINDOWS\system32\WebUpdateSvc4.exe

C:\Program Files\F-Secure\Common\FAMEH32.EXE

C:\Program Files\F-Secure\Anti-Virus\fsqh.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\PROGRA~1\LANDesk\LDClient\rcgui.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\msiexec.exe

C:\Program Files\F-Secure\Anti-Virus\fssm32.exe

C:\Program Files\F-Secure\FSAUA\program\fsaua.exe

C:\Program Files\F-Secure\Common\FNRB32.EXE

C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe

C:\Program Files\F-Secure\Common\FIH32.EXE

C:\Program Files\F-Secure\Anti-Virus\fsav32.exe

C:\Program Files\F-Secure\Common\FSM32.EXE

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe

C:\Program Files\F-Secure\FSGUI\fsguidll.exe

C:\Program Files\Lenovo\Zoom\TpScrex.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe

C:\Program Files\Intel\AMT\atchk.exe

C:\WINDOWS\system32\TpShocks.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe

C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe

C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\VMware\VMware Player\hqtray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Lenovo\AwayTask\AwaySch.EXE

C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe

C:\Documents and Settings\100371322\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Documents and Settings\100371322\Desktop\mike.exe



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uoit.ca/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll

O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash

O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW

O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe

O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor

O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog

O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r

O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper

O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"

O4 - HKLM\..\Run: [TpShocks] TpShocks.exe

O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe

O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe

O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE

O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\100371322\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [\\delorean\EPSON Stylus CX9400Fax Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICFA.EXE /FU "C:\DOCUME~1\100371~1\LOCALS~1\Temp\E_S1C4.tmp" /EF "HKCU"

O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit…b?1227373676390

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1207683156375

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1207850411078

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\Software\..\Telephony: DomainName = oncampus.local

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\System\CS5\Services\Tcpip\Parameters: Domain = oncampus.local

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Intel® Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: LANDesk® Management Agent (CBA8) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\Shared Files\residentagent.exe

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe

O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure\FSAUA\program\fsaua.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe

O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE

O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe

O23 - Service: Intel Local Scheduler Service - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\LocalSch.EXE

O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe

O23 - Service: LANDesk Targeted Multicast (Intel Targeted Multicast) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\tmcsvc.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE

O23 - Service: LANDesk Remote Control Service (ISSUSER) - LANDesk Software, Ltd. - C:\PROGRA~1\LANDesk\LDClient\issuser.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: LANDesk Policy Invoker - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\policy.client.invoker.exe

O23 - Service: LANDesk® Out-of-Band Monitor Service - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\amtmon.exe

O23 - Service: Intel® Active Management Technology Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe

O23 - Service: MaxiVista_service_D - Unknown owner - C:\Program Files\MaxiVista Demo Viewer\MaxiVistaDemoViewer.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

O23 - Service: LANDesk® Software Monitoring Service (Softmon) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\softmon.exe

O23 - Service: SSIRuntimeService - Unknown owner - C:\Program Files\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe

O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe

O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe

O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe

O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

O23 - Service: TVT Windows Update Monitor (TVT_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe

O23 - Service: Intel® Active Management Technology User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\AMT\UNS.exe

O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe

O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe

O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe

O23 - Service: Web Update Wizard Service V4 (WebUpdate4) - Data Perceptions / PowerProgrammer - C:\WINDOWS\system32\WebUpdateSvc4.exe



–

End of file - 18193 bytes
Did you uncheck word wrap?

Click: Start > All Programs> Accessories
Open Notepad, click on Format and uncheck Word Wrap.


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\tysphj.0ll
c:\windows\system32\adijnndx.0ll
C:\pyfypodg.0xe
C:\bufy.0xe
c:\windows\system32\drivers\809d8e6b.0ys
C:\-131037151
c:\windows\system32\ljJBurro.0ll
c:\windows\system32\xxywUOHW.dll.bak

Driver::
809d8e6b

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
I tried turning off word wrap, however, i'm not using notepad … i'm on my linux laptop for this. Everything seems to be fixed (my DNS is not changing automatically anymore). Here are my logs:

HijackThis:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 18:48, on 2008-12-21

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Boot mode: Normal



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\ibmpmsvc.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\IPSSVC.EXE

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Intel\AMT\atchksrv.exe

C:\Program Files\LANDesk\Shared Files\residentagent.exe

C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe

C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE

C:\Program Files\F-Secure\Common\FSMA32.EXE

C:\Program Files\LANDesk\LDClient\LocalSch.EXE

C:\Program Files\F-Secure\Common\FSMB32.EXE

C:\WINDOWS\system32\CBA\pds.exe

C:\Program Files\LANDesk\LDClient\tmcsvc.exe

C:\PROGRA~1\LANDesk\LDClient\issuser.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\LANDesk\LDClient\policy.client.invoker.exe

