Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

infected, but not able to find source


  • This topic is locked This topic is locked
15 replies to this topic

#1 cpm0813

cpm0813

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:36 AM

Posted 13 February 2009 - 11:22 AM

I know a good amount about computer security, and I am usually able to find and get rid of any infections/malware I may get, but this time I can't seem to find it. I found an autorun.inf file in my C:\ directory, which I got rid of, in addition to the file it was telling to run. I cannot run Spybot or Microsoft Windows Malicious Software Removal Tool unless I rename them. I even did a manual update of Spybot since I cannot access its website, but it only found cookies. Updated Ad-aware also found nothing. My browser is often trying to redirect. Even in safe mode, which I'm currently in, the problems continue. Thanks.


DDS (Ver_09-02-01.01) - NTFSx86 NETWORK
Run by Administrator at 11:15:21.51 on Fri 02/13/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2014.1646 [GMT -5:00]

AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uWindow Title = Windows Internet Explorer
mStart Page = about:blank
mWindow Title = Windows Internet Explorer
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\2.1.1119.1736\swg.dll
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
mRun: [LPManager] c:\progra~1\thinkv~1\prdctr\LPMGR.exe
mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog
mRun: [AwaySch] c:\program files\lenovo\awaytask\AwaySch.EXE
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe
mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray
mRun: [TpShocks] TpShocks.exe
mRun: [Run StartupMonitor] StartupMonitor.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe
mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe
mRun: [<NO NAME>]
mRun: [TPFNF7] c:\progra~1\lenovo\npdirect\TPFNF7SP.exe /r
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Digital Line Detect.lnk.disabled
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1D082E71-DF20-4AAF-863B-596428C49874} - hxxp://www.worldwinner.com/games/v50/tpir/tpir.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2DAD3559-2923-4935-AD49-B673D2539944} - hxxp://www-307.ibm.com/pc/support/acpir.cab
DPF: {2E062718-4B2D-4926-9E31-36ECB6F4F273} - hxxp://www.worldwinner.com/games/v46/nhltrivia/nhltrivia.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} - hxxp://www.worldwinner.com/games/v47/solitairerush/solitairerush.cab
DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} - hxxp://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - hxxp://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188772002578
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189021432906
DPF: {74FFE28D-2378-11D5-990C-006094235084} - hxxp://www-307.ibm.com/pc/support/IbmEgath.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} - hxxp://www.worldwinner.com/games/v46/grandslam/grandslamtrivia.cab
DPF: {C26027F5-C7EF-4CC1-9637-B514BCF8BF4E} - hxxp://www.arcadetown.com/swf/scorchanisland/saionline.cab
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} - hxxp://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} - hxxp://games.bigfishgames.com/en_cinematycoon/online/cinematycoon.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.station.sony.com/games/en/031/popcaploader_v10.cab
Notify: ACNotify - ACNotify.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: psfus - c:\windows\system32\psqlpwd.dll
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll
LSA: Notification Packages = scecli ACGina psqlpwd ACGina

============= SERVICES / DRIVERS ===============

R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2008-5-14 114728]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2008-5-14 19496]
S1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2007-9-5 11520]
S1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2007-9-5 4224]
S1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2008-12-17 53752]
S1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
S1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
S1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2007-9-5 4442]
S1 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [2007-12-5 46144]
S2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104]
S2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576]
S2 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.dll [2005-7-27 10829]
S2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2005-3-7 37376]
S2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2005-3-7 21504]
S2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2005-3-7 674304]
S2 nidimk;nidimk;c:\windows\system32\drivers\nidimk.dll [2006-7-13 159232]
S2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2005-3-7 50688]
S2 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfk.dll [2006-7-19 200704]
S2 niemrk;niemrk;c:\windows\system32\drivers\niemrk.dll [2006-7-20 370176]
S2 nifslk;nifslk;c:\windows\system32\drivers\nifslk.dll [2006-7-16 81920]
S2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2005-3-7 30208]
S2 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpk.dll [2006-7-15 20480]
S2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmk.dll [2006-7-18 71680]
S2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2005-3-7 111616]
S2 niswdk;niswdk;c:\windows\system32\drivers\niswdk.dll [2006-8-23 490496]
S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2007-2-23 11552]
S2 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrk.dll [2006-7-20 1746432]
S2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\thinkpad\utilities\PWMDBSVC.exe [2008-10-14 94208]
S2 smihlp2;SMI Helper Driver (smihlp2);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2007-8-14 10896]
S2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-6-6 1821376]
S2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\lenovo\rescue and recovery\rrpservice.exe [2007-12-5 520192]
S2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\lenovo\rescue and recovery\UpdateMonitor.exe [2007-12-5 360448]
S2 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.dll [2006-7-16 19968]
S3 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-9-6 99376]
S3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090212.003\naveng.sys [2009-2-12 89104]
S3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090212.003\navex15.sys [2009-2-12 876112]
S3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrk.dll [2006-7-15 171520]
S3 nidevldu;nidevldu;system32\nipalsm.exe --> system32\nipalsm.exe [?]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsark.dll [2006-7-20 648192]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrk.dll [2006-7-20 500224]
S3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2k.dll [2006-7-13 248832]
S3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrk.dll [2006-7-15 137728]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [2006-6-5 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [2006-6-5 151683]
S3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstsk.dll [2006-7-15 51712]
S3 niscdk;niscdk;c:\windows\system32\drivers\niscdk.dll [2006-7-15 506880]
S3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigk.dll [2006-7-16 240128]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftk.dll [2006-7-15 164864]
S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2006-7-18 51200]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdk.dll [2006-7-15 43008]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrk.dll [2006-7-20 1026560]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2k.dll [2006-6-5 163328]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrk.dll [2006-7-15 111616]
S3 nitiork;nitiork;c:\windows\system32\drivers\nitiork.dll [2006-7-15 790528]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2007-2-22 11552]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2007-2-23 11552]
S3 NIVIUSBK;NI-VISA USB Driver;c:\windows\system32\drivers\NiViUsbK.sys [2007-2-22 45856]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrk.dll [2006-7-20 434688]
S3 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007;c:\program files\solidworks\cosmos\floworks\bincfw\StandAloneSlv.exe [2008-6-4 237568]
S3 Remote Solver for COSMOSFloWorks 2008;Remote Solver for COSMOSFloWorks 2008;c:\program files\solidworks\cosmos\floworks\bincfw\StandAloneSlv.exe [2008-6-4 237568]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-6-6 116928]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-5-22 30336]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]

=============== Created Last 30 ================

2009-02-13 10:50 <DIR> --d----- c:\program files\Trend Micro
2009-02-12 18:54 <DIR> --ds---- c:\documents and settings\administrator\UserData
2009-02-12 12:47 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2009-02-12 12:47 <DIR> --d----- c:\documents and settings\administrator\.housecall6.6
2009-02-12 12:16 <DIR> --d----- c:\documents and settings\Administrator
2009-02-11 20:25 0 a------- c:\windows\system32\budda
2009-02-11 20:20 <DIR> --d----- c:\program files\PlayFirst
2009-02-09 10:17 53,248 a------- c:\windows\system32\dnssd.dll
2009-02-09 10:17 <DIR> --d----- c:\program files\Bonjour
2009-02-09 10:16 <DIR> --d----- c:\program files\TiVo
2009-02-09 10:16 <DIR> --d----- c:\program files\common files\TiVo Shared
2009-02-09 10:16 <DIR> --d----- c:\docume~1\alluse~1\applic~1\TiVo
2009-01-29 16:11 <DIR> --d----- c:\program files\GPLGS
2009-01-29 16:11 87,552 a------- c:\windows\system32\cpwmon2k.dll
2009-01-29 16:11 <DIR> --d----- c:\program files\Acro Software
2009-01-29 11:28 10,240 a------- c:\windows\system32\virport.dll
2009-01-19 17:21 <DIR> --d----- c:\program files\AdgarTheBarbarian
2009-01-19 17:03 <DIR> --d----- c:\windows\SxsCaPendDel
2009-01-16 16:41 <DIR> --d----- c:\program files\Atari

==================== Find3M ====================

2009-02-12 18:26 43,447 a------- c:\windows\system32\nvModes.dat
2008-03-18 15:33 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat
2003-09-16 01:19 99,544 a------- c:\windows\inf\virprn.exe
2003-09-16 01:19 18,950 a------- c:\windows\inf\virpntd.dll
2003-09-16 01:19 10,240 a------- c:\windows\inf\virport.dll
2003-09-16 01:19 90,624 a------- c:\windows\inf\prtproc.dll

============= FINISH: 11:15:50.10 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:36 PM

Posted 20 February 2009 - 03:56 PM

Hi,

Sorry for delayed response. Forums have been really busy. If you still need help with this post a fresh dds log, please.

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#3 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:36 PM

Posted 26 February 2009 - 01:27 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact a Staff member. Include the address of this thread in your request. This applies only to the original topic starter. Should you have a new issue, please start a New Topic.

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#4 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:36 PM

Posted 03 March 2009 - 01:35 PM

Topic re-opened upon user's request.

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#5 cpm0813

cpm0813
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:36 AM

Posted 03 March 2009 - 02:14 PM

The problems had gone away before. I used MBAM, SpyBot, AntiVirus, to clean it, I thought. Computer seemed fine for last 2 weeks; however, I have been hibernating since then. I restarted two days ago and problems started up. Now, for first 11 min of system up-time, system seems ok. Then, once 11 min passes, all http traffic stops working. Tried both IE and FireFox. Problem is on both wired and wireless. https, AIM, ping, etc are fine, but http stops working. In safe mode w/ networking, it's fine, but not normal mode. Spybot in safe mode w/ networking yesterday found Win32.TDSS.rtk; I believe antivirus found TDSS previously also. The exact file found was system32\gaopdxcounter. It also found multiple registry entries, all of which had gaopdx.serv.sys in them. I think I might have run it under the Administrator account, but I'm not sure.


