Hi Ken
just to let u know I did a combofix scan few days ago ready to be sent but then I deleted it, this is the new one but the recovery point was already created.
tell me if this can any problem with the log pasted below
thanks
ComboFix 09-01-13.04 - Admin 2009-01-14 13:14:09.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1429 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090113-1] *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\abtnigyy.dll
c:\windows\system32\Adgilnpo.ini
c:\windows\system32\Adgilnpo.ini2
c:\windows\system32\afossxak.ini
c:\windows\system32\bqggkahu.ini
c:\windows\system32\cvchiw.dll
c:\windows\system32\idwddtrf.ini
c:\windows\system32\jgbpishd.ini
c:\windows\system32\kcibiygi.ini
c:\windows\system32\kxcudwca.ini
c:\windows\system32\nenothjk.dll
c:\windows\system32\nnarbxoy.ini
c:\windows\system32\oudbplnl.ini
c:\windows\system32\pokeydjw.ini
c:\windows\system32\wbqgtqte.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_SENEKA
((((((((((((((((((((((((( Files Created from 2008-12-14 to 2009-01-14 )))))))))))))))))))))))))))))))
.
2009-01-14 01:07 . 2009-01-14 01:07 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-14 01:07 . 2009-01-14 01:07 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-14 01:07 . 2009-01-14 01:07 d——– c:\documents and settings\Admin\Application Data\Malwarebytes
2009-01-14 01:07 . 2009-01-04 18:39 38,496 ——— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 01:07 . 2009-01-04 18:39 15,504 ——— c:\windows\system32\drivers\mbam.sys
2009-01-04 20:55 . 2009-01-04 20:55 d——– c:\program files\Trend Micro
2009-01-04 16:50 . 2009-01-04 16:50 d——– c:\program files\Alwil Software
2009-01-04 15:06 . 2007-05-03 20:19 20,480 ——— c:\windows\system32\drivers\PcdrNdisuio.sys
2009-01-04 11:29 . 2009-01-04 11:29 d——– c:\program files\Common Files\Wise Installation Wizard
2009-01-03 23:39 . 2009-01-03 23:40 d——– c:\program files\SpywareBlaster
2009-01-02 01:47 . 2009-01-02 01:47 d——– c:\windows\Sun
2009-01-01 12:12 . 2009-01-01 12:12 410,984 ——— c:\windows\system32\deploytk.dll
2009-01-01 12:12 . 2009-01-01 12:12 73,728 ——— c:\windows\system32\javacpl.cpl
2008-12-29 14:10 . 2008-12-29 14:10 d——– c:\program files\Lavasoft
2008-12-29 14:10 . 2008-12-29 14:10 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-28 16:21 . 2008-12-28 16:24 d——– c:\windows\SxsCaPendDel
2008-12-28 16:08 . 2008-12-28 16:08 d——– c:\program files\Common Files\iS3
2008-12-28 16:08 . 2008-12-28 16:17 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2008-12-28 16:08 . 2008-12-28 16:08 d——– c:\documents and settings\All Users\Application Data\SITEguard
2008-12-27 17:54 . 2008-09-04 16:42 1,106,944 ——— c:\windows\system32\dllcache\msxml3.dll
2008-12-27 17:48 . 2008-05-01 14:30 331,776 ——— c:\windows\system32\dllcache\msadce.dll
2008-12-27 17:48 . 2008-10-03 10:15 247,326 ——— c:\windows\system32\dllcache\strmdll.dll
2008-12-27 17:44 . 2008-12-27 17:54 d——– c:\windows\system32\CatRoot_bak
2008-12-27 16:54 . 2008-12-27 16:54 d——– c:\documents and settings\Admin\Application Data\Uniblue
2008-12-24 18:55 . 2008-12-24 18:55 d——– c:\windows\system32\scripting
2008-12-24 18:55 . 2008-12-24 18:55 d——– c:\windows\system32\en
2008-12-24 18:55 . 2008-12-27 15:53 d——– c:\windows\system32\bits