C:\Program Files\F-Secure\Common\FCH32.EXE

C:\Program Files\LANDesk\LDClient\amtmon.exe

C:\Program Files\Intel\AMT\LMS.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

C:\Program Files\LANDesk\LDClient\softmon.exe

C:\PROGRA~1\LANDesk\LDClient\collector.exe

C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

C:\Program Files\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe

C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

C:\WINDOWS\System32\TPHDEXLG.exe

C:\WINDOWS\system32\TpKmpSVC.exe

C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe

C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe

C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe

C:\Program Files\Intel\AMT\UNS.exe

C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe

C:\WINDOWS\system32\WebUpdateSvc4.exe

C:\Program Files\Common Files\Lenovo\Logger\logmon.exe

C:\Program Files\F-Secure\Anti-Virus\fsqh.exe

C:\Program Files\F-Secure\Common\FAMEH32.EXE

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\PROGRA~1\LANDesk\LDClient\rcgui.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\F-Secure\Anti-Virus\fssm32.exe

C:\Program Files\F-Secure\FSAUA\program\fsaua.exe

C:\Program Files\F-Secure\Common\FNRB32.EXE

C:\Program Files\F-Secure\Common\FIH32.EXE

C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe

C:\Program Files\F-Secure\Anti-Virus\fsav32.exe

C:\Program Files\F-Secure\Common\FSM32.EXE

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\F-Secure\FSGUI\fsguidll.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe

C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe

C:\Program Files\Lenovo\Zoom\TpScrex.exe

C:\Program Files\Intel\AMT\atchk.exe

C:\WINDOWS\system32\TpShocks.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe

C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe

C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\VMware\VMware Player\hqtray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Lenovo\AwayTask\AwaySch.EXE

C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe

C:\Documents and Settings\100371322\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

C:\WINDOWS\explorer.exe

C:\Documents and Settings\100371322\Desktop\mike.exe



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uoit.ca/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll

O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash

O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW

O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe

O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor

O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog

O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r

O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper

O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"

O4 - HKLM\..\Run: [TpShocks] TpShocks.exe

O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe

O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe

O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE

O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\100371322\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [\\delorean\EPSON Stylus CX9400Fax Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICFA.EXE /FU "C:\DOCUME~1\100371~1\LOCALS~1\Temp\E_S1C4.tmp" /EF "HKCU"

O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit…b?1227373676390

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1207683156375

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1207850411078

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\Software\..\Telephony: DomainName = oncampus.local

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = oncampus.local

O17 - HKLM\System\CS5\Services\Tcpip\Parameters: Domain = oncampus.local

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Intel® Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: LANDesk® Management Agent (CBA8) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\Shared Files\residentagent.exe

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe

O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure\FSAUA\program\fsaua.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe

O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE

O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe

O23 - Service: Intel Local Scheduler Service - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\LocalSch.EXE

O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe

O23 - Service: LANDesk Targeted Multicast (Intel Targeted Multicast) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\tmcsvc.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE

O23 - Service: LANDesk Remote Control Service (ISSUSER) - LANDesk Software, Ltd. - C:\PROGRA~1\LANDesk\LDClient\issuser.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: LANDesk Policy Invoker - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\policy.client.invoker.exe

O23 - Service: LANDesk® Out-of-Band Monitor Service - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\amtmon.exe

O23 - Service: Intel® Active Management Technology Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe

O23 - Service: MaxiVista_service_D - Unknown owner - C:\Program Files\MaxiVista Demo Viewer\MaxiVistaDemoViewer.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

O23 - Service: LANDesk® Software Monitoring Service (Softmon) - LANDesk Software, Ltd. - C:\Program Files\LANDesk\LDClient\softmon.exe

O23 - Service: SSIRuntimeService - Unknown owner - C:\Program Files\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe

O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe

O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe

O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe

O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

O23 - Service: TVT Windows Update Monitor (TVT_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe

O23 - Service: Intel® Active Management Technology User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\AMT\UNS.exe

O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe

O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe

O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe

O23 - Service: Web Update Wizard Service V4 (WebUpdate4) - Data Perceptions / PowerProgrammer - C:\WINDOWS\system32\WebUpdateSvc4.exe



–

End of file - 18127 bytes



ComboFix:

ComboFix 08-12-21.02 - 100371322 2008-12-21 18:29:08.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2030.1300 [GMT -5:00]

Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\100371322\Desktop\CFScript.txt

* Created a new restore point

* Resident AV is active





WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!



FILE ::

C:\-131037151

C:\bufy.0xe

C:\pyfypodg.0xe

c:\windows\system32\adijnndx.0ll

c:\windows\system32\drivers\809d8e6b.0ys

c:\windows\system32\ljJBurro.0ll

c:\windows\system32\tysphj.0ll

c:\windows\system32\xxywUOHW.dll.bak

.



