2 more logs
ComboFix 10-12-08.04 - admin 09/12/2010 15:36:15.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3032.2255 [GMT -5:00]
Running from: c:\documents and settings\admin\Desktop\slacker.exe
Command switches used :: c:\documents and settings\admin\Desktop\cfscript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-11-09 to 2010-12-09 )))))))))))))))))))))))))))))))
.
2010-12-09 20:31 . 2010-12-09 20:31 -------- d-----w- C:\HijackThis
2010-12-06 11:36 . 2010-12-06 11:36 -------- d-----w- c:\documents and settings\admin\Application Data\Malwarebytes
2010-12-06 11:36 . 2010-12-06 11:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-12-06 11:36 . 2010-11-29 22:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-06 11:36 . 2010-12-06 11:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-06 11:36 . 2010-11-29 22:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-06 11:26 . 2010-12-06 11:26 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Opera
2010-12-06 01:53 . 2010-12-06 01:53 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-12-06 01:53 . 2010-12-06 01:53 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-12-06 01:53 . 2010-12-06 01:53 -------- d-----w- c:\windows\Logs
2010-11-28 01:32 . 2010-11-28 01:32 -------- d-----w- c:\documents and settings\admin\save
2010-11-27 05:47 . 2010-11-27 05:47 -------- d-----w- c:\program files\ProtectDisc Driver Installer
2010-11-27 05:47 . 2010-11-27 05:47 -------- d-----w- c:\documents and settings\admin\Application Data\ProtectDISC
2010-11-22 16:24 . 2010-11-22 16:24 -------- d-----w- c:\windows\Sun
2010-11-19 18:19 . 2010-09-07 15:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-11-19 18:19 . 2010-09-07 15:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-11-19 18:19 . 2010-09-07 15:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-11-19 18:19 . 2010-09-07 15:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-11-19 18:19 . 2010-09-07 15:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-11-19 18:19 . 2010-09-07 15:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-11-19 18:19 . 2010-09-07 15:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-11-19 18:18 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-11-19 18:18 . 2010-09-07 16:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-11-19 18:18 . 2010-11-19 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-11-17 05:14 . 2009-08-07 00:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-11-16 20:42 . 2010-11-16 20:42 -------- d-----w- c:\documents and settings\admin\Application Data\Microsoft Corporation
2010-11-16 19:22 . 2010-11-16 19:22 -------- d-----w- c:\documents and settings\AL-T400S
2010-11-16 18:13 . 2010-11-26 01:23 -------- d-----w- c:\program files\Microsoft Silverlight
2010-11-16 18:12 . 2010-11-16 18:12 -------- d-----w- c:\program files\Microsoft ASP.NET
2010-11-16 18:12 . 2010-11-16 18:12 -------- d-----w- c:\program files\IIS
2010-11-16 18:12 . 2010-11-16 18:13 617152 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VWDExpress\10.0\1033\ResourceCache.dll
2010-11-16 18:08 . 2010-11-16 18:09 226688 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VBExpress\10.0\1033\ResourceCache.dll
2010-11-16 18:06 . 2010-11-16 18:11 -------- d-----w- c:\program files\Microsoft Visual Studio 10.0
2010-11-16 18:06 . 2010-11-16 18:06 -------- d-----w- c:\program files\Microsoft Help Viewer
2010-11-16 15:10 . 2000-08-05 19:50 57410 ----a-w- c:\windows\system32\axscphst.DLL
2010-11-16 15:10 . 2002-12-17 11:23 528960 ----a-w- c:\windows\system32\dtspump.DLL
2010-11-16 15:10 . 2002-12-17 11:23 1905216 ----a-w- c:\windows\system32\dtspkg.DLL
2010-11-16 15:09 . 2010-11-16 15:09 -------- d-----w- c:\windows\system32\Resources
2010-11-16 15:09 . 2002-12-17 11:25 29248 ----a-w- c:\windows\system32\sqlresld.DLL
2010-11-16 15:09 . 2002-12-17 11:23 119360 ----a-w- c:\windows\system32\dtsffile.DLL
2010-11-16 15:09 . 2002-12-17 11:23 315968 ----a-w- c:\windows\system32\custtask.DLL
2010-11-16 15:09 . 2001-04-17 17:21 65536 ----a-w- c:\windows\system32\custtask.RLL
2010-11-16 15:01 . 2010-04-03 16:51 47968 ----a-w- c:\windows\system32\perf-ReportServer$SECTOR70-rsctr.dll
2010-11-16 15:01 . 2010-04-03 16:51 47456 ----a-w- c:\windows\system32\perf-MSSQL10_50.SECTOR70-sqlagtctr.dll
2010-11-16 15:01 . 2010-04-03 16:51 73568 ----a-w- c:\windows\system32\perf-MSSQL$SECTOR70-sqlctr10.50.1600.1.dll
2010-11-16 08:41 . 2010-11-16 08:41 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-11-16 05:40 . 2010-11-16 16:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-11-16 04:45 . 2010-11-16 04:45 -------- d-----w- c:\documents and settings\admin\Application Data\Avaya
2010-11-16 03:47 . 2010-12-09 00:21 -------- d-----w- c:\documents and settings\admin\Application Data\CoreFTP
2010-11-16 03:46 . 2010-11-16 03:46 -------- d-----w- c:\documents and settings\admin\Local Settings\Application Data\Microsoft_Corporation
2010-11-16 03:38 . 2010-11-16 03:38 438496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VSTAHost\SSIS_ScriptComponent\9.0\1033\ResourceCache.dll