2008-12-24 18:55 . 2008-12-24 18:55 d——– c:\windows\l2schemas
2008-12-24 18:47 . 2008-08-14 09:55 2,142,720 ——— c:\windows\system32\ntoskrnl.exe
2008-12-18 13:22 . 2008-12-18 13:22 d——– c:\program files\Real
2008-12-18 13:22 . 2008-12-18 13:22 d——– c:\program files\Common Files\xing shared
2008-12-18 13:22 . 2008-12-18 13:22 d——– c:\program files\Common Files\Real
2008-12-14 19:21 . 2008-12-14 19:22 d——– c:\program files\SopCast
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 14:23 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-08 13:58 ——— d—–w c:\documents and settings\Admin\Application Data\Lenovo
2009-01-04 00:40 ——— d—–w c:\program files\PCDR5
2009-01-03 21:27 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-01-03 21:22 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-01 12:12 ——— d—–w c:\program files\Java
2008-12-27 18:30 ——— d—–w c:\program files\CCleaner
2008-12-11 13:48 ——— d—–w c:\program files\Windows Media Connect 2
2008-12-11 05:25 ——— d—–w c:\documents and settings\Admin\Application Data\DivX
2008-12-11 04:41 ——— d—–w c:\documents and settings\All Users\Application Data\Lenovo
2008-12-11 04:41 ——— d—–w c:\documents and settings\Administrator\Application Data\Lenovo
2008-12-10 13:46 ——— d—–w c:\program files\iTunes
2008-12-10 13:46 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-10 13:46 ——— d—–w c:\documents and settings\Admin\Application Data\Apple Computer
2008-12-10 13:45 ——— d—–w c:\program files\QuickTime
2008-12-10 13:45 ——— d—–w c:\program files\iPod
2008-12-10 13:45 ——— d—–w c:\program files\Common Files\Apple
2008-12-10 13:45 ——— d—–w c:\program files\Bonjour
2008-12-10 13:44 ——— d—–w c:\program files\Apple Software Update
2008-12-10 13:44 ——— d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-10 13:43 ——— d—–w c:\documents and settings\All Users\Application Data\Apple
2008-12-10 13:33 ——— d—–w c:\program files\DivX
2008-12-10 13:22 ——— d—–w c:\documents and settings\Admin\Application Data\Intel
2008-12-09 19:07 ——— d—–w c:\documents and settings\Admin\Application Data\ESET
2008-12-09 19:06 ——— d—–w c:\program files\ESET
2008-12-09 19:06 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2008-12-09 18:55 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-12-09 18:49 ——— d—–w c:\program files\Windows Live Toolbar
2008-12-09 18:48 50 ——w c:\windows\system32\drivers\LENOVO_0769_BLG.MRK
2008-12-09 18:42 ——— d—–w c:\program files\Lenovo
2008-12-09 18:41 ——— d—–w c:\program files\Common Files\Lenovo
2008-12-09 18:40 806 ——w c:\windows\system32\drivers\SYMEVENT.INF
2008-12-09 18:40 8,014 ——w c:\windows\system32\drivers\SYMEVENT.CAT
2008-12-09 18:38 ——— d—–w c:\windows\system32\config\systemprofile\Application Data\Lenovo
2008-12-09 18:35 33,536 ——w c:\windows\system32\drivers\tvtfilter.sys
2008-12-09 18:34 7,012 ——w c:\windows\system32\drivers\pmemnt.sys
2008-12-09 18:34 ——— d—–w c:\program files\Picasa2
2008-12-09 18:34 ——— d—–w c:\program files\Google
2008-12-09 18:33 ——— d—–w c:\program files\ThinkPad
2008-12-09 18:33 ——— d—–w c:\program files\Lenovo Fingerprint Software
2008-12-09 18:33 ——— d—–w c:\program files\Diskeeper Corporation
2008-12-09 18:30 ——— d—–w c:\program files\ThinkVantage
2008-12-09 18:30 ——— d—–w c:\documents and settings\All Users\Application Data\PC-Doctor