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.



C:\-131037151

C:\bufy.0xe

C:\pyfypodg.0xe

c:\windows\system32\adijnndx.0ll

c:\windows\system32\drivers\809d8e6b.0ys

c:\windows\system32\ljJBurro.0ll

c:\windows\system32\tysphj.0ll

c:\windows\system32\xxywUOHW.dll.bak



.

((((((((((((((((((((((((( Files Created from 2008-11-21 to 2008-12-21 )))))))))))))))))))))))))))))))

.



2008-12-21 13:26 . 2008-12-21 13:26 d——– c:\program files\Trend Micro

2008-12-21 13:06 . 2008-12-21 13:24 d——– C:\fixwareout

2008-12-21 13:04 . 2008-12-21 13:04 d——– C:\VundoFix Backups

2008-12-20 14:42 . 2008-12-20 14:42 236 –a—— C:\sqmdata19.sqm

2008-12-20 14:42 . 2008-12-20 14:42 200 –a—— C:\sqmnoopt19.sqm

2008-12-20 14:39 . 2008-12-20 14:39 d——– c:\documents and settings\100371322\Application Data\Malwarebytes

2008-12-20 14:28 . 2008-12-20 14:28 d——– c:\program files\Malwarebytes' Anti-Malware

2008-12-20 14:28 . 2008-12-20 14:28 d——– c:\documents and settings\Mobile\Application Data\Malwarebytes

2008-12-20 14:28 . 2008-12-20 14:28 d——– c:\documents and settings\All Users\Application Data\Malwarebytes

2008-12-20 14:28 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys

2008-12-20 14:28 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys

2008-12-20 14:22 . 2008-12-20 14:22 236 –a—— C:\sqmdata18.sqm

2008-12-20 14:22 . 2008-12-20 14:22 200 –a—— C:\sqmnoopt18.sqm

2008-12-20 14:20 . 2008-12-12 00:57 78,336 –a—— c:\windows\system32\Agent.OMZ.Fix.exe

2008-12-19 22:37 . 2008-12-19 22:37 236 –a—— C:\sqmdata17.sqm

2008-12-19 22:37 . 2008-12-19 22:37 200 –a—— C:\sqmnoopt17.sqm

2008-12-19 19:45 . 2008-12-19 19:45 236 –a—— C:\sqmdata16.sqm

2008-12-19 19:45 . 2008-12-19 19:45 200 –a—— C:\sqmnoopt16.sqm

2008-12-19 19:24 . 2007-06-13 08:26 1,033,216 –a—— c:\windows\explorer.exe

2008-12-19 19:24 . 2004-08-03 19:56 14,336 –a—— c:\windows\system32\svchost.exe

2008-12-19 12:58 . 2008-12-19 12:58 236 –a—— C:\sqmdata15.sqm

2008-12-19 12:58 . 2008-12-19 12:58 200 –a—— C:\sqmnoopt15.sqm

2008-12-18 22:58 . 2008-12-18 22:58 d——– c:\program files\Alwil Software

2008-12-18 22:26 . 2008-12-18 22:26 236 –a—— C:\sqmdata14.sqm

2008-12-18 22:26 . 2008-12-18 22:26 200 –a—— C:\sqmnoopt14.sqm

2008-12-18 21:32 . 2008-12-18 21:32 236 –a—— C:\sqmdata13.sqm

2008-12-18 21:32 . 2008-12-18 21:32 200 –a—— C:\sqmnoopt13.sqm

2008-12-18 00:15 . 2008-12-18 00:15 d——– c:\documents and settings\Mobile\Application Data\DivX

2008-12-16 22:06 . 2005-05-09 20:08 33,792 –a—— c:\windows\system32\drivers\cledx.sys

2008-12-16 22:06 . 2002-11-25 05:46 16,896 –a—— c:\windows\system32\drivers\synasUSB.sys

2008-12-16 22:04 . 2007-12-04 13:38 550,912 –a—— c:\windows\system32\OLEAUT32.DLL

2008-12-16 22:04 . 2004-08-04 06:00 83,456 –a—— c:\windows\system32\OLEPRO32.DLL

2008-12-16 22:04 . 2008-12-16 22:05 83,375 –a—— c:\program files\Common Files\insta.exe

2008-12-16 22:04 . 2004-08-04 06:00 65,024 –a—— c:\windows\system32\ASYCFILT.DLL

2008-12-16 22:04 . 2004-08-04 06:00 17,920 –a—— c:\windows\system32\STDOLE2.TLB

2008-12-16 22:04 . 2004-08-04 06:00 3,584 –a—— c:\windows\system32\COMCAT.DLL

2008-12-16 18:23 . 2006-11-29 13:06 3,426,072 –a—— c:\windows\system32\d3dx9_32.dll