DDS (Ver_09-02-01.01) - NTFSx86
Run by Avi Mirchandani at 13:55:05.96 on Tue 03/03/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2014.1299 [GMT -5:00]

AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe
C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\PWMUIAux.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Avi Mirchandani\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://rpinfo.rpi.edu/
mStart Page = about:blank
mWindow Title = Windows Internet Explorer
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog
mRun: [AwaySch] c:\program files\lenovo\awaytask\AwaySch.EXE
mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [TpShocks] TpShocks.exe
mRun: [Run StartupMonitor] StartupMonitor.exe
mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe
mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [vptray] c:\progra~1\symant~1\\vptray.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
StartupFolder: c:\docume~1\avimir~1\startm~1\programs\startup\window~1.lnk - c:\windows\system32\taskmgr.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1D082E71-DF20-4AAF-863B-596428C49874} - hxxp://www.worldwinner.com/games/v50/tpir/tpir.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2DAD3559-2923-4935-AD49-B673D2539944} - hxxp://www-307.ibm.com/pc/support/acpir.cab
DPF: {2E062718-4B2D-4926-9E31-36ECB6F4F273} - hxxp://www.worldwinner.com/games/v46/nhltrivia/nhltrivia.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} - hxxp://www.worldwinner.com/games/v47/solitairerush/solitairerush.cab
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} - hxxp://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - hxxp://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188772002578
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189021432906
DPF: {74FFE28D-2378-11D5-990C-006094235084} - hxxp://www-307.ibm.com/pc/support/IbmEgath.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} - hxxp://www.worldwinner.com/games/v46/grandslam/grandslamtrivia.cab
DPF: {B9F79165-A264-4C4A-A211-133A5E8D647F} - hxxp://support.f-secure.com/enu/home/onlineservices/fshc/fscax.cab
DPF: {C26027F5-C7EF-4CC1-9637-B514BCF8BF4E} - hxxp://www.arcadetown.com/swf/scorchanisland/saionline.cab
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} - hxxp://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} - hxxp://games.bigfishgames.com/en_cinematycoon/online/cinematycoon.cab
Notify: ACNotify - ACNotify.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: psfus - c:\program files\thinkvantage fingerprint software\psqlpwd.dll
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll
LSA: Notification Packages = scecli ACGina psqlpwd ACGina c:\program files\thinkvantage fingerprint software\psqlpwd.dll

============= SERVICES / DRIVERS ===============

R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2008-5-14 114728]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2008-5-14 19496]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2007-9-5 11520]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2007-9-5 4224]
R1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2008-12-17 53752]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2007-9-5 4442]
R1 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [2007-12-5 46144]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576]
R2 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.dll [2005-7-27 10829]
R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2005-3-7 37376]
R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2005-3-7 21504]
R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2005-3-7 674304]
R2 nidimk;nidimk;c:\windows\system32\drivers\nidimk.dll [2006-7-13 159232]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2005-3-7 50688]
R2 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfk.dll [2006-7-19 200704]
R2 niemrk;niemrk;c:\windows\system32\drivers\niemrk.dll [2006-7-20 370176]
R2 nifslk;nifslk;c:\windows\system32\drivers\nifslk.dll [2006-7-16 81920]
R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2005-3-7 30208]
R2 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpk.dll [2006-7-15 20480]
R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmk.dll [2006-7-18 71680]
R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2005-3-7 111616]
R2 niswdk;niswdk;c:\windows\system32\drivers\niswdk.dll [2006-8-23 490496]
R2 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrk.dll [2006-7-20 1746432]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\thinkpad\utilities\PWMDBSVC.exe [2008-10-14 53248]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2008-11-21 12560]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-6-6 1821376]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\lenovo\rescue and recovery\rrpservice.exe [2007-12-5 520192]
R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\lenovo\rescue and recovery\UpdateMonitor.exe [2007-12-5 360448]
R2 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.dll [2006-7-16 19968]
R2 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-27 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090303.003\naveng.sys [2009-3-3 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090303.003\navex15.sys [2009-3-3 876144]
R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrk.dll [2006-7-15 171520]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2k.dll [2006-7-13 248832]
R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrk.dll [2006-7-15 137728]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstsk.dll [2006-7-15 51712]
R3 niscdk;niscdk;c:\windows\system32\drivers\niscdk.dll [2006-7-15 506880]
R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigk.dll [2006-7-16 240128]
R3 nitiork;nitiork;c:\windows\system32\drivers\nitiork.dll [2006-7-15 790528]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-5-22 30336]
S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2007-2-23 11552]
S3 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664]
S3 AJDIQ;AJDIQ;c:\docume~1\avimir~1\locals~1\temp\AJDIQ.exe [2009-3-3 428928]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsark.dll [2006-7-20 648192]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrk.dll [2006-7-20 500224]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [2006-6-5 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [2006-6-5 151683]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftk.dll [2006-7-15 164864]
S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2006-7-18 51200]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdk.dll [2006-7-15 43008]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrk.dll [2006-7-20 1026560]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2k.dll [2006-6-5 163328]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrk.dll [2006-7-15 111616]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2007-2-22 11552]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2007-2-23 11552]
S3 NIVIUSBK;NI-VISA USB Driver;c:\windows\system32\drivers\NiViUsbK.sys [2007-2-22 45856]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrk.dll [2006-7-20 434688]
S3 OMYWDHJR;OMYWDHJR;c:\docume~1\avimir~1\locals~1\temp\OMYWDHJR.exe [2009-3-3 539520]
S3 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007;c:\program files\solidworks\cosmos\floworks\bincfw\StandAloneSlv.exe [2008-6-4 237568]
S3 Remote Solver for COSMOSFloWorks 2008;Remote Solver for COSMOSFloWorks 2008;c:\program files\solidworks\cosmos\floworks\bincfw\StandAloneSlv.exe [2008-6-4 237568]
S3 RKLGFNIRGCM;RKLGFNIRGCM;c:\docume~1\avimir~1\locals~1\temp\RKLGFNIRGCM.exe [2009-3-3 584576]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-6-6 116928]
S4 nidevldu;nidevldu;system32\nipalsm.exe --> system32\nipalsm.exe [?]

=============== Created Last 30 ================

2009-03-03 12:50 0 a------- c:\windows\system32\WT
2009-03-03 12:42 <DIR> --ds---- c:\documents and settings\avi mirchandani\UserData
2009-03-03 12:26 <DIR> --d----- C:\RootRepeal
2009-03-03 12:18 <DIR> a-dshr-- C:\autorun.inf
2009-03-02 14:57 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-02 12:51 <DIR> --d----- c:\program files\Support Tools
2009-02-22 12:43 <DIR> --d----- c:\program files\common files\CANON
2009-02-22 12:43 <DIR> --d----- c:\program files\Canon
2009-02-16 13:44 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-15 18:25 1,324 a------- c:\windows\system32\d3d9caps.dat
2009-02-15 13:21 <DIR> --d----- c:\program files\common files\ThinkVantage Fingerprint Software
2009-02-15 13:21 <DIR> --d----- c:\program files\common files\SPBA
2009-02-15 13:18 3,632,384 a------- c:\windows\system32\drivers\NETw5x32.sys
2009-02-15 13:18 2,756,608 a------- c:\windows\system32\NETw5r32.dll
2009-02-15 13:18 663,552 a------- c:\windows\system32\NETw5c32.dll
2009-02-15 13:17 <DIR> --d----- c:\docume~1\avimir~1\applic~1\Intel
2009-02-15 13:17 <DIR> --d----- c:\program files\common files\Intel
2009-02-14 11:26 <DIR> --d----- c:\windows\ERUNT
2009-02-14 10:48 <DIR> --d----- c:\docume~1\avimir~1\applic~1\Malwarebytes
2009-02-13 23:30 <DIR> --d----- C:\SDFix
2009-02-13 15:26 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-13 15:26 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-13 15:26 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-02-13 15:26 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-13 11:53 <DIR> --d----- C:\fixwareout
2009-02-13 10:50 <DIR> --d----- c:\program files\Trend Micro
2009-02-12 12:47 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2009-02-11 20:25 0 a------- c:\windows\system32\budda
2009-02-11 20:20 <DIR> --d----- c:\program files\PlayFirst
2009-02-09 10:17 53,248 a------- c:\windows\system32\dnssd.dll
2009-02-09 10:17 <DIR> --d----- c:\program files\Bonjour
2009-02-09 10:16 <DIR> --d----- c:\program files\TiVo
2009-02-09 10:16 <DIR> --d----- c:\program files\common files\TiVo Shared
2009-02-09 10:16 <DIR> --d----- c:\docume~1\alluse~1\applic~1\TiVo

==================== Find3M ====================

2009-02-12 18:26 43,447 a------- c:\windows\system32\nvModes.dat
2008-12-04 19:26 453,152 a------- c:\windows\system32\NVUNINST.EXE
2008-03-18 15:33 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat
2003-09-16 01:19 99,544 a------- c:\windows\inf\virprn.exe
2003-09-16 01:19 18,950 a------- c:\windows\inf\virpntd.dll
2003-09-16 01:19 10,240 a------- c:\windows\inf\virport.dll
2003-09-16 01:19 90,624 a------- c:\windows\inf\prtproc.dll

============= FINISH: 13:55:50.07 ===============

Attached Files



#6 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:36 PM

Posted 03 March 2009 - 02:32 PM

Hi

Ok. Let's start cleaning then :thumbup2:


Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
  • Run Spybot-S&D in Advanced Mode
  • If it is not already set to do this, go to the Mode menu
    select
    Advanced Mode
  • On the left hand side, click on Tools
  • Then click on the Resident icon in the list
  • Uncheck
    Resident TeaTimer
    and OK any prompts.
  • Restart your computer
Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  • Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds.txt log.


A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

Edited by Blade81, 03 March 2009 - 02:32 PM.

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#7 cpm0813

cpm0813
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:36 AM

Posted 04 March 2009 - 12:53 PM

Unfortunately, the 11 min for http traffic condition remains. I know my anti-virus and anti-malware software is still off, left it off for anything else you want me to do.


ComboFix 09-03-03.01 - Avi Mirchandani 2009-03-04 12:18:14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2014.1426 [GMT -5:00]
Running from: c:\documents and settings\Avi Mirchandani\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-02-04 to 2009-03-04 )))))))))))))))))))))))))))))))
.