2010-11-16 03:38 . 2010-11-16 03:38 438496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VSTAHost\SSIS_ScriptTask\9.0\1033\ResourceCache.dll
2010-11-16 03:36 . 2010-11-16 03:36 -------- d-----w- c:\windows\system32\RsFx
2010-11-16 03:33 . 2010-11-16 03:33 -------- d-----w- c:\program files\Microsoft Analysis Services
2010-11-16 03:31 . 2010-11-19 18:27 20128 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2010-11-16 03:31 . 2010-11-19 18:27 139872 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2010-11-16 03:29 . 2010-11-16 03:29 -------- d-----w- c:\program files\Common Files\Merge Modules
2010-11-16 03:29 . 2010-11-16 03:29 416 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2010-11-16 03:28 . 2010-11-16 03:28 -------- d-----w- c:\documents and settings\admin\Local Settings\Application Data\Microsoft Help
2010-11-16 03:27 . 2010-11-19 21:24 -------- d-----w- c:\program files\Microsoft SDKs
2010-11-16 03:27 . 2010-11-16 03:29 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2010-11-16 03:27 . 2010-11-19 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-11-16 03:27 . 2010-11-16 03:27 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-11-16 03:27 . 2010-11-16 17:57 -------- d-----w- c:\program files\Microsoft.NET
2010-11-16 03:02 . 2010-11-16 15:21 -------- d-----w- c:\program files\Microsoft SQL Server
2010-11-16 02:50 . 2010-11-16 02:50 -------- d-----w- c:\program files\Common Files\Adobe
2010-11-16 01:11 . 2010-11-16 01:11 53248 ----a-r- c:\documents and settings\admin\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-11-16 01:10 . 2010-11-16 01:10 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-11-16 01:10 . 2010-03-18 09:01 10448 ----a-w- c:\windows\system32\drivers\LBeepKE.sys
2010-11-16 01:10 . 2010-11-16 02:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Logishrd
2010-11-16 01:10 . 2010-11-16 02:09 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-11-16 01:10 . 2010-11-16 01:11 -------- d-----w- c:\documents and settings\admin\Application Data\Logitech
2010-11-16 01:10 . 2010-11-16 01:10 -------- d-----w- c:\documents and settings\admin\Application Data\Logishrd
2010-11-16 00:57 . 2010-11-16 00:57 -------- d-----w- c:\documents and settings\admin\Local Settings\Application Data\Conexant
2010-11-15 22:14 . 2010-11-15 22:14 -------- d-----w- c:\documents and settings\admin\Local Settings\Application Data\Opera
2010-11-15 22:10 . 2010-11-15 22:10 -------- d-----w- c:\windows\IIS Temporary Compressed Files
2010-11-15 21:35 . 2008-04-14 12:00 2560 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2010-11-15 21:23 . 2001-08-17 21:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-11-15 21:23 . 2001-08-17 21:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-11-15 21:23 . 2008-04-14 08:15 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-11-15 21:23 . 2008-04-14 08:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-11-15 16:08 . 2010-11-15 16:08 -------- d-----w- c:\program files\MSXML 4.0
2010-11-14 01:35 . 2010-11-14 01:35 -------- d-----w- c:\windows\system32\Client Security Solution
2010-11-13 17:04 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-11-13 17:04 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-11-13 17:03 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-11-13 17:03 . 2010-09-18 06:53 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2010-11-13 17:03 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-11-13 17:03 . 2010-08-26 13:39 357248 -c----w- c:\windows\system32\dllcache\srv.sys
2010-11-13 17:01 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-11-13 17:00 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-11-13 17:00 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-11-13 17:00 . 2010-08-27 08:02 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-11-13 17:00 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-11-13 17:00 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-11-13 16:59 . 2010-04-28 02:25 2189952 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-11-13 16:59 . 2010-04-27 13:59 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-11-13 16:59 . 2010-04-27 13:05 2066816 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-11-13 16:59 . 2010-04-27 13:05 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-11-13 16:59 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2010-11-13 16:59 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-11-13 16:58 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-11-13 16:55 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-11-13 16:55 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-11-13 16:55 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-11-13 16:55 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-11-13 16:55 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-11-13 16:55 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2010-11-13 16:55 . 2009-02-06 10:39 35328 -c----w- c:\windows\system32\dllcache\sc.exe