2008-12-09 18:29 ——— d—–w c:\program files\Lenovo Registration
2008-12-09 18:29 ——— d—–w c:\program files\Common Files\Adobe
2008-12-09 18:28 ——— d—–w c:\program files\Sonic Icons for Lenovo
2008-12-09 18:28 ——— d—–w c:\program files\Roxio
2008-12-09 18:28 ——— d—–w c:\program files\Common Files\SureThing Shared
2008-12-09 18:28 ——— d—–w c:\program files\Common Files\Sonic Shared
2008-12-09 18:28 ——— d—–w c:\program files\Common Files\Installshield
2008-12-09 18:28 ——— d—–w c:\documents and settings\All Users\Application Data\InstallShield
2008-12-09 18:27 ——— d—–w c:\program files\InterVideo
2008-12-09 18:27 ——— d—–w c:\program files\Common Files\InterVideo
2008-12-09 18:26 ——— d—–w c:\windows\system32\config\systemprofile\Application Data\InstallShield
2008-12-09 18:26 ——— d—–w c:\program files\Common Files\Java
2008-12-09 18:26 ——— d—–w c:\documents and settings\Administrator\Application Data\InstallShield
2008-12-09 18:26 ——— d—–w c:\documents and settings\Admin\Application Data\InstallShield
2008-12-09 18:24 ——— d—–w c:\documents and settings\NetworkService\Application Data\Intel
2008-12-09 18:22 21,425 ——w c:\windows\system32\drivers\AegisP.sys
2008-12-09 18:22 ——— d—–w c:\windows\system32\config\systemprofile\Application Data\Intel
2008-12-09 18:22 ——— d—–w c:\documents and settings\LocalService\Application Data\Intel
2008-12-09 18:22 ——— d—–w c:\documents and settings\All Users\Application Data\Intel
2008-12-09 18:21 ——— d—–w c:\program files\Intel
2008-12-09 18:21 ——— d—–w c:\program files\Broadcom
2008-12-09 18:20 315,392 ——w c:\windows\HideWin.exe
2008-12-09 18:20 ——— d—–w c:\program files\Realtek
2008-12-09 18:19 ——— d—–w c:\program files\Synaptics
2008-12-09 18:17 ——— d—–w c:\program files\MSXML 4.0
2008-12-09 12:32 ——— d—–w c:\documents and settings\All Users\Application Data\CyberLink
2008-12-09 12:31 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-09 12:31 ——— d—–w c:\program files\Nero
2008-12-09 12:31 ——— d—–w c:\program files\CyberLink
2008-12-09 12:31 ——— d—–w c:\program files\Common Files\Ahead
2008-12-09 12:29 ——— d—–w c:\program files\Microsoft Works
2008-12-09 12:29 ——— d—–w c:\program files\Microsoft ActiveSync
2008-12-09 12:29 ——— d—–w c:\program files\Common Files\L&H
2008-12-09 12:28 ——— d—–w c:\program files\Microsoft.NET
.
——- Sigcheck ——-
2005-03-01 23:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2005-03-02 00:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\$NtUninstallKB890859$\ntkrnlpa.exe
2008-08-14 09:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\Driver Cache\i386\ntkrnlpa.exe
2008-08-14 09:18 2020864 501fde895f35df1dae49fd54bbf9d396 c:\windows\system32\ntkrnlpa.exe
2008-08-14 09:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\system32\dllcache\ntkrnlpa.exe
2005-03-02 01:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2005-03-02 00:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\$NtUninstallKB890859$\ntoskrnl.exe
2008-08-14 09:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\Driver Cache\i386\ntoskrnl.exe
2008-08-14 09:55 2142720 60794ea12961b7341ad54c731b50ae15 c:\windows\system32\ntoskrnl.exe
2008-08-14 09:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\system32\dllcache\ntoskrnl.exe
.