2008-12-16 17:20 . 2008-12-18 20:08 d——– c:\program files\VstPlugins

2008-12-16 17:20 . 2008-12-16 17:20 d——– c:\program files\Outsim

2008-12-16 17:20 . 2002-07-07 17:14 1,294,336 –a—— c:\windows\system32\vorbis.acm

2008-12-16 17:20 . 2006-06-20 03:56 225,280 –a—— c:\windows\system32\rewire.dll

2008-12-16 17:18 . 2008-12-18 20:09 d——– c:\program files\Image-Line

2008-12-16 17:14 . 2008-12-16 17:14 0 –ah—– c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf

2008-12-16 17:14 . 2008-12-16 17:14 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_xusb20_01001.Wdf

2008-12-16 17:13 . 2008-12-18 20:09 d——– c:\program files\Drum Machine

2008-12-16 17:13 . 2006-10-04 18:46 1,418,720 –a—— c:\windows\system32\WdfCoInstaller01001.dll

2008-12-16 17:13 . 2007-04-04 17:53 81,768 –a—— c:\windows\system32\xinput1_3.dll

2008-12-16 17:13 . 2006-10-13 14:48 50,048 –a—— c:\windows\system32\drivers\xusb20.sys

2008-12-15 15:19 . 2008-12-15 15:19 236 –a—— C:\sqmdata12.sqm

2008-12-15 15:19 . 2008-12-15 15:19 200 –a—— C:\sqmnoopt12.sqm

2008-12-15 14:16 . 2008-12-15 14:16 1,409 –a—— c:\windows\QTFont.for

2008-12-11 19:46 . 2008-12-21 18:42 54,156 –ah—– c:\windows\QTFont.qfn

2008-12-10 16:50 . 2008-12-10 16:50 d——– c:\program files\Winamp Toolbar

2008-12-10 16:50 . 2008-12-10 16:51 d——– c:\program files\Winamp

2008-12-10 16:50 . 2008-12-10 16:50 d——– c:\documents and settings\All Users\Application Data\Winamp Toolbar

2008-12-10 16:50 . 2008-12-10 16:51 d——– c:\documents and settings\100371322\Application Data\Winamp

2008-12-09 16:29 . 2008-12-09 16:30 d——– c:\program files\iPhone Configuration Utility

2008-12-09 16:21 . 2008-12-09 16:33 d——– c:\windows\SxsCaPendDel

2008-12-07 18:08 . 2008-12-07 18:46 31 –a—— c:\documents and settings\100371322\jagex_runescape_preferences.dat

2008-12-06 17:44 . 2008-12-18 20:08 d——– c:\program files\Big Rigs Racing

2008-12-02 20:31 . 2008-12-02 20:31 d——– C:\ICO

2008-12-02 20:27 . 2008-09-21 20:09 47,815 –a—— C:\nes.png

2008-12-02 20:27 . 2008-09-21 20:09 17,359 –a—— C:\controller.png

2008-12-01 09:39 . 2008-12-01 09:51 d——– c:\program files\Spybot - Search & Destroy

2008-12-01 09:39 . 2008-12-01 09:51 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2008-12-01 09:20 . 2008-12-16 22:08 d——– c:\documents and settings\100371322\Application Data\FrostWire

2008-12-01 09:06 . 2008-12-01 09:06 d——– C:\Batch

2008-12-01 09:03 . 2008-12-01 09:03 d——– C:\NirCMD

2008-12-01 08:58 . 2008-12-01 09:20 d——– c:\program files\FrostWire

2008-12-01 08:31 . 2008-12-01 08:32 d——– c:\program files\ApexDC++

2008-11-25 23:00 . 2008-11-30 19:48 d——– c:\documents and settings\100371322\Application Data\Thinstall

2008-11-21 16:20 . 2008-11-21 16:20 d——– c:\program files\SC



.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-21 23:43 ——— d—–w c:\program files\Steam

2008-12-21 18:48 ——— d—–w c:\documents and settings\All Users\Application Data\vulScan

2008-12-17 03:08 ——— d—–w c:\documents and settings\100371322\Application Data\Azureus

2008-12-15 20:14 ——— d—–w c:\program files\Common Files\Research In Motion

2008-12-15 20:02 ——— d—–w c:\documents and settings\100371322\Application Data\Research In Motion

2008-12-12 04:04 ——— d—–w c:\documents and settings\100371322\Application Data\FileZilla

2008-12-09 21:40 ——— d—–w c:\documents and settings\All Users\Application Data\VMware

2008-12-09 21:36 ——— d—–w c:\documents and settings\NetworkService\Application Data\VMware