2010-11-13 16:55 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-11-13 16:55 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-11-13 16:46 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-11-13 16:43 . 2010-07-12 12:55 218112 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-11-13 16:43 . 2010-08-16 08:45 590848 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2010-11-13 16:43 . 2010-08-26 12:52 5120 ----a-w- c:\windows\system32\xpsp4res.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 20:23 . 2008-07-21 22:49 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-07-21 22:49 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-07-21 22:49 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-07-21 22:49 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-16 16:22 . 2010-09-16 16:22 33536 ----a-w- c:\windows\system32\drivers\tvtfilter.sys
2010-09-16 16:22 . 2010-09-16 16:22 7012 ----a-w- c:\windows\system32\drivers\pmemnt.sys
2010-09-16 16:16 . 2010-09-16 16:10 30144 ----a-w- c:\windows\system32\drivers\psadd.sys
2010-09-16 16:16 . 2010-09-16 16:16 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-16 16:16 . 2010-09-16 16:16 410984 ----a-w- c:\windows\system32\deploytk.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-07_03.13.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-12-09 00:44 . 2010-12-09 00:44 16384 c:\windows\temp\Perflib_Perfdata_5dc.dat
+ 2010-12-08 21:45 . 2010-12-08 21:45 28672 c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\forum\62988167\87ef7290\App_Web_zrdo1amo.dll
+ 2010-12-08 21:45 . 2010-12-08 21:45 15360 c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\forum\62988167\87ef7290\App_Web_ygbdfocp.dll
+ 2010-12-08 21:45 . 2010-12-08 21:45 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\forum\62988167\87ef7290\App_Web_xvs3ql43.dll
+ 2010-12-08 21:45 . 2010-12-08 21:45 53248 c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\forum\62988167\87ef7290\App_Web_lpufl6cu.dll
+ 2010-12-08 21:45 . 2010-12-08 21:45 36864 c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\forum\62988167\87ef7290\App_Web_geumdni0.dll
+ 2010-12-08 21:45 . 2010-12-08 21:45 45056 c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\forum\62988167\87ef7290\App_Web_cl0gz47i.dll
+ 2010-12-08 21:45 . 2010-12-08 21:45 19968 c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\forum\62988167\87ef7290\App_Web_cal6sl4y.dll
+ 2010-12-08 21:39 . 2010-12-08 21:39 40960 c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\forum\62988167\87ef7290\App_Theme_Light.gpxx3opa.dll
+ 2010-11-15 22:10 . 2010-12-09 00:45 215256 c:\windows\system32\inetsrv\MetaBase.bin
+ 2010-12-08 21:45 . 2010-12-08 21:45 110592 c:\windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\forum\62988167\87ef7290\App_Web_vhvp2tfo.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"picon"="c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2009-02-12 357400]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-05-28 61728]
"TpShocks"="TpShocks.exe" [2009-02-03 181536]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2009-03-13 68976]
"LENOVO.TPFNF6R"="c:\program files\Lenovo\HOTKEY\TPFNF6R.exe" [2009-08-20 62752]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-05-11 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-05-11 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-05-11 142872]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-11-24 487424]
"LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2009-01-28 185688]
"LPMailChecker"="c:\progra~1\THINKV~1\PrdCtr\LPMLCHK.exe" [2009-01-28 124248]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-09-16 148888]
"Message Center Plus"="c:\program files\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-05-28 49976]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2009-10-22 421888]
"CreateLMBCShortCut"="c:\program files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe" [2009-12-04 40960]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2009-07-29 425984]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2009-07-29 172032]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2009-03-05 3093816]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 19968]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2009-04-09 03:23 100104 ----a-w- c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 07:37 34344 ----a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"d:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\ThinkPad\\ConnectUtilities\\Access Connections.exe"=
"d:\\Program Files\\CoreFTP\\coreftp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP
eer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [28/01/2009 7:57 PM 20520]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [19/11/2010 1:19 PM 165584]
R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [23/10/2008 3:15 AM 13480]
R2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [24/02/2010 5:22 AM 185472]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [19/11/2010 1:19 PM 17744]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [15/11/2010 8:10 PM 10448]