2009-03-03 12:50 . 2009-03-03 12:50 0 --a------ c:\windows\system32\WT
2009-03-03 12:42 . 2009-03-03 12:42 <DIR> d---s---- c:\documents and settings\Avi Mirchandani\UserData
2009-03-03 12:26 . 2009-03-03 12:26 <DIR> d-------- C:\RootRepeal
2009-03-02 14:57 . 2009-03-02 14:57 <DIR> d----c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-02 13:24 . 2009-03-02 13:24 <DIR> d-------- C:\ERDNT
2009-03-02 12:51 . 2009-03-02 12:51 <DIR> d-------- c:\program files\Support Tools
2009-02-22 12:43 . 2009-02-22 12:43 <DIR> d-------- c:\program files\Common Files\CANON
2009-02-22 12:43 . 2009-02-22 12:44 <DIR> d-------- c:\program files\Canon
2009-02-22 12:30 . 2009-02-22 12:45 <DIR> d-------- c:\documents and settings\Avi Mirchandani\Application Data\Canon
2009-02-16 13:44 . 2009-02-16 13:44 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-15 18:25 . 2009-03-03 17:33 1,324 --a------ c:\windows\system32\d3d9caps.dat
2009-02-15 13:21 . 2009-02-15 13:21 <DIR> d-------- c:\program files\Common Files\ThinkVantage Fingerprint Software
2009-02-15 13:21 . 2009-02-15 13:21 <DIR> d-------- c:\program files\Common Files\SPBA
2009-02-15 13:18 . 2009-02-15 13:18 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\Intel
2009-02-15 13:18 . 2009-02-15 13:18 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Intel
2009-02-15 13:18 . 2008-08-28 23:34 3,632,384 --a------ c:\windows\system32\drivers\NETw5x32.sys
2009-02-15 13:18 . 2008-06-20 10:33 2,756,608 --a------ c:\windows\system32\NETw5r32.dll
2009-02-15 13:18 . 2008-06-20 10:32 663,552 --a------ c:\windows\system32\NETw5c32.dll
2009-02-15 13:17 . 2009-02-15 13:17 <DIR> d-------- c:\program files\Common Files\Intel
2009-02-15 13:17 . 2009-02-15 13:17 <DIR> d-------- c:\documents and settings\LocalService\Application Data\Intel
2009-02-15 13:17 . 2009-02-15 13:17 <DIR> d-------- c:\documents and settings\Avi Mirchandani\Application Data\Intel
2009-02-15 13:17 . 2009-02-15 13:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Intel
2009-02-14 11:26 . 2009-02-14 11:26 <DIR> d-------- c:\windows\ERUNT
2009-02-14 10:48 . 2009-02-14 10:48 <DIR> d-------- c:\documents and settings\Avi Mirchandani\Application Data\Malwarebytes
2009-02-13 23:30 . 2009-02-14 21:38 <DIR> d-------- C:\SDFix
2009-02-13 15:26 . 2009-02-13 23:26 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-13 15:26 . 2009-02-13 15:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-13 15:26 . 2009-02-13 15:26 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-13 15:26 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-13 15:26 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-13 11:53 . 2009-02-13 11:58 <DIR> d-------- C:\fixwareout
2009-02-13 10:50 . 2009-02-13 10:50 <DIR> d-------- c:\program files\Trend Micro
2009-02-12 18:54 . 2009-02-12 18:54 <DIR> d---s---- c:\documents and settings\Administrator\UserData
2009-02-12 12:47 . 2009-02-12 14:27 <DIR> d-------- c:\documents and settings\Administrator\.housecall6.6
2009-02-12 12:47 . 2009-02-12 12:47 102,664 --a------ c:\windows\system32\drivers\tmcomm.sys
2009-02-12 12:22 . 2009-02-12 12:23 <DIR> d-------- c:\program files\Windows Live Safety Center
2009-02-12 12:16 . 2009-02-14 10:40 <DIR> d-------- c:\documents and settings\Administrator
2009-02-11 20:25 . 2009-02-11 20:25 0 --a------ c:\windows\system32\budda
2009-02-11 20:21 . 2009-02-11 20:21 <DIR> d-------- c:\documents and settings\Avi Mirchandani\Application Data\PlayFirst
2009-02-11 20:20 . 2009-02-11 20:20 <DIR> d-------- c:\program files\PlayFirst
2009-02-11 20:08 . 2009-02-11 20:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\TEMP
2009-02-09 10:17 . 2009-02-09 10:17 <DIR> d-------- c:\program files\Bonjour
2009-02-09 10:17 . 2009-01-27 15:52 53,248 --a------ c:\windows\system32\dnssd.dll
2009-02-09 10:16 . 2009-02-09 10:16 <DIR> d-------- c:\program files\TiVo
2009-02-09 10:16 . 2009-02-09 10:16 <DIR> d-------- c:\program files\Common Files\TiVo Shared
2009-02-09 10:16 . 2009-02-09 10:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\TiVo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-04 17:06 --------- d-----w c:\program files\Symantec AntiVirus
2009-03-03 22:37 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\.purple
2009-02-27 16:39 --------- d-----w c:\program files\Cheat Engine
2009-02-16 18:44 --------- d-----w c:\program files\Java
2009-02-15 19:09 --------- d-----w c:\program files\Defraggler
2009-02-15 18:52 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-15 18:51 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\Lenovo
2009-02-15 18:31 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-15 18:22 --------- d-----w c:\program files\ThinkVantage Fingerprint Software
2009-02-15 18:20 --------- d-----w c:\documents and settings\All Users\Application Data\UIB
2009-02-15 18:19 --------- d-----w c:\documents and settings\All Users\Application Data\Lenovo
2009-02-15 18:17 --------- d-----w c:\program files\Intel
2009-02-15 17:51 --------- d-----w c:\documents and settings\All Users\Application Data\PCDr
2009-02-15 14:51 --------- d-----w c:\program files\PCDR5
2009-02-10 20:57 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\Move Networks
2009-01-29 23:30 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\Skype
2009-01-29 23:28 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\skypePM
2009-01-29 21:11 --------- d-----w c:\program files\GPLGS
2009-01-29 21:11 --------- d-----w c:\program files\Acro Software
2009-01-20 18:42 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\gtk-2.0
2009-01-19 22:21 --------- d-----w c:\program files\AdgarTheBarbarian
2009-01-16 22:21 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\Atari
2009-01-16 21:41 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-16 21:41 --------- d-----w c:\program files\Atari
2009-01-15 16:17 --------- d-----w c:\program files\CCleaner
2009-01-08 15:16 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\IM
2009-01-05 23:55 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\SPORE
2008-03-18 20:33 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2004-03-15 21:51 114,688 ----a-w c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2003-05-01 13:36 114,688 ----a-w c:\program files\internet explorer\plugins\LV7ActiveXControl.dll
2006-01-23 14:32 131,072 ----a-w c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2006-06-07 18:40 132,848 ----a-w c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-12-04 16:38 3431224 --a------ c:\program files\MozyHome\mozyshell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-12-04 16:38 3431224 --a------ c:\program files\MozyHome\mozyshell.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-05 13549568]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2008-11-21 385024]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-03-17 208896]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-09-30 68976]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-10-27 143360]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-10-27 425984]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-05 86016]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2008-07-03 118784]
"nwiz"="nwiz.exe" [2008-12-05 c:\windows\system32\nwiz.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]
"TpShocks"="TpShocks.exe" [2008-06-06 c:\windows\system32\TpShocks.exe]
"Run StartupMonitor"="StartupMonitor.exe" [2000-05-20 c:\windows\StartupMonitor.exe]

c:\documents and settings\Avi Mirchandani\Start Menu\Programs\Startup\
Windows Task Manager.lnk - c:\windows\system32\taskmgr.exe [2004-08-04 135680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2008-11-21 00:35 95496 c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 15:37 34344 c:\program files\Lenovo\HOTKEY\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2008-08-08 19:14 28672 c:\program files\Lenovo\HOTKEY\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2008-10-27 09:57 32768 c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ACGina psqlpwd c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk.disabled
backup=c:\windows\pss\Digital Line Detect.lnk.disabledCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
--a------ 2008-03-20 11:46 217544 c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
--a------ 2008-03-18 01:06 1848648 c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
--a------ 2008-12-12 01:31 722256 c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZEJMNAP]
--------- 2007-04-27 01:33 243248 c:\progra~1\ThinkPad\UTILIT~1\EZEJMNAP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SolidWorks_CheckForUpdates]
--a------ 2008-06-14 04:55 6862104 c:\program files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2007-08-08 08:13 831488 c:\program files\Analog Devices\SoundMAX\SMax4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2008-04-24 16:53 1036288 c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2009-02-16 13:44 148888 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoNotify]
--a------ 2009-01-27 16:18 425472 c:\program files\TiVo\Desktop\TiVoNotify.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoServer]
--a------ 2009-01-27 16:21 2143232 c:\program files\TiVo\Desktop\TiVoServer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPFNF7]
--------- 2008-07-31 04:01 60192 c:\progra~1\Lenovo\NPDIRECT\tpfnf7sp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TranscodingService]
--a------ 2009-01-27 16:03 520192 c:\program files\TiVo\Desktop\TranscodingService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
--a------ 2008-03-04 09:34 487424 c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
"LPMailChecker"=c:\progra~1\THINKV~1\PrdCtr\LPMLCHK.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"=
"c:\\Program Files\\ThinkPad\\ConnectUtilities\\ACMainGUI.exe"=
"c:\\Program Files\\Maple 10\\jre\\bin\\maple.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Quake 3\\quake3.exe"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\rise.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cdsdoc.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cdsinfo.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cdsmps.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cdsMsgServer.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cdsNameServer.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cdsRemshClient.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cdsRunHidden.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cdsUnzip.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cdswhich.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cdsZip.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\cds_root.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\clsAdminTool.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\clsbd.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\clu.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\dregprint.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\mpsinfo.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\nmp.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\nmppath.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\obServer.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\van.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\bin\\versionviewer.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\capture\\capture.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\capture\\comp16.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\capture\\pcadi.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\capture\\pspiceexplorersrvr.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\capture\\pstswp.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\capture\\regsvr32.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\capture\\sch2cap.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\capture\\SETBROWS.EXE"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\capture\\tutorial\\CAPTUTOR.EXE"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\cdsdoc\\bin\\cdsdocIndexer.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\cdsdoc\\bin\\obServer.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\dfII\\bin\\cdsservipc.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\dfII\\bin\\skill.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\dfII\\bin\\skill_g.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\fet\\bin\\mkdefcfg.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\fet\\bin\\versiontool.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\javaws-1_2_0_02-windows-i586-i.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\java.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\javaw.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\jpicpl32.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\keytool.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\kinit.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\klist.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\ktab.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\orbd.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\policytool.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\rmid.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\rmiregistry.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\servertool.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\jre\\bin\\tnameserv.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\fvupdateutil.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\gcdin.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\idfin.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\layout.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\libcat.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\lsession.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxascx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxdxf.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxeco.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxfnetx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxminx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxorcad.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxp99x.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxpadx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxpcadx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxprotx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxstrx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\maxtangx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\mfceco.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\padx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\pcadx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\pcb2max.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\prcat.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\protx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\searchTool.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\setbrows.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\specin.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\strx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\tangx.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\tomax.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\tospec.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\update90.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\sroute\\batch32.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\sroute\\sroute.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\layout\\tutorial\\laytutor.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pcb\\bin\\specctra.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\IndiceFileGeneration.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\Magneticdesigner.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\modeled.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\MrkSrvr.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\pspice.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\pspiceaa.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\pspiceexplorersrvr.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\psp_cmd.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\regsvr32.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\simmgr.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\simsrvr.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\pspice\\stmed.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\specctra\\bin\\specctra.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\bin\\cdsdocIndexer.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\bin\\merge.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\bin\\mkvdk.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\bin\\search.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\bin\\setup.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\bin\\v_uninst.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\callback.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\filter.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\htmlini.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\htmserv.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\index.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\jstree.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\jvtree.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\kvoop.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\regsvr32.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\summary.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\verity\\_nti40\\filters\\viewers\\amovie.exe"=
"c:\\OrCAD\\OrCAD_10.5_Demo\\tools\\specctra\\bin\\specctra.com"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\K1RFD\\EchoLink\\EchoLink.exe"=
"c:\\Documents and Settings\\Avi Mirchandani\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Avi Mirchandani\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Avi Mirchandani\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 0 (0x0)