2008-12-05 12:49 ——— d—–w c:\program files\Vuze

2008-12-01 15:21 ——— d—–w c:\documents and settings\All Users\Application Data\SoftwareSecure

2008-12-01 15:01 ——— d—–w c:\program files\Project64 1.6

2008-12-01 15:00 ——— d—–w c:\program files\YuGiOh Virtual Desktop

2008-12-01 15:00 ——— d—–w c:\program files\PTDD Group

2008-12-01 13:51 ——— d—–w c:\documents and settings\100371322\Application Data\LimeWire

2008-12-01 13:28 ——— d—–w c:\program files\DC++

2008-11-28 00:11 ——— d—–w c:\program files\Minefield

2008-11-21 02:11 ——— d–h–w c:\program files\InstallShield Installation Information

2008-11-21 02:11 ——— d—–w c:\program files\Logitech

2008-11-21 02:11 ——— d—–w c:\program files\Common Files\Remote Control Software Common

2008-11-21 02:10 ——— d—–w c:\program files\Common Files\Remote Control USB Driver

2008-11-17 15:24 ——— d—–w c:\documents and settings\100371322\Application Data\vlc

2008-11-07 22:35 ——— d—–w c:\documents and settings\100371322\Application Data\Sibelius Software

2008-11-07 22:34 ——— d—–w c:\program files\Musicnotes

2008-11-03 22:54 ——— d—–w c:\documents and settings\100371322\Application Data\VMware

2008-11-01 19:22 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help

2008-11-01 18:41 ——— d—–w c:\documents and settings\100371322\Application Data\GrabIt

2008-10-30 19:19 ——— d—–w c:\documents and settings\100371322\Application Data\Red Alert 3

2008-10-29 23:51 ——— d—–w c:\program files\JFK Reloaded

2008-10-27 15:04 70,992 —-a-w c:\windows\system32\XAPOFX1_2.dll

2008-10-27 15:04 514,384 —-a-w c:\windows\system32\XAudio2_3.dll

2008-10-27 15:04 235,856 —-a-w c:\windows\system32\xactengine3_3.dll

2008-10-27 15:04 23,376 —-a-w c:\windows\system32\X3DAudio1_5.dll

2008-10-23 18:43 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft

2008-10-23 18:41 ——— d—–w c:\program files\Lavasoft

2008-10-23 18:41 ——— d—–w c:\program files\Common Files\Wise Installation Wizard

2008-10-23 18:33 ——— d—–w c:\program files\Windows Live

2008-10-23 18:31 ——— d—–w c:\program files\Microsoft

2008-10-23 18:27 ——— d—–w c:\program files\Common Files\Windows Live

2008-10-22 00:08 ——— d—–w c:\program files\Duke Nukem 3D

2008-10-20 13:46 50,546 —-a-w c:\windows\system32\wuwuninst.exe

2008-10-10 09:52 452,440 —-a-w c:\windows\system32\d3dx10_40.dll

2008-10-10 09:52 4,379,984 —-a-w c:\windows\system32\D3DX9_40.dll

2008-10-10 09:52 2,036,576 —-a-w c:\windows\system32\D3DCompiler_40.dll

2008-10-08 00:05 64,971 —-a-w c:\windows\BricoPackUninst.cmd

2008-10-08 00:05 6,120 —-a-w c:\windows\BricoPackFoldersDelete.cmd

2008-10-01 00:58 410,976 —-a-w c:\windows\system32\deploytk.dll

.



——- Sigcheck ——-



2007-10-30 11:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys

2004-08-04 06:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB941644$\tcpip.sys

2008-09-07 13:41 360064 8283a4d489b207991efdc8328733d0bc c:\windows\system32\dllcache\TCPIP.SYS

2008-09-07 13:41 360064 8283a4d489b207991efdc8328733d0bc c:\windows\system32\drivers\TCPIP.SYS

.

((((((((((((((((((((((((((((( snapshot@2008-12-21_17.33.19.01 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-12-21 23:34:51 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_50c.dat

+ 2008-12-21 23:34:43 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_668.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4



[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2008-09-08 3513344]

"Google Update"="c:\documents and settings\100371322\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-04 133104]

"Steam"="c:\program files\Steam\Steam.exe" [2008-10-07 1410296]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]

"\\delorean\EPSON Stylus CX9400Fax Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICFA.EXE" [2007-03-23 182272]



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"F-Secure Manager"="c:\program files\F-Secure\Common\FSM32.EXE" [2006-12-05 176177]

"F-Secure TNB"="c:\program files\F-Secure\FSGUI\TNBUtil.exe" [2007-01-08 724992]

"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2007-12-05 122880]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-05 524288]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-10 8495104]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-10 81920]

"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-01-24 66928]

"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-04-27 243248]