R2 Lenovo.micmute;Lenovo Microphone Mute;c:\program files\Lenovo\HOTKEY\micmute.exe [05/10/2009 9:21 PM 45424]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [16/09/2010 11:19 AM 53248]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [13/03/2009 4:47 PM 12560]
R2 TPHKSVC;On Screen Display;c:\program files\Lenovo\HOTKEY\TPHKSVC.exe [05/10/2009 9:21 PM 62320]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [24/11/2008 5:34 PM 520192]
R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [16/09/2010 11:04 AM 2058776]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [16/09/2010 10:51 AM 243856]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [22/02/2008 5:54 PM 37312]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 1:16 PM 130384]
S2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [09/05/2008 7:50 PM 360448]
S3 MSSQL$SECTOR70;SQL Server (SECTOR70);d:\sector70\MSSQL10_50.SECTOR70\MSSQL\Binn\sqlservr.exe [03/04/2010 11:56 AM 42884448]
S3 MSSQLFDLauncher$SECTOR70;SQL Full-text Filter Daemon Launcher (SECTOR70);d:\sector70\MSSQL10_50.SECTOR70\MSSQL\Binn\fdlauncher.exe [03/04/2010 11:56 AM 28512]
S3 ReportServer$SECTOR70;SQL Server Reporting Services (SECTOR70);d:\sector70\MSRS10_50.SECTOR70\Reporting Services\ReportServer\bin\ReportingServicesService.exe [03/04/2010 11:56 AM 1177952]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [25/04/2008 10:15 AM 1120752]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 1:16 PM 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [03/04/2010 2:56 PM 44896]
S4 RsFx0150;RsFx0150 Driver;c:\windows\system32\drivers\RsFx0150.sys [03/04/2010 2:02 PM 240608]
S4 SQLAgent$SECTOR70;SQL Server Agent (SECTOR70);d:\sector70\MSSQL10_50.SECTOR70\MSSQL\Binn\SQLAGENT.EXE [03/04/2010 11:56 AM 367456]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
2010-09-16 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PCDR5\pcdr5cuiw32.exe [2009-10-06 21:55]
2010-12-09 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2010-09-16 16:04]
.
.
------- Supplementary Scan -------
.
TCP: {8D2A77B2-899C-40C2-A2DA-6D120A92C1AE} = 169.254.11.203
.
- - - - ORPHANS REMOVED - - - -
Notify-ACNotify - ACNotify.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-12-09 15:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(756)
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\qlbase.dll
c:\program files\ThinkVantage Fingerprint Software\ps2css.dll
c:\windows\system32\igfxdev.dll
c:\program files\Lenovo\HOTKEY\notifyf2.dll
- - - - - - - > 'lsass.exe'(812)
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll
- - - - - - - > 'explorer.exe'(3852)
c:\windows\system32\WININET.dll
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\windows\system32\ieframe.dll
c:\program files\Common Files\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\msi.dll
.
Completion time: 2010-12-09 15:41:18
ComboFix-quarantined-files.txt 2010-12-09 20:41
ComboFix2.txt 2010-12-07 03:16
Pre-Run: 27,962,916,864 bytes free
Post-Run: 28,017,590,272 bytes free
- - End Of File - - 93D0BDAC3135FB965292F8BFDE15CAB5
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:45:02 PM, on 09/12/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17091)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlk.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Program Files\Lenovo\HOTKEY\TPFNF6R.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
D:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Password Manager Browser Helper Object - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [picon] "C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" -startup
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [LENOVO.TPFNF6R] C:\Program Files\Lenovo\HOTKEY\TPFNF6R.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Message Center Plus] C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe /start
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [CreateLMBCShortCut] "C:\Program Files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe"
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra 'Tools' menuitem: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1289871982729
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D2A77B2-899C-40C2-A2DA-6D120A92C1AE}: NameServer = 169.254.11.203
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: avast! Antivirus - AVAST Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lenovo Microphone Mute (Lenovo.micmute) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Power Manager DBC Service - Unknown owner - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Intel(R) PROSet/Wireless WiFi Service (S24EventMonitor) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TSS Core Service (TSSCoreService) - Lenovo - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe
O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: TVT Windows Update Monitor (TVT_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel Corporation - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
--
End of file - 11432 bytes