((((((((((((((((((((((((((((( snapshot@2008-12-27_17.39.33.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-01 15:04:00 331,776 ——w c:\windows\$hf_mig$\KB952287\SP2QFE\msadce.dll
+ 2008-05-01 14:33:02 331,776 ——w c:\windows\$hf_mig$\KB952287\SP3GDR\msadce.dll
+ 2008-05-01 14:38:05 331,776 ——w c:\windows\$hf_mig$\KB952287\SP3QFE\msadce.dll
+ 2008-10-03 09:57:49 247,326 ——w c:\windows\$hf_mig$\KB954600\SP2QFE\strmdll.dll
+ 2008-10-03 10:02:42 247,326 ——w c:\windows\$hf_mig$\KB954600\SP3GDR\strmdll.dll
+ 2008-10-03 09:49:31 247,326 ——w c:\windows\$hf_mig$\KB954600\SP3QFE\strmdll.dll
+ 2008-09-04 16:32:52 1,106,944 ——w c:\windows\$hf_mig$\KB955069\SP2QFE\msxml3.dll
+ 2008-09-04 17:15:04 1,106,944 ——w c:\windows\$hf_mig$\KB955069\SP3GDR\msxml3.dll
+ 2008-09-04 17:12:27 1,106,944 ——w c:\windows\$hf_mig$\KB955069\SP3QFE\msxml3.dll
- 2000-08-31 08:00:00 28,672 —-a-w c:\windows\NIRCMD.exe
+ 2000-08-31 08:00:00 29,696 —-a-w c:\windows\NIRCMD.exe
+ 2008-11-26 17:21:30 1,236,208 —-a-w c:\windows\system32\aswBoot.exe
+ 2008-11-26 17:15:10 97,480 —-a-w c:\windows\system32\AvastSS.scr
- 2008-12-24 19:49:09 16,384 ——w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-13 12:59:24 16,384 ——w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-24 19:49:09 32,768 ——w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-13 12:59:24 32,768 ——w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-24 19:49:09 32,768 ——w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-13 12:59:24 32,768 ——w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-26 17:15:35 26,944 ——w c:\windows\system32\drivers\aavmker4.sys
+ 2008-11-26 17:17:25 20,560 ——w c:\windows\system32\drivers\aswFsBlk.sys
+ 2008-11-26 17:18:25 93,296 ——w c:\windows\system32\drivers\aswmon.sys
+ 2008-11-26 17:18:18 94,032 ——w c:\windows\system32\drivers\aswmon2.sys
+ 2008-11-26 17:16:29 23,152 ——w c:\windows\system32\drivers\aswRdr.sys
+ 2008-11-26 17:17:36 111,184 ——w c:\windows\system32\drivers\aswSP.sys
+ 2008-11-26 17:16:38 50,864 ——w c:\windows\system32\drivers\aswTdi.sys
+ 2008-04-29 10:19:50 12,960 ——w c:\windows\system32\drivers\Awrtpd.sys
+ 2008-04-29 10:19:54 15,648 ——w c:\windows\system32\drivers\Awrtrd.sys
+ 2008-04-29 10:20:00 15,648 ——w c:\windows\system32\drivers\NSDriver.sys
- 2005-11-10 19:27:06 49,248 —-a-w c:\windows\system32\java.exe
+ 2009-01-01 12:12:06 144,792 ——w c:\windows\system32\java.exe
- 2005-11-10 19:27:16 49,250 —-a-w c:\windows\system32\javaw.exe
+ 2009-01-01 12:12:06 144,792 ——w c:\windows\system32\javaw.exe
- 2005-11-10 21:03:54 127,078 —-a-w c:\windows\system32\javaws.exe
+ 2009-01-01 12:12:06 148,888 ——w c:\windows\system32\javaws.exe
+ 2008-05-16 10:58:04 12,632 ——w c:\windows\system32\lsdelete.exe
- 2008-12-10 13:30:33 84,661 —-a-w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-01-05 23:43:38 84,661 ——w c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2004-08-04 12:00:00 1,236,480 —-a-w c:\windows\system32\msxml3.dll
+ 2008-09-04 16:42:02 1,106,944 ——w c:\windows\system32\msxml3.dll
- 2008-12-27 17:21:23 62,746 —-a-w c:\windows\system32\perfc009.dat
+ 2009-01-05 20:17:07 62,746 ——w c:\windows\system32\perfc009.dat
- 2008-12-27 17:21:23 401,632 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-05 20:17:07 401,632 ——w c:\windows\system32\perfh009.dat
- 2004-08-04 12:00:00 246,302 —-a-w c:\windows\system32\strmdll.dll
+ 2008-10-03 10:15:47 247,326 ——w c:\windows\system32\strmdll.dll
+ 2009-01-14 13:17:18 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_384.dat
+ 2009-01-14 13:17:23 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_49c.dat
+ 2009-01-14 13:17:23 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_4f8.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PMHandler"="c:\progra~1\Lenovo\PMDRIV~1\PMHandler.exe" [2007-03-16 31840]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 774233]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-04-09 58416]
"TPWAUDAP"="c:\program files\Lenovo\HOTKEY\TpWAudAp.exe" [2006-09-06 54824]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2007-08-23 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-23 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-23 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-23 138008]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2007-02-08 536576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-01 136600]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-28 81920]