"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2008-01-11 294912]

"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2008-01-11 208896]

"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-12-20 60704]

"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352]

"atchk"="c:\program files\Intel\AMT\atchk.exe" [2007-09-07 408088]

"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-12-11 1044480]

"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2008-01-11 144728]

"LPMailChecker"="c:\progra~1\THINKV~2\PrdCtr\LPMLCHK.exe" [2008-01-11 124248]

"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2007-12-05 487424]

"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-07-29 185896]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-09-30 144792]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-09-12 36352]

"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696]

"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

"VMware hqtray"="c:\program files\VMware\VMware Player\hqtray.exe" [2008-03-03 55856]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-19 267048]

"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]

"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]

"nwiz"="nwiz.exe" [2007-12-10 c:\windows\system32\nwiz.exe]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]

"TpShocks"="TpShocks.exe" [2007-11-22 c:\windows\system32\TpShocks.exe]



c:\documents and settings\All Users\Start Menu\Programs\Startup\

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-04-09 50688]



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"AllowMultipleTSSessions"= 1 (0x1)

"SynchronousMachineGroupPolicy"= 0 (0x0)

"SynchronousUserGroupPolicy"= 0 (0x0)



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoWelcomeScreen"= 1 (0x1)



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"ForceStartMenuLogOff"= 1 (0x1)

"NoWelcomeScreen"= 1 (0x1)

"NoAutoUpdate"= 0 (0x0)

"NoStartMenuNetworkPlaces"= 1 (0x1)

"NoSecurityTab"= 1 (0x1)



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]

2007-08-14 14:54 89600 c:\windows\system32\psqlpwd.dll



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]

2006-09-06 15:37 34344 c:\program files\Lenovo\HOTKEY\notifyf2.dll



[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]

2007-12-14 15:36 28672 c:\program files\Lenovo\HOTKEY\tphklock.dll



[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Notification Packages REG_MULTI_SZ scecli psqlpwd



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1644491937-682003330-725345543-231014\Scripts\Logon\0\0]

"Script"=\\oncampus.local\SysVol\oncampus.local\scripts\javaupdate\javaupd.bat



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1644491937-682003330-725345543-231014\Scripts\Logon\1\0]

"Script"=\\oncampus.local\NETLOGON\AcademicIntegrity\stu\icon.bat



[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1644491937-682003330-725345543-231014\Scripts\Logon\2\0]

"Script"=\\oncampus.local\NETLOGON\IE6SiteAddition.bat



[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"Bonjour Service"=2 (0x2)



[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)



[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=

"c:\\Program Files\\FrostWire\\FrostWire.exe"=

"c:\\Program Files\\LANDesk\\Shared Files\\residentagent.exe"=



R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2008-04-08 50240]

R0 Shockprf;Shockprf;c:\windows\system32\DRIVERS\Apsx86.sys [2007-10-16 103472]

R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\DRIVERS\ApsHM86.sys [2007-10-16 19504]

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-18 111184]

R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\Tppwrif.sys [2008-04-09 4442]

R1 tvtumon;tvtumon;c:\windows\system32\DRIVERS\tvtumon.sys [2007-12-05 46656]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-18 20560]

R2 CBA8;LANDesk® Management Agent;"c:\program files\LANDesk\Shared Files\residentagent.exe" [2008-06-02 155648]

R2 LANDesk Policy Invoker;LANDesk Policy Invoker;"c:\program files\LANDesk\LDClient\policy.client.invoker.exe" [2008-09-04 118784]

R2 LANDesk® Out-of-Band Monitor Service;LANDesk® Out-of-Band Monitor Service;c:\program files\LANDesk\LDClient\amtmon.exe [2008-09-04 987136]

R2 smihlp;SMI Helper Driver (smihlp);\??\c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-08-14 10896]

R2 Softmon;LANDesk® Software Monitoring Service;"c:\program files\LANDesk\LDClient\softmon.exe" [2008-09-04 331776]

R2 SSIRuntimeService;SSIRuntimeService;"c:\program files\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe" [2007-09-11 45056]

R2 TVT Backup Protection Service;TVT Backup Protection Service;"c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe" [2007-12-05 520192]

R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2007-12-05 249856]

R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Intel\AMT\UNS.exe [2008-04-09 1464856]

R2 WebUpdate4;Web Update Wizard Service V4;c:\windows\system32\WebUpdateSvc4.exe [2007-05-18 229856]

R3 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\c:\program files\F-Secure\Anti-Virus\minifilter\fsgk.sys [2008-04-08 51712]

R3 ldblank;Screen Blanking driver for Remote Control;c:\windows\system32\DRIVERS\ldblank.sys [2008-09-04 11904]

R3 ldmirror;ldmirror;c:\windows\system32\DRIVERS\ldmirror.sys [2008-09-04 3328]