R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2008-05-14 114728]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2008-05-14 19496]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2007-09-05 11520]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2007-09-05 4224]
R1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2008-12-17 53752]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2007-09-05 4442]
R1 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [2007-12-05 46144]
R2 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.dll [2005-07-27 10829]
R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2005-03-07 37376]
R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2005-03-07 21504]
R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2005-03-07 674304]
R2 nidimk;nidimk;c:\windows\system32\drivers\nidimk.dll [2006-07-13 159232]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2005-03-07 50688]
R2 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfk.dll [2006-07-19 200704]
R2 niemrk;niemrk;c:\windows\system32\drivers\niemrk.dll [2006-07-20 370176]
R2 nifslk;nifslk;c:\windows\system32\drivers\nifslk.dll [2006-07-16 81920]
R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2005-03-07 30208]
R2 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpk.dll [2006-07-15 20480]
R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmk.dll [2006-07-18 71680]
R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2005-03-07 111616]
R2 niswdk;niswdk;c:\windows\system32\drivers\niswdk.dll [2006-08-23 490496]
R2 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrk.dll [2006-07-20 1746432]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [2008-10-14 53248]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2008-11-21 12560]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2007-12-05 520192]
R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2007-12-05 360448]
R2 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.dll [2006-07-16 19968]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-27 101936]
R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrk.dll [2006-07-15 171520]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2k.dll [2006-07-13 248832]
R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrk.dll [2006-07-15 137728]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstsk.dll [2006-07-15 51712]
R3 niscdk;niscdk;c:\windows\system32\drivers\niscdk.dll [2006-07-15 506880]
R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigk.dll [2006-07-16 240128]
R3 nitiork;nitiork;c:\windows\system32\drivers\nitiork.dll [2006-07-15 790528]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-05-22 30336]
S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2007-02-23 11552]
S3 AJDIQ;AJDIQ;c:\docume~1\AVIMIR~1\LOCALS~1\Temp\AJDIQ.exe --> c:\docume~1\AVIMIR~1\LOCALS~1\Temp\AJDIQ.exe [?]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsark.dll [2006-07-20 648192]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrk.dll [2006-07-20 500224]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [2006-06-05 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [2006-06-05 151683]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftk.dll [2006-07-15 164864]
S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2006-07-18 51200]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdk.dll [2006-07-15 43008]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrk.dll [2006-07-20 1026560]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2k.dll [2006-06-05 163328]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrk.dll [2006-07-15 111616]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2007-02-22 11552]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2007-02-23 11552]
S3 NIVIUSBK;NI-VISA USB Driver;c:\windows\system32\drivers\NiViUsbK.sys [2007-02-22 45856]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrk.dll [2006-07-20 434688]
S3 OMYWDHJR;OMYWDHJR;c:\docume~1\AVIMIR~1\LOCALS~1\Temp\OMYWDHJR.exe --> c:\docume~1\AVIMIR~1\LOCALS~1\Temp\OMYWDHJR.exe [?]
S3 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007;c:\program files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe [2008-06-04 237568]
S3 Remote Solver for COSMOSFloWorks 2008;Remote Solver for COSMOSFloWorks 2008;c:\program files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe [2008-06-04 237568]
S3 RKLGFNIRGCM;RKLGFNIRGCM;c:\docume~1\AVIMIR~1\LOCALS~1\Temp\RKLGFNIRGCM.exe --> c:\docume~1\AVIMIR~1\LOCALS~1\Temp\RKLGFNIRGCM.exe [?]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2007-06-06 116928]
S4 nidevldu;nidevldu;system32\nipalsm.exe --> system32\nipalsm.exe [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - NIPALK

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1d160015-c563-11dc-88ca-0013e8838db3}]
\Shell\AutoRun\command - E:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6811538-002c-11dd-88d4-00059a3c7800}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa7a6d7f-8b4a-11dc-88b4-0013e8838db3}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-03-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1767777339-725345543-1003.job
- c:\documents and settings\Avi Mirchandani\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-14 22:29]

2009-02-15 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PCDR5\pcdr5cuiw32.exe [2008-10-31 13:14]

2009-03-04 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-11-21 10:56]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://rpinfo.rpi.edu/
mStart Page = about:blank
mWindow Title = Windows Internet Explorer
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {C26027F5-C7EF-4CC1-9637-B514BCF8BF4E} - hxxp://www.arcadetown.com/swf/scorchanisland/saionline.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-04 12:30:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-789336058-1767777339-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:b6,b7,12,36,04,b4,69,dc,20,3e,d8,fa,f1,5c,24,77,0c,04,fc,aa,e2,
53,89,ad,dc,d5,33,8d,9a,a8,ff,e5,45,f1,89,2b,6e,76,61,71,fe,14,16,5e,de,11,\
"rkeysecu"=hex:48,be,87,da,47,81,45,cf,1c,24,33,c3,4f,a4,ab,b2
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1500)
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\qlbase.dll
c:\program files\ThinkVantage Fingerprint Software\ps2css.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll
c:\program files\ThinkVantage Fingerprint Software\pscssint.dll
c:\program files\ThinkVantage Fingerprint Software\vti.dll

- - - - - - - > 'lsass.exe'(1560)
c:\program files\ThinkPad\ConnectUtilities\ACGina.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACON.dll
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgr.dll
c:\program files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll
c:\program files\ThinkPad\ConnectUtilities\ACTurinSupport.dll
c:\program files\ThinkPad\ConnectUtilities\AcSmBiosHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\system32\TPHDEXLG.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Lenovo\System Update\SUService.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\ZOOM\TpScrex.exe
c:\windows\system32\rundll32.exe
c:\progra~1\ThinkPad\UTILIT~1\PWMUIAux.EXE
.
**************************************************************************
.
Completion time: 2009-03-04 12:37:27 - machine was rebooted [Avi Mirchandani]
ComboFix-quarantined-files.txt 2009-03-04 17:37:24

Pre-Run: 59,073,667,072 bytes free
Post-Run: 59,290,877,952 bytes free

474 --- E O F --- 2009-03-01 04:22:13





DDS (Ver_09-02-01.01) - NTFSx86
Run by Avi Mirchandani at 12:48:38.79 on Wed 03/04/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2014.1432 [GMT -5:00]

AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
svchost.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe
C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\PWMUIAux.exe
C:\Documents and Settings\Avi Mirchandani\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://rpinfo.rpi.edu/
mStart Page = about:blank
mWindow Title = Windows Internet Explorer
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog
mRun: [AwaySch] c:\program files\lenovo\awaytask\AwaySch.EXE
mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [TpShocks] TpShocks.exe
mRun: [Run StartupMonitor] StartupMonitor.exe
mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe
mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
StartupFolder: c:\docume~1\avimir~1\startm~1\programs\startup\window~1.lnk - c:\windows\system32\taskmgr.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1D082E71-DF20-4AAF-863B-596428C49874} - hxxp://www.worldwinner.com/games/v50/tpir/tpir.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2DAD3559-2923-4935-AD49-B673D2539944} - hxxp://www-307.ibm.com/pc/support/acpir.cab
DPF: {2E062718-4B2D-4926-9E31-36ECB6F4F273} - hxxp://www.worldwinner.com/games/v46/nhltrivia/nhltrivia.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} - hxxp://www.worldwinner.com/games/v47/solitairerush/solitairerush.cab
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} - hxxp://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - hxxp://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188772002578
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189021432906
DPF: {74FFE28D-2378-11D5-990C-006094235084} - hxxp://www-307.ibm.com/pc/support/IbmEgath.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} - hxxp://www.worldwinner.com/games/v46/grandslam/grandslamtrivia.cab
DPF: {B9F79165-A264-4C4A-A211-133A5E8D647F} - hxxp://support.f-secure.com/enu/home/onlineservices/fshc/fscax.cab
DPF: {C26027F5-C7EF-4CC1-9637-B514BCF8BF4E} - hxxp://www.arcadetown.com/swf/scorchanisland/saionline.cab
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} - hxxp://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} - hxxp://games.bigfishgames.com/en_cinematycoon/online/cinematycoon.cab
Notify: ACNotify - ACNotify.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: psfus - c:\program files\thinkvantage fingerprint software\psqlpwd.dll
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll
LSA: Notification Packages = scecli ACGina psqlpwd c:\program files\thinkvantage fingerprint software\psqlpwd.dll