"FingerPrintSoftware"="c:\program files\Lenovo Fingerprint Software\fpapp.exe" [2007-05-31 946176]
"LPManager"="c:\progra~1\Lenovo\LENOVO~2\LPMGR.exe" [2007-04-26 120368]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
"AMSG"="c:\progra~1\THINKV~1\AMSG\amsg.exe" [2007-02-01 439856]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-19 196696]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2007-01-31 2618944]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 c:\windows\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2006-08-30 c:\windows\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2006-11-13 561213]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ATFUS]
2007-05-31 21:57 155648 c:\windows\system32\FpWinlogonNp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2006-12-14 02:06 28672 c:\program files\Lenovo\HOTKEY\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0sprecovr \SystemRoot\sprecovr.txt\
0lsdelete
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-04 111184]
R1 PMHler;PMHler;c:\windows\system32\drivers\PMHler.sys [2006-05-24 10240]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2006-09-13 35264]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-04 20560]
R4 FingerprintServer;Fingerprint Server;c:\windows\system32\FpLogonServ.exe [2007-06-22 106496]
R4 FNF5SVC;Fn+F5 Service;c:\program files\Lenovo\HOTKEY\FnF5svc.exe [2007-05-11 54832]
R4 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2007-02-08 569344]
.
Contents of the 'Scheduled Tasks' folder
2008-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-01-14 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 23:54]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://lenovo.live.com
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\vh7nbw9c.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-14 13:19:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1412)
c:\windows\system32\FpWinLogonNp.dll
c:\program files\Lenovo Fingerprint Software\ATCSSINT.dll
c:\program files\Lenovo Fingerprint Software\SharedResources.dll
c:\program files\Lenovo Fingerprint Software\FPResource.dll
c:\program files\Lenovo\Client Security Solution\CSS_Enroll.dll
c:\program files\Lenovo\Client Security Solution\css_banner.dll
c:\windows\system32\cssuserdatadispatcher.dll
c:\windows\system32\tvttsp.dll
c:\windows\system32\tcsrpc.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lenovo\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Lenovo\PM Driver\PMSveH.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Lenovo\System Update\SUService.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files\Common Files\Lenovo\Logger\logmon.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\progra~1\Lenovo\BLUETO~1\BTSTAC~1.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-01-14 13:22:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-14 13:21:59
ComboFix2.txt 2008-12-27 17:40:01
Pre-Run: 47,718,301,696 bytes free
Post-Run: 48,337,428,480 bytes free
356 — E O F — 2008-12-27 20:23:53
———————————————————————————————————————————————————————————————————-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:35:37, on 14/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\FpLogonServ.exe
C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Lenovo\PM Driver\PMSveH.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
C:\PROGRA~1\THINKV~1\AMSG\amsg.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Lenovo\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Lenovo\Client Security Solution\tvtpwm_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [PMHandler] C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FingerPrintSoftware] "C:\Program Files\Lenovo Fingerprint Software\fpapp.exe" \s
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
O4 - HKLM\..\Run: [AMSG] C:\PROGRA~1\THINKV~1\AMSG\amsg.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager… - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - Winlogon Notify: ATFUS - C:\WINDOWS\system32\FpWinLogonNp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Fingerprint Server (FingerprintServer) - AuthenTec,Inc - C:\WINDOWS\system32\FpLogonServ.exe
O23 - Service: Fn+F5 Service (FNF5SVC) - Lenovo. - C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
–
End of file - 11201 bytes