R3 mirrorflt;Mirror Filter Driver for Uninstall;c:\windows\system32\DRIVERS\mirrorflt.sys [2008-09-04 3712]

R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2007-05-22 30336]

S2 MaxiVista_service_D;MaxiVista_service_D;"c:\program files\MaxiVista Demo Viewer\MaxiVistaDemoViewer.exe" -service []

S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\DRIVERS\xusb20.sys [2008-12-16 50048]

S4 F-Secure Filter;F-Secure File System Filter;\??\c:\program files\F-Secure\Anti-Virus\Win2K\FSfilter.sys [2008-04-08 33024]

S4 F-Secure Recognizer;F-Secure File System Recognizer;\??\c:\program files\F-Secure\Anti-Virus\Win2K\FSrec.sys [2008-04-08 18432]

S4 msvsmon80;Visual Studio 2005 Remote Debugger;"c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 [2006-12-02 2805000]



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a9d78a89-8cae-11dd-8d68-005056c00008}]

\Shell\AutoRun\command - H:\LaunchU3.exe -a

.

Contents of the 'Scheduled Tasks' folder



2008-12-21 c:\windows\Tasks\GoogleUpdateTaskUser.job

- c:\documents and settings\100371322\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 14:37]



2008-12-21 c:\windows\Tasks\PMTask.job

- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-01-11 00:30]

.

.

——- Supplementary Scan ——-

.

uStart Page = hxxp://uoit.ca/

uInternet Settings,ProxyOverride = *.local

IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\100371322\Application Data\Mozilla\Firefox\Profiles\hzklqdrv.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - component: c:\documents and settings\100371322\Application Data\Mozilla\Firefox\Profiles\hzklqdrv.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np32asw.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np32dsw.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npnul32.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\NPOFF12.DLL

FF - plugin: c:\program files\Mozilla Firefox\plugins\nppl3260.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin4.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin5.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin6.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin7.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\nprjplug.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\nprpjplug.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npsibelius.dll

FF - plugin: c:\program files\Opera\program\plugins\npsibelius.dll



ATTENTION: FIREFOX POLICES IS IN FORCE

c:\program files\Minefield\greprefs\all.js - pref("browser.display.focus_ring_style", 1);

c:\program files\Minefield\greprefs\all.js - pref("gfx.color_management.mode", 2);

c:\program files\Minefield\greprefs\all.js - pref("gfx.color_management.rendering_intent", 0);

c:\program files\Minefield\greprefs\all.js - pref("gfx.downloadable_fonts.enabled", true);

c:\program files\Minefield\greprefs\all.js - pref("gfx.downloadable_fonts.enforce_same_site_origin", true);

c:\program files\Minefield\greprefs\all.js - pref("view_source.editor.args", "");

c:\program files\Minefield\greprefs\all.js - pref("javascript.options.jit.content", false);

c:\program files\Minefield\greprefs\all.js - pref("javascript.options.jit.chrome", false);

c:\program files\Minefield\greprefs\all.js - pref("layout.css.visited_links_enabled", true);

c:\program files\Minefield\greprefs\all.js - pref("ui.panel.default_level_parent", false);

c:\program files\Minefield\greprefs\all.js - pref("image.cache.size", 5242880);

c:\program files\Minefield\greprefs\all.js - pref("image.cache.timeweight", 500);

c:\program files\Minefield\defaults\pref\channel-prefs.js - pref("app.update.channel", "nightly");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("startup.homepage_override_url","http://www.mozilla.org/projects/%APP%/%VERSION%/whatsnew/");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("startup.homepage_welcome_url","http://www.mozilla.org/projects/%APP%/%VERSION%/firstrun/");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.mozilla.org/products/%APP%/");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("app.update.url.details", "http://www.mozilla.org/projects/%APP%/");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("app.releaseNotesURL", "http://www.mozilla.org/projects/%APP%/%VERSION%/releasenotes/");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "");

c:\program files\Minefield\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-f-CN", "");

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.urlbar.restrict.history", "^");

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.urlbar.restrict.tag", "+");

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.urlbar.match.title", "#");

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.urlbar.match.url", "@");

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.search.cache.enabled", true);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.tabs.autoHide", false);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.tabs.closeWindowWithLastTab", true);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.ctrlTab.mostRecentlyUsed", true);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.ctrlTab.recentlyUsedLimit", 7);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.ctrlTab.smoothScroll", true);

c:\program files\Minefield\defaults\pref\firefox.js - pref("browser.sessionstore.max_resumed_crashes", 1);

.



**************************************************************************



catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-21 18:41:07

Windows 5.1.2600 Service Pack 2 NTFS



scanning hidden processes …



scanning hidden autostart entries …



scanning hidden files …



scan completed successfully

hidden files: 0



**************************************************************************

.