============= SERVICES / DRIVERS ===============

R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2008-5-14 114728]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2008-5-14 19496]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2007-9-5 11520]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2007-9-5 4224]
R1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2008-12-17 53752]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2007-9-5 4442]
R1 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [2007-12-5 46144]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576]
R2 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.dll [2005-7-27 10829]
R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2005-3-7 37376]
R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2005-3-7 21504]
R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2005-3-7 674304]
R2 nidimk;nidimk;c:\windows\system32\drivers\nidimk.dll [2006-7-13 159232]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2005-3-7 50688]
R2 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfk.dll [2006-7-19 200704]
R2 niemrk;niemrk;c:\windows\system32\drivers\niemrk.dll [2006-7-20 370176]
R2 nifslk;nifslk;c:\windows\system32\drivers\nifslk.dll [2006-7-16 81920]
R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2005-3-7 30208]
R2 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpk.dll [2006-7-15 20480]
R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmk.dll [2006-7-18 71680]
R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2005-3-7 111616]
R2 niswdk;niswdk;c:\windows\system32\drivers\niswdk.dll [2006-8-23 490496]
R2 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrk.dll [2006-7-20 1746432]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\thinkpad\utilities\PWMDBSVC.exe [2008-10-14 53248]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2008-11-21 12560]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\lenovo\rescue and recovery\rrpservice.exe [2007-12-5 520192]
R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\lenovo\rescue and recovery\UpdateMonitor.exe [2007-12-5 360448]
R2 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.dll [2006-7-16 19968]
R2 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-27 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090303.003\naveng.sys [2009-3-3 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090303.003\navex15.sys [2009-3-3 876144]
R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrk.dll [2006-7-15 171520]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2k.dll [2006-7-13 248832]
R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrk.dll [2006-7-15 137728]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstsk.dll [2006-7-15 51712]
R3 niscdk;niscdk;c:\windows\system32\drivers\niscdk.dll [2006-7-15 506880]
R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigk.dll [2006-7-16 240128]
R3 nitiork;nitiork;c:\windows\system32\drivers\nitiork.dll [2006-7-15 790528]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-5-22 30336]
S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2007-2-23 11552]
S3 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664]
S3 AJDIQ;AJDIQ;c:\docume~1\avimir~1\locals~1\temp\ajdiq.exe --> c:\docume~1\avimir~1\locals~1\temp\AJDIQ.exe [?]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsark.dll [2006-7-20 648192]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrk.dll [2006-7-20 500224]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [2006-6-5 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [2006-6-5 151683]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftk.dll [2006-7-15 164864]
S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2006-7-18 51200]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdk.dll [2006-7-15 43008]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrk.dll [2006-7-20 1026560]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2k.dll [2006-6-5 163328]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrk.dll [2006-7-15 111616]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2007-2-22 11552]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2007-2-23 11552]
S3 NIVIUSBK;NI-VISA USB Driver;c:\windows\system32\drivers\NiViUsbK.sys [2007-2-22 45856]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrk.dll [2006-7-20 434688]
S3 OMYWDHJR;OMYWDHJR;c:\docume~1\avimir~1\locals~1\temp\omywdhjr.exe --> c:\docume~1\avimir~1\locals~1\temp\OMYWDHJR.exe [?]
S3 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007;c:\program files\solidworks\cosmos\floworks\bincfw\StandAloneSlv.exe [2008-6-4 237568]
S3 Remote Solver for COSMOSFloWorks 2008;Remote Solver for COSMOSFloWorks 2008;c:\program files\solidworks\cosmos\floworks\bincfw\StandAloneSlv.exe [2008-6-4 237568]
S3 RKLGFNIRGCM;RKLGFNIRGCM;c:\docume~1\avimir~1\locals~1\temp\rklgfnirgcm.exe --> c:\docume~1\avimir~1\locals~1\temp\RKLGFNIRGCM.exe [?]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-6-6 116928]
S3 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-6-6 1821376]
S4 nidevldu;nidevldu;system32\nipalsm.exe --> system32\nipalsm.exe [?]

=============== Created Last 30 ================

2009-03-04 12:17 161,792 a------- c:\windows\SWREG.exe
2009-03-04 12:17 98,816 a------- c:\windows\sed.exe
2009-03-04 12:00 <DIR> --dshr-- C:\cmdcons
2009-03-04 12:00 <DIR> --d----- c:\windows\setup.pss
2009-03-04 12:00 <DIR> --d----- c:\windows\setupupd
2009-03-03 12:50 0 a------- c:\windows\system32\WT
2009-03-03 12:42 <DIR> --ds---- c:\documents and settings\avi mirchandani\UserData
2009-03-03 12:26 <DIR> --d----- C:\RootRepeal
2009-03-03 12:18 <DIR> a-dshr-- C:\autorun.inf
2009-03-02 14:57 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-02 12:51 <DIR> --d----- c:\program files\Support Tools
2009-02-22 12:43 <DIR> --d----- c:\program files\common files\CANON
2009-02-22 12:43 <DIR> --d----- c:\program files\Canon
2009-02-16 13:44 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-15 18:25 1,324 a------- c:\windows\system32\d3d9caps.dat
2009-02-15 13:21 <DIR> --d----- c:\program files\common files\ThinkVantage Fingerprint Software
2009-02-15 13:21 <DIR> --d----- c:\program files\common files\SPBA
2009-02-15 13:18 3,632,384 a------- c:\windows\system32\drivers\NETw5x32.sys
2009-02-15 13:18 2,756,608 a------- c:\windows\system32\NETw5r32.dll
2009-02-15 13:18 663,552 a------- c:\windows\system32\NETw5c32.dll
2009-02-15 13:17 <DIR> --d----- c:\docume~1\avimir~1\applic~1\Intel
2009-02-15 13:17 <DIR> --d----- c:\program files\common files\Intel
2009-02-14 11:26 <DIR> --d----- c:\windows\ERUNT
2009-02-14 10:48 <DIR> --d----- c:\docume~1\avimir~1\applic~1\Malwarebytes
2009-02-13 23:30 <DIR> --d----- C:\SDFix
2009-02-13 15:26 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-13 15:26 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-13 15:26 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-02-13 15:26 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-13 11:53 <DIR> --d----- C:\fixwareout
2009-02-13 10:50 <DIR> --d----- c:\program files\Trend Micro
2009-02-12 12:47 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2009-02-11 20:25 0 a------- c:\windows\system32\budda
2009-02-11 20:20 <DIR> --d----- c:\program files\PlayFirst
2009-02-09 10:17 53,248 a------- c:\windows\system32\dnssd.dll
2009-02-09 10:17 <DIR> --d----- c:\program files\Bonjour
2009-02-09 10:16 <DIR> --d----- c:\program files\TiVo
2009-02-09 10:16 <DIR> --d----- c:\program files\common files\TiVo Shared
2009-02-09 10:16 <DIR> --d----- c:\docume~1\alluse~1\applic~1\TiVo

==================== Find3M ====================

2009-02-12 18:26 43,447 a------- c:\windows\system32\nvModes.dat
2008-12-04 19:26 453,152 a------- c:\windows\system32\NVUNINST.EXE
2008-03-18 15:33 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat
2003-09-16 01:19 99,544 a------- c:\windows\inf\virprn.exe
2003-09-16 01:19 18,950 a------- c:\windows\inf\virpntd.dll
2003-09-16 01:19 10,240 a------- c:\windows\inf\virport.dll
2003-09-16 01:19 90,624 a------- c:\windows\inf\prtproc.dll

============= FINISH: 12:49:35.75 ===============

#8 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:36 PM

Posted 05 March 2009 - 10:47 AM

Hi again,


Uninstall old Adobe Reader versions and get the latest one here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader!


Open notepad and copy/paste the text in the quotebox below into it:

Driver::
AJDIQ
OMYWDHJR
RKLGFNIRGCM

File::
c:\windows\system32\WT
c:\windows\system32\budda
c:\docume~1\AVIMIR~1\LOCALS~1\Temp\AJDIQ.exe
c:\docume~1\AVIMIR~1\LOCALS~1\Temp\OMYWDHJR.exe
c:\docume~1\AVIMIR~1\LOCALS~1\Temp\RKLGFNIRGCM.exe
C:\autorun.inf

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1d160015-c563-11dc-88ca-0013e8838db3}]

DDS::
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} -
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} -
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} -


Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Download ATF (Atribune Temp File) Cleanerę by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.

Edited by Blade81, 05 March 2009 - 10:57 AM.
dds.txt and not hijackthis log :)

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#9 cpm0813

cpm0813
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:36 AM

Posted 06 March 2009 - 12:00 AM

Note: I uninstalled OrCAD and this EZEject Utility which came with my laptop, which you will see signs of in the various logs.
Thanks for all the help so far and future help.


--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, March 5, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, March 05, 2009 18:30:40
Records in database: 1871308
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 261383
Threat name: 10
Infected objects: 43
Suspicious objects: 0
Duration of the scan: 08:17:55


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00C40000\49D6E89A.VBN Infected: Packed.Win32.Tdss.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07EC0000\4FFD9995.VBN Infected: EICAR-Test-File 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07EC0001\4FFD99AE.VBN Infected: EICAR-Test-File 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07EC0002\4FFD99B8.VBN Infected: EICAR-Test-File 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CE40000\4DF40B08.VBN Infected: Exploit.Win32.Pidief.abz 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D940000.VBN Infected: not-a-virus:Monitor.Win32.Perflogger.g 2
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D940000.VBN Infected: not-a-virus:Monitor.Win32.Perflogger.ad 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D940000.VBN Infected: Trojan-Spy.Win32.Perfloger.af 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D940001.VBN Infected: not-a-virus:Monitor.Win32.Perflogger.g 2
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D940001.VBN Infected: not-a-virus:Monitor.Win32.Perflogger.ad 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D940001.VBN Infected: Trojan-Spy.Win32.Perfloger.af 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EF80002\4FFB7B30.VBN Infected: Packed.Win32.Tdss.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F140000\4F350130.VBN Infected: Packed.JS.Agent.i 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F140001.VBN Infected: Packed.JS.Agent.i 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F140002.VBN Infected: Packed.JS.Agent.i 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F140003.VBN Infected: Packed.JS.Agent.i 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\14D40000\5DDC4FCD.VBN Infected: EICAR-Test-File 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\14D40001\5DDC4FCD.VBN Infected: EICAR-Test-File 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\14D40002\5DDC4FE0.VBN Infected: EICAR-Test-File 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\14D40003\5DDC4FF9.VBN Infected: EICAR-Test-File 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Indu\Downloads\MyFunCardsSetup2.3.50.10.exe Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.au 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Indu.rar Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.au 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Indu.rar Infected: not-a-virus:Monitor.Win32.Perflogger.g 2
C:\Documents and Settings\Avi Mirchandani\Desktop\Indu.rar Infected: not-a-virus:Monitor.Win32.Perflogger.ad 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Indu.rar Infected: Trojan-Spy.Win32.Perfloger.af 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Indu\AppData\Local\Microsoft\Windows Mail\Local Folders\Imported Folder\Sent Items\54405887-00000028.eml Infected: not-a-virus:Monitor.Win32.Perflogger.g 2
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Indu\AppData\Local\Microsoft\Windows Mail\Local Folders\Imported Folder\Sent Items\54405887-00000028.eml Infected: not-a-virus:Monitor.Win32.Perflogger.ad 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Indu\AppData\Local\Microsoft\Windows Mail\Local Folders\Imported Folder\Sent Items\54405887-00000028.eml Infected: Trojan-Spy.Win32.Perfloger.af 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Indu\Downloads\MyFunCardsSetup2.3.50.10.exe Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.au 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Outlook Express\natasha (1).dbx Infected: not-a-virus:Monitor.Win32.Perflogger.g 2
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Outlook Express\natasha (1).dbx Infected: not-a-virus:Monitor.Win32.Perflogger.ad 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Outlook Express\natasha (1).dbx Infected: Trojan-Spy.Win32.Perfloger.af 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Outlook Express\Sent Items (1).dbx Infected: not-a-virus:Monitor.Win32.Perflogger.g 2
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Outlook Express\Sent Items (1).dbx Infected: not-a-virus:Monitor.Win32.Perflogger.ad 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Outlook Express\Sent Items (1).dbx Infected: Trojan-Spy.Win32.Perfloger.af 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Outlook Express\Sent Items (1).dbx Infected: Exploit.HTML.CodeBaseExec 1
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Outlook Express\Sent Items (1).dbx Infected: Trojan.Win32.Glieder.gen 1

The selected area was scanned.


------***-------------------------------------***-------------------------------------***-------------------------------------***------


DDS (Ver_09-02-01.01) - NTFSx86
Run by Avi Mirchandani at 23:40:20.75 on Thu 03/05/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2014.1343 [GMT -5:00]

AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
svchost.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe
C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\PWMUIAux.exe
C:\Documents and Settings\Avi Mirchandani\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://rpinfo.rpi.edu/
mStart Page = about:blank
mWindow Title = Windows Internet Explorer
uInternet Connection Wizard,ShellNext = iexplore
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog
mRun: [AwaySch] c:\program files\lenovo\awaytask\AwaySch.EXE
mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [TpShocks] TpShocks.exe
mRun: [Run StartupMonitor] StartupMonitor.exe
mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe
mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
StartupFolder: c:\docume~1\avimir~1\startm~1\programs\startup\window~1.lnk - c:\windows\system32\taskmgr.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1D082E71-DF20-4AAF-863B-596428C49874} - hxxp://www.worldwinner.com/games/v50/tpir/tpir.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2DAD3559-2923-4935-AD49-B673D2539944} - hxxp://www-307.ibm.com/pc/support/acpir.cab
DPF: {2E062718-4B2D-4926-9E31-36ECB6F4F273} - hxxp://www.worldwinner.com/games/v46/nhltrivia/nhltrivia.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} - hxxp://www.worldwinner.com/games/v47/solitairerush/solitairerush.cab
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} - hxxp://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - hxxp://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188772002578
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189021432906
DPF: {74FFE28D-2378-11D5-990C-006094235084} - hxxp://www-307.ibm.com/pc/support/IbmEgath.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} - hxxp://www.worldwinner.com/games/v46/grandslam/grandslamtrivia.cab
DPF: {B9F79165-A264-4C4A-A211-133A5E8D647F} - hxxp://support.f-secure.com/enu/home/onlineservices/fshc/fscax.cab
DPF: {C26027F5-C7EF-4CC1-9637-B514BCF8BF4E} - hxxp://www.arcadetown.com/swf/scorchanisland/saionline.cab
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} - hxxp://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} - hxxp://games.bigfishgames.com/en_cinematycoon/online/cinematycoon.cab
Notify: ACNotify - ACNotify.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
Notify: psfus - c:\program files\thinkvantage fingerprint software\psqlpwd.dll
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll
LSA: Notification Packages = scecli ACGina psqlpwd c:\program files\thinkvantage fingerprint software\psqlpwd.dll

============= SERVICES / DRIVERS ===============

R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2008-5-14 114728]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2008-5-14 19496]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2007-9-5 11520]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2007-9-5 4224]
R1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2008-12-17 53752]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2007-9-5 4442]
R1 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [2007-12-5 46144]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576]
R2 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.dll [2005-7-27 10829]
R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2005-3-7 37376]
R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2005-3-7 21504]
R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2005-3-7 674304]
R2 nidimk;nidimk;c:\windows\system32\drivers\nidimk.dll [2006-7-13 159232]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2005-3-7 50688]
R2 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfk.dll [2006-7-19 200704]
R2 niemrk;niemrk;c:\windows\system32\drivers\niemrk.dll [2006-7-20 370176]
R2 nifslk;nifslk;c:\windows\system32\drivers\nifslk.dll [2006-7-16 81920]
R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2005-3-7 30208]
R2 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpk.dll [2006-7-15 20480]
R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmk.dll [2006-7-18 71680]
R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2005-3-7 111616]
R2 niswdk;niswdk;c:\windows\system32\drivers\niswdk.dll [2006-8-23 490496]
R2 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrk.dll [2006-7-20 1746432]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\thinkpad\utilities\PWMDBSVC.exe [2008-10-14 53248]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2008-11-21 12560]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\lenovo\rescue and recovery\rrpservice.exe [2007-12-5 520192]
R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\lenovo\rescue and recovery\UpdateMonitor.exe [2007-12-5 360448]
R2 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.dll [2006-7-16 19968]
R2 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-27 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090305.002\naveng.sys [2009-3-5 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090305.002\navex15.sys [2009-3-5 876144]
R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrk.dll [2006-7-15 171520]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2k.dll [2006-7-13 248832]
R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrk.dll [2006-7-15 137728]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstsk.dll [2006-7-15 51712]
R3 niscdk;niscdk;c:\windows\system32\drivers\niscdk.dll [2006-7-15 506880]
R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigk.dll [2006-7-16 240128]
R3 nitiork;nitiork;c:\windows\system32\drivers\nitiork.dll [2006-7-15 790528]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-5-22 30336]
S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2007-2-23 11552]
S3 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsark.dll [2006-7-20 648192]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrk.dll [2006-7-20 500224]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [2006-6-5 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [2006-6-5 151683]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftk.dll [2006-7-15 164864]
S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2006-7-18 51200]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdk.dll [2006-7-15 43008]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrk.dll [2006-7-20 1026560]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2k.dll [2006-6-5 163328]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrk.dll [2006-7-15 111616]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2007-2-22 11552]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2007-2-23 11552]
S3 NIVIUSBK;NI-VISA USB Driver;c:\windows\system32\drivers\NiViUsbK.sys [2007-2-22 45856]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrk.dll [2006-7-20 434688]
S3 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007;c:\program files\solidworks\cosmos\floworks\bincfw\StandAloneSlv.exe [2008-6-4 237568]
S3 Remote Solver for COSMOSFloWorks 2008;Remote Solver for COSMOSFloWorks 2008;c:\program files\solidworks\cosmos\floworks\bincfw\StandAloneSlv.exe [2008-6-4 237568]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-6-6 116928]
S3 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-6-6 1821376]
S4 nidevldu;nidevldu;system32\nipalsm.exe --> system32\nipalsm.exe [?]

=============== Created Last 30 ================

2009-03-05 11:23 161,792 a------- c:\windows\SWREG.exe
2009-03-05 11:23 98,816 a------- c:\windows\sed.exe
2009-03-04 12:00 <DIR> --dshr-- C:\cmdcons
2009-03-04 12:00 <DIR> --d----- c:\windows\setup.pss
2009-03-04 12:00 <DIR> --d----- c:\windows\setupupd
2009-03-03 12:42 <DIR> --ds---- c:\documents and settings\avi mirchandani\UserData
2009-03-03 12:26 <DIR> --d----- C:\RootRepeal
2009-03-03 12:18 <DIR> a-dshr-- C:\autorun.inf
2009-03-02 14:57 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-02 12:51 <DIR> --d----- c:\program files\Support Tools
2009-02-22 12:43 <DIR> --d----- c:\program files\common files\CANON
2009-02-22 12:43 <DIR> --d----- c:\program files\Canon
2009-02-16 13:44 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-15 18:25 1,324 a------- c:\windows\system32\d3d9caps.dat
2009-02-15 13:21 <DIR> --d----- c:\program files\common files\ThinkVantage Fingerprint Software
2009-02-15 13:21 <DIR> --d----- c:\program files\common files\SPBA
2009-02-15 13:18 3,632,384 a------- c:\windows\system32\drivers\NETw5x32.sys
2009-02-15 13:18 2,756,608 a------- c:\windows\system32\NETw5r32.dll
2009-02-15 13:18 663,552 a------- c:\windows\system32\NETw5c32.dll
2009-02-15 13:17 <DIR> --d----- c:\docume~1\avimir~1\applic~1\Intel
2009-02-15 13:17 <DIR> --d----- c:\program files\common files\Intel
2009-02-14 11:26 <DIR> --d----- c:\windows\ERUNT
2009-02-14 10:48 <DIR> --d----- c:\docume~1\avimir~1\applic~1\Malwarebytes
2009-02-13 23:30 <DIR> --d----- C:\SDFix
2009-02-13 15:26 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-13 15:26 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-13 15:26 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-02-13 15:26 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-13 11:53 <DIR> --d----- C:\fixwareout
2009-02-13 10:50 <DIR> --d----- c:\program files\Trend Micro
2009-02-12 12:47 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2009-02-11 20:20 <DIR> --d----- c:\program files\PlayFirst
2009-02-09 10:17 53,248 a------- c:\windows\system32\dnssd.dll
2009-02-09 10:17 <DIR> --d----- c:\program files\Bonjour
2009-02-09 10:16 <DIR> --d----- c:\program files\TiVo
2009-02-09 10:16 <DIR> --d----- c:\program files\common files\TiVo Shared
2009-02-09 10:16 <DIR> --d----- c:\docume~1\alluse~1\applic~1\TiVo

==================== Find3M ====================

2009-02-12 18:26 43,447 a------- c:\windows\system32\nvModes.dat
2008-03-18 15:33 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat
2003-09-16 01:19 99,544 a------- c:\windows\inf\virprn.exe
2003-09-16 01:19 18,950 a------- c:\windows\inf\virpntd.dll
2003-09-16 01:19 10,240 a------- c:\windows\inf\virport.dll
2003-09-16 01:19 90,624 a------- c:\windows\inf\prtproc.dll

============= FINISH: 23:40:54.78 ===============



------***-------------------------------------***-------------------------------------***-------------------------------------***------


ComboFix 09-03-04.01 - Avi Mirchandani 2009-03-05 11:24:43.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2014.1422 [GMT -5:00]
Running from: c:\documents and settings\Avi Mirchandani\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Avi Mirchandani\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
C:\autorun.inf
c:\docume~1\AVIMIR~1\LOCALS~1\Temp\AJDIQ.exe
c:\docume~1\AVIMIR~1\LOCALS~1\Temp\OMYWDHJR.exe
c:\docume~1\AVIMIR~1\LOCALS~1\Temp\RKLGFNIRGCM.exe
c:\windows\system32\budda
c:\windows\system32\WT
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\budda
c:\windows\system32\WT

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_AJDIQ
-------\Legacy_OMYWDHJR
-------\Legacy_RKLGFNIRGCM
-------\Service_AJDIQ
-------\Service_OMYWDHJR
-------\Service_RKLGFNIRGCM


((((((((((((((((((((((((( Files Created from 2009-02-05 to 2009-03-05 )))))))))))))))))))))))))))))))
.

2009-03-03 12:42 . 2009-03-03 12:42 <DIR> d---s---- c:\documents and settings\Avi Mirchandani\UserData
2009-03-03 12:26 . 2009-03-04 12:44 <DIR> d-------- C:\RootRepeal
2009-03-02 14:57 . 2009-03-02 14:57 <DIR> d----c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-02 13:24 . 2009-03-02 13:24 <DIR> d-------- C:\ERDNT
2009-03-02 12:51 . 2009-03-02 12:51 <DIR> d-------- c:\program files\Support Tools
2009-02-22 12:43 . 2009-02-22 12:43 <DIR> d-------- c:\program files\Common Files\CANON
2009-02-22 12:43 . 2009-02-22 12:44 <DIR> d-------- c:\program files\Canon
2009-02-22 12:30 . 2009-02-22 12:45 <DIR> d-------- c:\documents and settings\Avi Mirchandani\Application Data\Canon
2009-02-16 13:44 . 2009-02-16 13:44 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-15 18:25 . 2009-03-03 17:33 1,324 --a------ c:\windows\system32\d3d9caps.dat
2009-02-15 13:21 . 2009-02-15 13:21 <DIR> d-------- c:\program files\Common Files\ThinkVantage Fingerprint Software
2009-02-15 13:21 . 2009-02-15 13:21 <DIR> d-------- c:\program files\Common Files\SPBA
2009-02-15 13:18 . 2009-02-15 13:18 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\Intel
2009-02-15 13:18 . 2009-02-15 13:18 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Intel
2009-02-15 13:18 . 2008-08-28 23:34 3,632,384 --a------ c:\windows\system32\drivers\NETw5x32.sys
2009-02-15 13:18 . 2008-06-20 10:33 2,756,608 --a------ c:\windows\system32\NETw5r32.dll
2009-02-15 13:18 . 2008-06-20 10:32 663,552 --a------ c:\windows\system32\NETw5c32.dll
2009-02-15 13:17 . 2009-02-15 13:17 <DIR> d-------- c:\program files\Common Files\Intel
2009-02-15 13:17 . 2009-02-15 13:17 <DIR> d-------- c:\documents and settings\LocalService\Application Data\Intel
2009-02-15 13:17 . 2009-02-15 13:17 <DIR> d-------- c:\documents and settings\Avi Mirchandani\Application Data\Intel
2009-02-15 13:17 . 2009-02-15 13:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Intel
2009-02-14 11:26 . 2009-02-14 11:26 <DIR> d-------- c:\windows\ERUNT
2009-02-14 10:48 . 2009-02-14 10:48 <DIR> d-------- c:\documents and settings\Avi Mirchandani\Application Data\Malwarebytes
2009-02-13 23:30 . 2009-02-14 21:38 <DIR> d-------- C:\SDFix
2009-02-13 15:26 . 2009-02-13 23:26 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-13 15:26 . 2009-02-13 15:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-13 15:26 . 2009-02-13 15:26 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-13 15:26 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-13 15:26 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-13 11:53 . 2009-02-13 11:58 <DIR> d-------- C:\fixwareout
2009-02-13 10:50 . 2009-02-13 10:50 <DIR> d-------- c:\program files\Trend Micro
2009-02-12 18:54 . 2009-02-12 18:54 <DIR> d---s---- c:\documents and settings\Administrator\UserData
2009-02-12 12:47 . 2009-02-12 14:27 <DIR> d-------- c:\documents and settings\Administrator\.housecall6.6
2009-02-12 12:47 . 2009-02-12 12:47 102,664 --a------ c:\windows\system32\drivers\tmcomm.sys
2009-02-12 12:22 . 2009-02-12 12:23 <DIR> d-------- c:\program files\Windows Live Safety Center
2009-02-12 12:16 . 2009-02-14 10:40 <DIR> d-------- c:\documents and settings\Administrator
2009-02-11 20:21 . 2009-02-11 20:21 <DIR> d-------- c:\documents and settings\Avi Mirchandani\Application Data\PlayFirst
2009-02-11 20:20 . 2009-02-11 20:20 <DIR> d-------- c:\program files\PlayFirst
2009-02-11 20:08 . 2009-02-11 20:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\TEMP
2009-02-09 10:17 . 2009-02-09 10:17 <DIR> d-------- c:\program files\Bonjour
2009-02-09 10:17 . 2009-01-27 15:52 53,248 --a------ c:\windows\system32\dnssd.dll
2009-02-09 10:16 . 2009-02-09 10:16 <DIR> d-------- c:\program files\TiVo
2009-02-09 10:16 . 2009-02-09 10:16 <DIR> d-------- c:\program files\Common Files\TiVo Shared
2009-02-09 10:16 . 2009-02-09 10:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\TiVo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-05 16:17 --------- d-----w c:\program files\Symantec AntiVirus
2009-03-05 16:11 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-05 16:07 --------- d-----w c:\program files\Common Files\Adobe
2009-03-03 22:37 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\.purple
2009-02-27 16:39 --------- d-----w c:\program files\Cheat Engine
2009-02-16 18:44 --------- d-----w c:\program files\Java
2009-02-15 19:09 --------- d-----w c:\program files\Defraggler
2009-02-15 18:52 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-15 18:51 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\Lenovo
2009-02-15 18:31 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-15 18:22 --------- d-----w c:\program files\ThinkVantage Fingerprint Software
2009-02-15 18:20 --------- d-----w c:\documents and settings\All Users\Application Data\UIB
2009-02-15 18:19 --------- d-----w c:\documents and settings\All Users\Application Data\Lenovo
2009-02-15 18:17 --------- d-----w c:\program files\Intel
2009-02-15 17:51 --------- d-----w c:\documents and settings\All Users\Application Data\PCDr
2009-02-15 14:51 --------- d-----w c:\program files\PCDR5
2009-02-10 20:57 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\Move Networks
2009-01-29 23:30 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\Skype
2009-01-29 23:28 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\skypePM
2009-01-29 21:11 --------- d-----w c:\program files\GPLGS
2009-01-29 21:11 --------- d-----w c:\program files\Acro Software
2009-01-20 18:42 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\gtk-2.0
2009-01-19 22:21 --------- d-----w c:\program files\AdgarTheBarbarian
2009-01-16 22:21 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\Atari
2009-01-16 21:41 --------- d-----w c:\program files\Atari
2009-01-15 16:17 --------- d-----w c:\program files\CCleaner
2009-01-08 15:16 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\IM
2009-01-05 23:55 --------- d-----w c:\documents and settings\Avi Mirchandani\Application Data\SPORE
2008-03-18 20:33 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2004-03-15 21:51 114,688 ----a-w c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2003-05-01 13:36 114,688 ----a-w c:\program files\internet explorer\plugins\LV7ActiveXControl.dll
2006-01-23 14:32 131,072 ----a-w c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2006-06-07 18:40 132,848 ----a-w c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-12-04 16:38 3431224 --a------ c:\program files\MozyHome\mozyshell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-12-04 16:38 3431224 --a------ c:\program files\MozyHome\mozyshell.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-05 13549568]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2008-11-21 385024]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-03-17 208896]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-09-30 68976]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-10-27 143360]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-10-27 425984]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-05 86016]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2008-07-03 118784]
"nwiz"="nwiz.exe" [2008-12-05 c:\windows\system32\nwiz.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]
"TpShocks"="TpShocks.exe" [2008-06-06 c:\windows\system32\TpShocks.exe]
"Run StartupMonitor"="StartupMonitor.exe" [2000-05-20 c:\windows\StartupMonitor.exe]

c:\documents and settings\Avi Mirchandani\Start Menu\Programs\Startup\
Windows Task Manager.lnk - c:\windows\system32\taskmgr.exe [2004-08-04 135680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2008-11-21 00:35 95496 c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 15:37 34344 c:\program files\Lenovo\HOTKEY\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2008-08-08 19:14 28672 c:\program files\Lenovo\HOTKEY\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2008-10-27 09:57 32768 c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ACGina psqlpwd c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk.disabled
backup=c:\windows\pss\Digital Line Detect.lnk.disabledCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
--a------ 2008-03-20 11:46 217544 c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
--a------ 2008-03-18 01:06 1848648 c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
--a------ 2008-12-12 01:31 722256 c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SolidWorks_CheckForUpdates]
--a------ 2008-06-14 04:55 6862104 c:\program files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2007-08-08 08:13 831488 c:\program files\Analog Devices\SoundMAX\SMax4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2008-04-24 16:53 1036288 c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2009-02-16 13:44 148888 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoNotify]
--a------ 2009-01-27 16:18 425472 c:\program files\TiVo\Desktop\TiVoNotify.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoServer]
--a------ 2009-01-27 16:21 2143232 c:\program files\TiVo\Desktop\TiVoServer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPFNF7]
--------- 2008-07-31 04:01 60192 c:\progra~1\Lenovo\NPDIRECT\tpfnf7sp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TranscodingService]
--a------ 2009-01-27 16:03 520192 c:\program files\TiVo\Desktop\TranscodingService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
--a------ 2008-03-04 09:34 487424 c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
"LPMailChecker"=c:\progra~1\THINKV~1\PrdCtr\LPMLCHK.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\National Instruments\\LabVIEW 8.2\\LabVIEW.exe"=
"c:\\Program Files\\ThinkPad\\ConnectUtilities\\ACMainGUI.exe"=
"c:\\Program Files\\Maple 10\\jre\\bin\\maple.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Quake 3\\quake3.exe"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\rise.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\K1RFD\\EchoLink\\EchoLink.exe"=
"c:\\Documents and Settings\\Avi Mirchandani\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Avi Mirchandani\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Avi Mirchandani\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 0 (0x0)

R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2008-05-14 114728]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2008-05-14 19496]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2007-09-05 11520]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2007-09-05 4224]
R1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2008-12-17 53752]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2007-09-05 4442]
R1 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [2007-12-05 46144]
R2 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.dll [2005-07-27 10829]
R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2005-03-07 37376]
R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2005-03-07 21504]
R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2005-03-07 674304]
R2 nidimk;nidimk;c:\windows\system32\drivers\nidimk.dll [2006-07-13 159232]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2005-03-07 50688]
R2 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfk.dll [2006-07-19 200704]
R2 niemrk;niemrk;c:\windows\system32\drivers\niemrk.dll [2006-07-20 370176]
R2 nifslk;nifslk;c:\windows\system32\drivers\nifslk.dll [2006-07-16 81920]
R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2005-03-07 30208]
R2 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpk.dll [2006-07-15 20480]
R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmk.dll [2006-07-18 71680]
R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2005-03-07 111616]
R2 niswdk;niswdk;c:\windows\system32\drivers\niswdk.dll [2006-08-23 490496]
R2 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrk.dll [2006-07-20 1746432]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [2008-10-14 53248]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2008-11-21 12560]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2007-12-05 520192]
R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [2007-12-05 360448]
R2 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.dll [2006-07-16 19968]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-27 101936]
R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrk.dll [2006-07-15 171520]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2k.dll [2006-07-13 248832]
R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrk.dll [2006-07-15 137728]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstsk.dll [2006-07-15 51712]
R3 niscdk;niscdk;c:\windows\system32\drivers\niscdk.dll [2006-07-15 506880]
R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigk.dll [2006-07-16 240128]
R3 nitiork;nitiork;c:\windows\system32\drivers\nitiork.dll [2006-07-15 790528]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-05-22 30336]
S2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2007-02-23 11552]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsark.dll [2006-07-20 648192]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrk.dll [2006-07-20 500224]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [2006-06-05 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [2006-06-05 151683]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftk.dll [2006-07-15 164864]
S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2006-07-18 51200]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdk.dll [2006-07-15 43008]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrk.dll [2006-07-20 1026560]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2k.dll [2006-06-05 163328]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrk.dll [2006-07-15 111616]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2007-02-22 11552]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2007-02-23 11552]
S3 NIVIUSBK;NI-VISA USB Driver;c:\windows\system32\drivers\NiViUsbK.sys [2007-02-22 45856]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrk.dll [2006-07-20 434688]
S3 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007;c:\program files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe [2008-06-04 237568]
S3 Remote Solver for COSMOSFloWorks 2008;Remote Solver for COSMOSFloWorks 2008;c:\program files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe [2008-06-04 237568]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2007-06-06 116928]
S4 nidevldu;nidevldu;system32\nipalsm.exe --> system32\nipalsm.exe [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - NIPALK

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6811538-002c-11dd-88d4-00059a3c7800}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa7a6d7f-8b4a-11dc-88b4-0013e8838db3}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-03-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1767777339-725345543-1003.job
- c:\documents and settings\Avi Mirchandani\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-14 22:29]

2009-02-15 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PCDR5\pcdr5cuiw32.exe [2008-10-31 13:14]

2009-03-05 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-11-21 10:56]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-EZEJMNAP - c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://rpinfo.rpi.edu/
mStart Page = about:blank
mWindow Title = Windows Internet Explorer
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} - hxxp://aolsvc.aol.com/onlinegames/free-trial-burger-shop/GoBitGamesPlayer_v4.cab
DPF: {C26027F5-C7EF-4CC1-9637-B514BCF8BF4E} - hxxp://www.arcadetown.com/swf/scorchanisland/saionline.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-05 11:34:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-789336058-1767777339-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:b6,b7,12,36,04,b4,69,dc,20,3e,d8,fa,f1,5c,24,77,0c,04,fc,aa,e2,
53,89,ad,dc,d5,33,8d,9a,a8,ff,e5,45,f1,89,2b,6e,76,61,71,fe,14,16,5e,de,11,\
"rkeysecu"=hex:48,be,87,da,47,81,45,cf,1c,24,33,c3,4f,a4,ab,b2
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1500)
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\qlbase.dll
c:\program files\ThinkVantage Fingerprint Software\ps2css.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll
c:\program files\ThinkVantage Fingerprint Software\pscssint.dll
c:\program files\ThinkVantage Fingerprint Software\vti.dll

- - - - - - - > 'lsass.exe'(1556)
c:\program files\ThinkPad\ConnectUtilities\ACGina.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACON.dll
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgr.dll
c:\program files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll
c:\program files\ThinkPad\ConnectUtilities\ACTurinSupport.dll
c:\program files\ThinkPad\ConnectUtilities\AcSmBiosHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll
c:\program files\ThinkVantage Fingerprint Software\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infql2.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\system32\TPHDEXLG.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Lenovo\System Update\SUService.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\ZOOM\TpScrex.exe
c:\progra~1\ThinkPad\UTILIT~1\PWMUIAux.EXE
.
**************************************************************************
.
Completion time: 2009-03-05 11:41:43 - machine was rebooted [Avi Mirchandani]
ComboFix-quarantined-files.txt 2009-03-05 16:41:39
ComboFix2.txt 2009-03-04 17:37:29

Pre-Run: 59,359,391,744 bytes free
Post-Run: 59,421,106,176 bytes free

371 --- E O F --- 2009-03-01 04:22:13

#10 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:36 PM

Posted 06 March 2009 - 12:23 PM

Hi

Show hidden files
-----------------
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.


Delete items in C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine folder.


Delete also these files:
C:\Documents and Settings\Avi Mirchandani\Desktop\Indu\Downloads\MyFunCardsSetup2.3.50.10.exe
C:\Documents and Settings\Avi Mirchandani\Desktop\Indu.rar
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Indu\AppData\Local\Microsoft\Windows Mail\Local Folders\Imported Folder\Sent Items\54405887-00000028.eml
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Indu\Downloads\MyFunCardsSetup2.3.50.10.exe


You should check email messages in these boxes and delete suspicious looking ones:
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Outlook Express\natasha (1).dbx
C:\Documents and Settings\Avi Mirchandani\Desktop\Personal\Outlook Express\Sent Items (1).dbx



Open notepad and copy/paste the text in the quotebox below into it:

Folder::
C:\autorun.inf


Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe (let ComboFix update itself if asked for permission)
Then post the resultant log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Run full scan with MBAM and post back its report & a fresh dds.txt log. How's the system running?

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#11 cpm0813

cpm0813
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:36 AM

Posted 11 March 2009 - 09:28 AM

sorry, been super busy lately, will address this this afternoon. thanks.

#12 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:36 PM

Posted 11 March 2009 - 10:39 AM

Ok. Thanks for the heads up :thumbup2:

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#13 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:36 PM

Posted 17 March 2009 - 02:46 PM

Hi

Had time to follow the instructions?

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.


#14 cpm0813

cpm0813
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:36 AM

Posted 18 March 2009 - 11:15 PM

Started doing it, but got busy with other stuff again. Will try to do this stuff on 3/19, will update software as necessary before 11 min elapses, but will wait until internet issues begin (11 mins elapse) each time before running combofix/mbam/dds/etc. Hopefully will find something that way.

#15 Blade81

Blade81

    Bleepin' Rocker


  • Malware Response Team
  • 6,465 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:36 PM

Posted 19 March 2009 - 11:24 AM

Ok. Hopefully you find the time needed :thumbup2:

Microsoft Windows Insider MVP 2016-2017

Microsoft MVP Consumer Security 2008-2015
UNITE member since 2006
unite_blue.png

Provided malware removal related instructions are meant to be used in the correspondent user's case only. If you have similar symptoms create own topic instead of following instructions given to some other, please.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users