——————— DLLs Loaded Under Running Processes ———————



- - - - - - - > 'winlogon.exe'(880)

c:\windows\system32\vrlogon.dll

c:\windows\system32\psqlpwd.dll

c:\program files\ThinkVantage Fingerprint Software\homefus2.dll

c:\program files\ThinkVantage Fingerprint Software\infra.dll

c:\program files\ThinkVantage Fingerprint Software\homepass.dll

c:\program files\ThinkVantage Fingerprint Software\bio.dll

c:\program files\ThinkVantage Fingerprint Software\ps2css.dll

c:\program files\ThinkVantage Fingerprint Software\crypto.dll

c:\program files\ThinkVantage Fingerprint Software\pscssint.dll

c:\program files\ThinkVantage Fingerprint Software\remote.dll

c:\program files\Lenovo\HOTKEY\tphklock.dll

c:\windows\system32\netprovcredman.dll



- - - - - - - > 'lsass.exe'(936)

c:\windows\system32\psqlpwd.dll

c:\program files\ThinkVantage Fingerprint Software\homefus2.dll

c:\program files\ThinkVantage Fingerprint Software\infra.dll



- - - - - - - > 'explorer.exe'(5708)

c:\windows\system32\nview.dll

c:\progra~1\WINDOW~2\wmpband.dll

.

———————— Other Running Processes ————————

.

c:\windows\system32\ibmpmsvc.exe

c:\program files\Intel\Wireless\Bin\S24EvMon.exe

c:\program files\Lavasoft\Ad-Aware\aawservice.exe

c:\program files\Alwil Software\Avast4\aswUpdSv.exe

c:\program files\Alwil Software\Avast4\ashServ.exe

c:\windows\system32\IPSSVC.EXE

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Intel\AMT\atchksrv.exe

c:\program files\Intel\Wireless\Bin\EvtEng.exe

c:\program files\F-Secure\Anti-Virus\fsgk32st.exe

c:\program files\F-Secure\Anti-Virus\fsgk32.exe

c:\program files\F-Secure\common\FSMA32.EXE

c:\program files\LANDesk\LDClient\LocalSch.EXE

c:\program files\F-Secure\common\FSMB32.EXE

c:\windows\system32\cba\pds.exe

c:\program files\LANDesk\LDClient\tmcsvc.exe

c:\progra~1\LANDesk\LDClient\issuser.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\F-Secure\common\FCH32.EXE

c:\program files\Intel\AMT\LMS.exe

c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

c:\windows\system32\nvsvc32.exe

c:\program files\Intel\Wireless\Bin\RegSrvc.exe

c:\progra~1\LANDesk\LDClient\collector.exe

c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe

c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

c:\windows\system32\TPHDEXLG.exe

c:\windows\system32\TpKmpSvc.exe

c:\program files\Lenovo\Rescue and Recovery\rrservice.exe

c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe

c:\program files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe

c:\program files\Common Files\Lenovo\Logger\logmon.exe

c:\program files\F-Secure\Anti-Virus\fsqh.exe

c:\program files\F-Secure\common\FAMEH32.EXE

c:\program files\Alwil Software\Avast4\ashMaiSv.exe

c:\progra~1\LANDesk\LDClient\rcgui.exe

c:\program files\Alwil Software\Avast4\ashWebSv.exe

c:\windows\system32\msiexec.exe

c:\program files\F-Secure\Anti-Virus\fssm32.exe

c:\program files\F-Secure\FSAUA\program\fsaua.exe

c:\program files\F-Secure\common\FNRB32.exe

c:\program files\F-Secure\common\FIH32.exe

c:\program files\F-Secure\FWES\program\fsdfwd.exe

c:\program files\F-Secure\Anti-Virus\fsav32.exe

c:\program files\F-Secure\FSGUI\fsguidll.exe

c:\windows\system32\rundll32.exe

c:\windows\system32\rundll32.exe

c:\windows\system32\rundll32.exe

c:\windows\system32\rundll32.exe

c:\program files\Lenovo\HOTKEY\TPONSCR.exe

c:\program files\Lenovo\ZOOM\TpScrex.exe

c:\program files\iPod\bin\iPodService.exe

c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

.

**************************************************************************

.

Completion time: 2008-12-21 18:46:59 - machine was rebooted

ComboFix-quarantined-files.txt 2008-12-21 23:46:50

ComboFix2.txt 2008-12-21 22:34:31



Pre-Run: 21,407,248,384 bytes free

Post-Run: 21,384,273,920 bytes free



453 — E O F — 2008-10-29 23:37:28
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    To be on the safe side, I would also change all my passwords.


    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • Winpatrol

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Also: "How to prevent malware"
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI