Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google searches redirecting to adware sites


  • This topic is locked This topic is locked
7 replies to this topic

#1 cmuhles

cmuhles

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:21 PM

Posted 06 August 2009 - 12:49 PM

Good afternoon!

I have been a lurker for a long time, and many of you have helped to educate me on numerous issues in the past, but I can't figure this one out.

I got infected by a nasty worm virus through FaceBook last night, and didn't realize it until this morning. I was able to get rid of most of the worm (my computer no longer has pop up messages, etc) however when I click on a link following a google search (in IE), it redirects me to an adware site.

I've searched others' problems with this and none of the fixes fit my situation, ergo...my first post here!

Here is my DDS report, as requested: ... any help would be much appreciated!!
Thanks! Chris


DDS (Ver_09-07-30.01) - NTFSx86
Run by Chris at 13:34:40.48 on Thu 08/06/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_12
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.385 [GMT -4:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\sySTEM32\SvchoSt.ExE -k browserctl
C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe
C:\Program Files\DDNI\DIBS\DDNIService.exe
C:\QSTART.SYS\config\DVMExportService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\BisonC07\BisonM07.exe
C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\notepad.exe
C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Chris Uhles\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [IdeaNotesUser] c:\program files\ddni\lenovo idea notes\DDNIMSGUser.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [BisonMnt] c:\windows\bisonc07\BisonM07.exe
mRun: [VeriFaceManager] c:\program files\lenovo\verifaceiii\PManage.exe
mRun: [EnergyUtility] c:\program files\lenovo\energy management\utility.exe
mRun: [Energy Management] c:\program files\lenovo\energy management\Energy Management.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [<NO NAME>]
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.lenovo.com
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
LSP: bmnet.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://javadl-esd.sun.com/update/1.6.0/jinstall-6-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R?2 browserctl;browserctl;c:\windows\system32\SvchoSt.ExE -k browserctl [2004-8-4 14336]
R1 browserctldrv;browserctldrv;c:\program files\browserctl\BrowserCtl.sys [2009-8-5 9472]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 DDNIMSGService;DDNIMSGService;c:\program files\ddni\lenovo idea notes\DDNIMSGService.exe [2009-1-17 185008]
R2 DDNIService;DDNIService;c:\program files\ddni\dibs\DDNIService.exe [2009-5-4 164528]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\qstart.sys\config\DVMExportService.exe [2009-3-25 315392]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-7-20 10384]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\lenovo\onekey app\system repair\UpdateMonitor.exe [2009-5-4 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [2009-5-4 48192]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [2009-6-6 9472]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-5-4 1684736]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2008-11-20 113152]
S3 CEUSBAUD;DigiTech USB MIDI Driver;c:\windows\system32\drivers\ceusbaud.sys [2009-8-5 17920]
S3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\drivers\Gt51Ip.sys [2008-2-18 106624]
S3 GT72UBUS;GT 72 U BUS;c:\windows\system32\drivers\gt72ubus.sys [2008-2-8 59648]
S3 GTPTSER;GT PT SER;c:\windows\system32\drivers\gtptser.sys [2007-3-30 8064]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2006-4-13 28933976]
S3 NAVENG;NAVENG;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20080829.024\naveng.sys --> c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20080829.024\NAVENG.SYS [?]
S3 NAVEX15;NAVEX15;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20080829.024\navex15.sys --> c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20080829.024\NAVEX15.SYS [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-5-4 165888]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\drivers\rts516xir.sys --> c:\windows\system32\drivers\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [2009-5-4 81192]
S4 Norton Internet Security;Norton Internet Security;"c:\program files\norton internet security\engine\16.0.0.125\ccsvchst.exe" /s "norton internet security" /m "c:\program files\norton internet security\engine\16.0.0.125\dimaster.dll" /prefetch:1 --> c:\program files\norton internet security\engine\16.0.0.125\ccSvcHst.exe [?]

=============== Created Last 30 ================

2009-08-05 23:48 1 a------- c:\windows\ectbbyn.dat
2009-08-05 23:47 9,167 a------- c:\windows\th1234.dat
2009-08-05 23:43 <DIR> --d----- c:\program files\BrowserCtl
2009-08-05 18:44 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{318921B0-B116-452F-ADB3-553ABE4A9546}
2009-08-05 18:43 60,032 a------- c:\windows\system32\drivers\USBAUDIO.sys
2009-08-05 18:43 60,032 a------- c:\windows\system32\dllcache\usbaudio.sys
2009-08-05 18:40 17,920 a------- c:\windows\system32\drivers\ceusbaud.sys
2009-07-25 14:26 <DIR> --d----- c:\documents and settings\chris uhles\.ehdc
2009-07-25 14:26 410,984 a------- c:\windows\system32\deploytk.dll
2009-07-25 14:26 73,728 a------- c:\windows\system32\javacpl.cpl
2009-07-25 14:20 15,104 a------- c:\windows\system32\drivers\usbscan.sys
2009-07-25 14:20 15,104 a------- c:\windows\system32\dllcache\usbscan.sys
2009-07-24 12:25 197,632 a------- c:\windows\system32\CNMLM7Q.DLL
2009-07-24 12:24 194,560 a------- c:\windows\system32\CNCC830.DLL
2009-07-24 12:24 143,360 a------- c:\windows\system32\CNCL830.DLL
2009-07-24 12:24 106,496 a------- c:\windows\system32\cncisco.dll
2009-07-24 12:24 49,152 a------- c:\windows\system32\CNCFMSb.EXE
2009-07-24 12:24 37,888 a------- c:\windows\system32\CNCI830.DLL
2009-07-24 12:24 3,072 a------- c:\windows\system32\CNCFLbUS.DLL
2009-07-24 12:24 2,560 a------- c:\windows\system32\CNCFLbJP.DLL
2009-07-24 12:24 130,048 a------- c:\windows\system32\CNCF2Lb.DLL
2009-07-24 07:57 <DIR> --d----- c:\program files\iPod
2009-07-24 07:57 <DIR> --d----- c:\program files\iTunes
2009-07-21 20:27 <DIR> --d----- c:\program files\Flash Video Recorder
2009-07-21 20:26 <DIR> --d----- c:\windows\Downloaded Installations
2009-07-21 20:00 23 a------- c:\windows\SWFDecompiler.INI
2009-07-21 18:50 <DIR> --d----- c:\documents and settings\chris uhles\dwhelper
2009-07-21 18:18 <DIR> --d----- c:\program files\IrfanView
2009-07-21 17:53 <DIR> --d----- c:\program files\Flash Favorite
2009-07-21 17:08 39,424 a------- c:\windows\zipinst.exe
2009-07-21 17:08 <DIR> --d----- c:\program files\WebVideoCap
2009-07-21 14:54 <DIR> --d----- C:\downloads
2009-07-21 14:54 <DIR> --d----- c:\docume~1\chrisu~1\applic~1\GrabPro
2009-07-21 10:30 73,728 ---sh--- c:\windows\system32\memsys.dll
2009-07-21 10:21 <DIR> --d----- c:\program files\Canon
2009-07-21 09:38 <DIR> --d----- c:\windows\system32\NtmsData
2009-07-20 18:42 <DIR> --d----- c:\docume~1\chrisu~1\applic~1\Bytemobile
2009-07-20 18:42 <DIR> --d----- c:\docume~1\chrisu~1\applic~1\DBUpdater
2009-07-20 18:42 27,072 a------- c:\windows\system32\drivers\PCASp50.sys
2009-07-20 18:42 <DIR> --d----- c:\docume~1\chrisu~1\applic~1\AT&T
2009-07-20 18:42 26,760 a----r-- c:\windows\system32\drivers\swmsflt.sys
2009-07-20 18:42 <DIR> --d----- c:\docume~1\chrisu~1\applic~1\Sierra Wireless
2009-07-20 18:29 26,496 a----r-- c:\windows\system32\drivers\RimSerial.sys
2009-07-20 18:29 <DIR> --d----- c:\program files\common files\Motorola Shared
2009-07-20 18:29 <DIR> --d----- C:\Research in Motion
2009-07-20 18:29 <DIR> --d----- c:\program files\Sierra Wireless Inc
2009-07-20 18:29 <DIR> --d----- c:\program files\common files\Research in Motion
2009-07-20 18:29 <DIR> --d----- c:\program files\AT&T
2009-07-20 18:29 <DIR> --d----- c:\docume~1\alluse~1\applic~1\AT&T
2009-07-20 18:26 <DIR> --d----- c:\program files\Option
2009-07-20 17:33 10,384 a------- c:\windows\system32\drivers\LBeepKE.sys
2009-07-20 17:33 301,656 a------- c:\windows\system32\BtCoreIf.dll
2009-07-20 17:33 170,512 a------- c:\windows\system32\kemutb.dll
2009-07-20 17:33 145,936 a------- c:\windows\system32\KemUtil.dll
2009-07-20 17:33 117,264 a------- c:\windows\system32\KemWnd.dll
2009-07-20 17:33 84,496 a------- c:\windows\system32\KemXML.dll
2009-07-20 17:29 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-20 17:29 21,504 a------- c:\windows\system32\drivers\hidserv.dll
2009-07-20 17:29 1,418,120 a------- c:\windows\system32\wdfcoinstaller01005.dll
2009-07-20 17:29 14,736 a------- c:\windows\system32\drivers\nuidfltr.sys
2009-07-20 17:29 <DIR> --d----- c:\program files\Microsoft IntelliType Pro
2009-07-20 14:18 33 a------- c:\windows\Multimedia manager.INI
2009-07-20 12:35 21,504 a------- c:\windows\system32\hidserv.dll
2009-07-20 12:35 21,504 a------- c:\windows\system32\dllcache\hidserv.dll
2009-07-20 12:30 14,592 a------- c:\windows\system32\drivers\kbdhid.sys
2009-07-20 12:30 14,592 a------- c:\windows\system32\dllcache\kbdhid.sys
2009-07-20 12:00 <DIR> --d----- c:\program files\TntWare
2009-07-20 12:00 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}
2009-07-17 16:58 <DIR> --d----- C:\ConvertTemp
2009-07-16 21:47 <DIR> --d----- c:\program files\VideoLAN
2009-07-16 04:10 <DIR> --d----- c:\program files\Trend Micro
2009-07-15 00:45 <DIR> --d----- c:\docume~1\chrisu~1\applic~1\MSNInstaller
2009-07-13 19:29 <DIR> --d----- c:\docume~1\chrisu~1\applic~1\Samsung
2009-07-13 19:13 174,592 a------- c:\windows\system32\framedyn.dll
2009-07-13 19:13 137,884 a------- c:\windows\system32\drivers\sscdmdm.sys
2009-07-13 19:13 80,272 a------- c:\windows\system32\drivers\sscdbus.sys
2009-07-13 19:13 11,877 a------- c:\windows\system32\drivers\sscdcmnt.sys
2009-07-13 19:13 11,877 a------- c:\windows\system32\drivers\sscdcm.sys
2009-07-13 19:13 11,188 a------- c:\windows\system32\drivers\sscdwhnt.sys
2009-07-13 19:13 11,188 a------- c:\windows\system32\drivers\sscdwh.sys
2009-07-13 19:13 10,864 a------- c:\windows\system32\drivers\sscdmdfl.sys
2009-07-13 19:13 <DIR> --d----- c:\windows\system32\Samsung_USB_Drivers
2009-07-13 19:13 766 a------- c:\windows\system32\Uninstall.ico
2009-07-13 19:13 5,632 a------- c:\windows\system32\drivers\StarOpen.sys
2009-07-13 19:13 <DIR> --d----- c:\program files\Samsung
2009-07-13 17:07 <DIR> --d----- c:\docume~1\chrisu~1\applic~1\LG Electronics
2009-07-13 17:06 320 a------- C:\Incoming Mails.csv

==================== Find3M ====================

2009-08-05 23:44 16,384 a------- c:\windows\ld12.exe
2009-08-05 23:43 15,872 ----h--- c:\windows\pp10.exe
2009-08-05 23:43 18,432 a------- c:\windows\sodinpix1249530210.ExE
2009-08-05 23:43 86,016 a------- c:\windows\mstre19.exe
2009-08-05 23:43 37,376 a------- c:\windows\freddy56.exe
2009-06-02 06:12 102,912 -------- c:\windows\system32\dllcache\iecompat.dll
2009-05-13 01:15 915,456 a------- c:\windows\system32\wininet.dll
2009-05-13 01:15 5,936,128 -------- c:\windows\system32\dllcache\mshtml.dll
2009-05-13 01:15 915,456 -------- c:\windows\system32\dllcache\wininet.dll
2004-03-16 17:21 143,360 ---sh--- c:\windows\system32\winup.exe
2009-05-04 07:32 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat

============= FINISH: 13:35:34.54 ===============

BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:21 PM

Posted 06 August 2009 - 04:29 PM

Hello cmuhles,

Posted Image

I need for you to go offline completely and disable ALL your protective programs after you download ComboFix, but before you run it. Sometimes those programs interfere with it, and we don't want that! :thumbup2:

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe

2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.


Please do this:
1. Download HijackThis™ here:
http://www.trendsecure.com/portal/en-US/th.../hijackthis.php

2. Click 'Do a System Scan and Save log'.
The HJT log will open in notepad.

Thanks,
tea

Edited by teacup61, 06 August 2009 - 04:30 PM.

Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 cmuhles

cmuhles
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:21 PM

Posted 06 August 2009 - 09:27 PM

Thanks for your help, Tea! ~~~~

ComboFix 09-08-06.01 - Chris Uhles 08/06/2009 19:40.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.671 [GMT -4:00]
Running from: c:\documents and settings\Chris Uhles\My Documents\DOWNLOADS\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-1232732179-1253765105-2384872684-1003
c:\windows\010112010146120114.dat
c:\windows\0101120101465453.dat
c:\windows\0101120101465749.dat
c:\windows\934fdfg34fgjf23
c:\windows\freddy56.exe
c:\windows\Installer\1cdb7f5.msi
c:\windows\jmmark2.dat
c:\windows\ld12.exe
c:\windows\mstre19.exe
c:\windows\pp10.exe
c:\windows\system32\sqlite3.dll
c:\windows\system32\winup.exe
c:\windows\th823567.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SfX


((((((((((((((((((((((((( Files Created from 2009-07-07 to 2009-08-07 )))))))))))))))))))))))))))))))
.

2009-08-06 03:48 . 2009-08-06 03:48 1 ----a-w- c:\windows\ectbbyn.dat
2009-08-06 03:47 . 2009-08-06 03:52 9167 ----a-w- c:\windows\th1234.dat
2009-08-06 03:43 . 2009-08-06 03:43 -------- d-----w- c:\program files\BrowserCtl
2009-08-06 03:43 . 2009-08-06 03:43 18432 ----a-w- c:\windows\sodinpix1249530210.ExE
2009-08-06 03:43 . 2009-08-06 03:44 247 ----a-w- c:\windows\prxid93ps.dat
2009-08-05 22:44 . 2009-08-05 22:44 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{318921B0-B116-452F-ADB3-553ABE4A9546}
2009-08-05 22:44 . 2008-06-23 18:55 2360533 -c--a-w- c:\documents and settings\All Users\Application Data\{318921B0-B116-452F-ADB3-553ABE4A9546}\rp250driverinstaller.exe
2009-08-05 22:43 . 2008-04-14 04:15 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-08-05 22:43 . 2008-04-14 04:15 60032 ----a-w- c:\windows\system32\dllcache\usbaudio.sys
2009-08-05 22:40 . 2003-11-01 20:19 17920 ----a-w- c:\windows\system32\drivers\ceusbaud.sys
2009-07-25 18:26 . 2009-07-25 18:32 -------- d-----w- c:\documents and settings\Chris Uhles\.ehdc
2009-07-25 18:26 . 2009-07-25 18:26 -------- d-----w- c:\windows\Sun
2009-07-25 18:26 . 2009-07-25 18:25 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-25 18:25 . 2009-07-25 18:25 -------- d-----w- c:\program files\Java
2009-07-25 18:24 . 2009-07-25 18:24 152576 ----a-w- c:\documents and settings\Chris Uhles\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-07-25 18:20 . 2008-04-14 04:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-07-25 18:20 . 2008-04-14 04:15 15104 ----a-w- c:\windows\system32\dllcache\usbscan.sys
2009-07-24 16:25 . 2006-09-13 18:00 74240 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP830 Series Printer\LanguageModules\0409\CNMsr7Q.dll
2009-07-24 16:25 . 2006-09-13 18:00 73216 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP830 Series Printer\LanguageModules\0411\CNMlr7Q.dll
2009-07-24 16:25 . 2006-09-13 18:00 42496 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP830 Series Printer\LanguageModules\0411\CNMsr7Q.dll
2009-07-24 16:25 . 2006-09-13 18:00 334848 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP830 Series Printer\LanguageModules\0409\CNMur7Q.dll
2009-07-24 16:25 . 2006-09-13 18:00 249344 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP830 Series Printer\LanguageModules\0411\CNMur7Q.dll
2009-07-24 16:25 . 2006-09-13 18:00 130048 ----a-w- c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon MP830 Series Printer\LanguageModules\0409\CNMlr7Q.dll
2009-07-24 16:25 . 2009-07-24 16:25 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonBJ
2009-07-24 16:25 . 2006-09-13 18:00 197632 ----a-w- c:\windows\system32\CNMLM7Q.DLL
2009-07-24 16:25 . 2009-07-24 16:25 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2009-07-24 16:24 . 2006-09-30 03:12 3072 ----a-w- c:\windows\system32\CNCFLbUS.DLL
2009-07-24 16:24 . 2006-09-30 03:12 2560 ----a-w- c:\windows\system32\CNCFLbJP.DLL
2009-07-24 16:24 . 2006-09-30 03:12 49152 ----a-w- c:\windows\system32\CNCFMSb.EXE
2009-07-24 16:24 . 2006-09-25 23:49 194560 ----a-w- c:\windows\system32\CNCC830.DLL
2009-07-24 16:24 . 2006-09-14 00:28 37888 ----a-w- c:\windows\system32\CNCI830.DLL
2009-07-24 16:24 . 2006-06-30 03:29 106496 ----a-w- c:\windows\system32\cncisco.dll
2009-07-24 16:24 . 2005-11-02 00:19 143360 ----a-w- c:\windows\system32\CNCL830.DLL
2009-07-24 16:24 . 2006-09-30 03:12 130048 ----a-w- c:\windows\system32\CNCF2Lb.DLL
2009-07-24 16:24 . 2009-07-24 16:24 -------- d--h--w- c:\program files\CanonBJ
2009-07-24 11:57 . 2009-07-24 11:57 -------- d-----w- c:\program files\iPod
2009-07-24 11:57 . 2009-07-24 11:58 -------- d-----w- c:\program files\iTunes
2009-07-24 11:53 . 2009-07-24 11:53 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-22 00:27 . 2009-07-22 00:27 8854 ----a-r- c:\documents and settings\Chris Uhles\Application Data\Microsoft\Installer\{F9CF85B4-73D1-4020-96CB-174E16D42974}\Uninstall_FVR_F9CF85B473D1402096CB174E16D42974.exe
2009-07-22 00:27 . 2009-07-22 00:27 49152 ----a-r- c:\documents and settings\Chris Uhles\Application Data\Microsoft\Installer\{F9CF85B4-73D1-4020-96CB-174E16D42974}\SWF_Converter.exe_F9CF85B473D1402096CB174E16D42974.exe
2009-07-22 00:27 . 2009-07-22 00:27 49152 ----a-r- c:\documents and settings\Chris Uhles\Application Data\Microsoft\Installer\{F9CF85B4-73D1-4020-96CB-174E16D42974}\Player.exe_F9CF85B473D1402096CB174E16D42974.exe
2009-07-22 00:27 . 2009-07-22 00:27 49152 ----a-r- c:\documents and settings\Chris Uhles\Application Data\Microsoft\Installer\{F9CF85B4-73D1-4020-96CB-174E16D42974}\FVR_Player.exe_F9CF85B473D1402096CB174E16D42974.exe
2009-07-22 00:27 . 2009-07-22 00:27 49152 ----a-r- c:\documents and settings\Chris Uhles\Application Data\Microsoft\Installer\{F9CF85B4-73D1-4020-96CB-174E16D42974}\FVR.exe1_F9CF85B473D1402096CB174E16D42974.exe
2009-07-22 00:27 . 2009-07-22 00:27 49152 ----a-r- c:\documents and settings\Chris Uhles\Application Data\Microsoft\Installer\{F9CF85B4-73D1-4020-96CB-174E16D42974}\FVR.exe_F9CF85B473D1402096CB174E16D42974.exe
2009-07-22 00:27 . 2009-07-22 00:27 49152 ----a-r- c:\documents and settings\Chris Uhles\Application Data\Microsoft\Installer\{F9CF85B4-73D1-4020-96CB-174E16D42974}\ARPPRODUCTICON.exe
2009-07-22 00:27 . 2009-07-22 00:27 -------- d-----w- c:\program files\Flash Video Recorder
2009-07-22 00:26 . 2009-07-22 00:26 -------- d-----w- c:\windows\Downloaded Installations
2009-07-21 22:50 . 2009-07-21 22:50 -------- d-----w- c:\documents and settings\Chris Uhles\dwhelper
2009-07-21 22:31 . 2009-07-21 22:31 0 ----a-w- c:\windows\nsreg.dat
2009-07-21 22:31 . 2009-07-21 22:31 -------- d-----w- c:\documents and settings\Chris Uhles\Local Settings\Application Data\Mozilla
2009-07-21 22:18 . 2009-07-21 22:18 -------- d-----w- c:\program files\IrfanView
2009-07-21 21:53 . 2009-07-22 00:22 -------- d-----w- c:\program files\Flash Favorite
2009-07-21 21:08 . 2009-07-21 21:26 -------- d-----w- c:\program files\WebVideoCap
2009-07-21 21:08 . 2009-07-21 21:08 39424 ----a-w- c:\windows\zipinst.exe
2009-07-21 18:54 . 2009-07-21 21:13 -------- d-----w- C:\downloads
2009-07-21 18:54 . 2009-07-21 18:54 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\GrabPro
2009-07-21 18:53 . 2009-07-21 20:57 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\Orbit
2009-07-21 14:30 . 2009-08-06 23:40 73728 --sh--w- c:\windows\system32\memsys.dll
2009-07-21 14:21 . 2009-07-21 14:21 -------- d-----w- c:\program files\Canon
2009-07-21 13:53 . 2009-07-21 20:07 -------- d-----w- c:\documents and settings\Big Red
2009-07-21 13:38 . 2009-07-28 00:00 -------- d-----w- c:\windows\system32\NtmsData
2009-07-21 12:53 . 2009-07-21 12:53 -------- d-----w- c:\documents and settings\Chris Uhles\Local Settings\Application Data\Help
2009-07-20 22:44 . 2009-07-20 22:44 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Bytemobile
2009-07-20 22:42 . 2009-07-20 22:42 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\Bytemobile
2009-07-20 22:42 . 2009-07-20 22:42 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\DBUpdater
2009-07-20 22:42 . 2008-11-21 01:59 27072 ----a-w- c:\windows\system32\drivers\PCASp50.sys
2009-07-20 22:42 . 2009-07-20 22:42 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\AT&T
2009-07-20 22:42 . 2009-07-20 22:42 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\Sierra Wireless
2009-07-20 22:42 . 2008-08-22 14:05 26760 ----a-r- c:\windows\system32\drivers\swmsflt.sys
2009-07-20 22:29 . 2007-01-18 14:24 26496 ----a-r- c:\windows\system32\drivers\RimSerial.sys
2009-07-20 22:29 . 2009-07-20 22:29 -------- d-----w- c:\program files\Common Files\Motorola Shared
2009-07-20 22:29 . 2009-07-20 22:29 -------- d-----w- c:\program files\Sierra Wireless Inc
2009-07-20 22:29 . 2009-07-20 22:29 -------- d-----w- C:\Research in Motion
2009-07-20 22:29 . 2009-07-20 22:29 -------- d-----w- c:\program files\Common Files\Research in Motion
2009-07-20 22:29 . 2009-07-20 22:29 -------- d-----w- c:\program files\AT&T
2009-07-20 22:29 . 2009-07-20 22:29 -------- d-----w- c:\documents and settings\All Users\Application Data\AT&T
2009-07-20 22:26 . 2009-07-20 22:26 -------- d-----w- c:\program files\Option
2009-07-20 21:34 . 2009-07-20 21:34 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\Logitech
2009-07-20 21:34 . 2009-07-20 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\LogiShrd
2009-07-20 21:33 . 2008-12-19 03:43 10384 ----a-w- c:\windows\system32\drivers\LBeepKE.sys
2009-07-20 21:33 . 2009-02-19 04:26 301656 ----a-w- c:\windows\system32\BtCoreIf.dll
2009-07-20 21:33 . 2009-02-19 04:27 84496 ----a-w- c:\windows\system32\KemXML.dll
2009-07-20 21:33 . 2009-02-19 04:27 117264 ----a-w- c:\windows\system32\KemWnd.dll
2009-07-20 21:33 . 2009-02-19 04:27 145936 ----a-w- c:\windows\system32\KemUtil.dll
2009-07-20 21:33 . 2009-02-19 04:27 170512 ----a-w- c:\windows\system32\kemutb.dll
2009-07-20 21:32 . 2009-07-20 21:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Logitech
2009-07-20 21:32 . 2009-07-20 21:33 -------- d-----w- c:\program files\Common Files\Logishrd
2009-07-20 21:32 . 2009-07-20 21:32 -------- d-----w- c:\program files\Logitech
2009-07-20 21:29 . 2008-04-14 09:41 21504 ----a-w- c:\windows\system32\drivers\hidserv.dll
2009-07-20 21:29 . 2009-06-01 17:43 14736 ----a-w- c:\windows\system32\drivers\nuidfltr.sys
2009-07-20 21:29 . 2009-06-01 17:43 1418120 ----a-w- c:\windows\system32\wdfcoinstaller01005.dll
2009-07-20 21:29 . 2009-07-20 21:29 -------- d-----w- c:\program files\Microsoft IntelliType Pro
2009-07-20 16:35 . 2008-04-14 09:41 21504 ----a-w- c:\windows\system32\hidserv.dll
2009-07-20 16:35 . 2008-04-14 09:41 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll
2009-07-20 16:30 . 2008-04-14 04:09 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-07-20 16:30 . 2008-04-14 04:09 14592 ----a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-07-20 16:00 . 2009-04-20 15:52 2799221 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\SetupTntMPD.exe
2009-07-20 16:00 . 2009-07-20 16:00 -------- d-----w- c:\program files\TntWare
2009-07-20 16:00 . 2009-07-20 16:00 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}
2009-07-20 15:58 . 2009-04-20 15:51 107184 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\IA_BundleFiles_Design.dll\IA_BundleFiles.dll
2009-07-20 15:58 . 2009-04-20 15:51 2141360 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\IA_TntWare_Design.dll\IA_TntWare.dll
2009-07-20 15:58 . 2009-04-20 15:51 2305712 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\95AB52C8\C0DF715E\TntTranslator.exe
2009-07-20 15:58 . 2008-08-07 03:04 433152 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\mMSI.dll\mMSIExec.dll
2009-07-20 15:58 . 2008-08-07 03:04 428032 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\mMDACRun.dll\mMDACExec.dll
2009-07-20 15:58 . 2008-08-07 03:04 407040 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\mWinRun.dll\mWinRunExec.dll
2009-07-20 15:58 . 2009-04-20 15:51 778416 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\9D76A04F\C0DF715E\HelpAndManualTrxTool.exe
2009-07-20 15:58 . 2009-04-20 15:51 3225264 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\244632A3\C0DF715E\TntSync.exe
2009-07-20 15:58 . 2009-04-20 15:51 2209456 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\9F7830EF\C0DF715E\TntCrypt.exe
2009-07-20 15:58 . 2009-04-20 15:51 6042288 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\18EBDE8\C0DF715E\TntMPD.exe
2009-07-20 15:58 . 2006-05-14 14:25 476672 -c--a-w- c:\documents and settings\All Users\Application Data\{848A0085-1BC9-42D0-82D7-7F1C4F1A9BF1}\OFFLINE\D97374AE\B7C2C7E8\7za.exe
2009-07-19 03:27 . 2009-07-19 03:28 1914000 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-07-19 03:27 . 2009-07-19 14:11 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-19 03:27 . 2009-07-19 14:11 -------- d-----w- c:\program files\NOS
2009-07-17 20:58 . 2009-07-17 20:58 -------- d-----w- C:\ConvertTemp
2009-07-17 01:48 . 2009-07-20 18:57 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\vlc
2009-07-17 01:47 . 2009-07-17 01:47 -------- d-----w- c:\program files\VideoLAN
2009-07-16 08:10 . 2009-07-16 08:10 -------- d-----w- c:\program files\Trend Micro
2009-07-15 04:45 . 2009-07-15 04:45 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\MSNInstaller
2009-07-13 23:29 . 2009-07-13 23:29 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\Samsung
2009-07-13 23:13 . 2006-05-04 04:53 174592 ----a-w- c:\windows\system32\framedyn.dll
2009-07-13 23:13 . 2005-12-22 18:24 11188 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
2009-07-13 23:13 . 2005-12-22 18:24 11188 ----a-w- c:\windows\system32\drivers\sscdwh.sys
2009-07-13 23:13 . 2005-12-22 18:24 137884 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
2009-07-13 23:13 . 2005-12-22 18:24 11877 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
2009-07-13 23:13 . 2005-12-22 18:24 11877 ----a-w- c:\windows\system32\drivers\sscdcm.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-07 00:34 . 2009-07-02 00:46 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\skypePM
2009-08-06 23:13 . 2009-07-02 00:46 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\Skype
2009-08-05 22:44 . 2008-11-16 19:50 -------- d-----w- c:\program files\DigiTech
2009-08-05 21:57 . 2009-07-02 00:23 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-03 02:15 . 2009-07-02 01:05 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\Apple Computer
2009-07-28 00:36 . 2008-08-19 16:52 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\Canon
2009-07-24 11:57 . 2009-07-02 01:04 -------- d-----w- c:\program files\Common Files\Apple
2009-07-22 00:24 . 2009-05-04 11:29 -------- d-----w- c:\program files\Windows Live Toolbar
2009-07-21 20:09 . 2009-07-02 00:22 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\InstallShield
2009-07-21 14:22 . 2008-09-18 05:17 -------- d-----w- c:\program files\InterVideo
2009-07-21 13:54 . 2008-09-18 05:20 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\InterVideo
2009-07-21 13:54 . 2008-11-14 00:57 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\Amazon
2009-07-20 22:18 . 2009-05-04 11:10 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-20 22:04 . 2009-07-02 00:22 74400 ----a-w- c:\documents and settings\Chris Uhles\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-20 21:32 . 2009-05-04 11:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-20 21:29 . 2009-07-20 21:29 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-20 21:03 . 2009-06-06 17:46 -------- d-----w- c:\documents and settings\All Users\Application Data\VeriFace
2009-07-20 20:42 . 2009-07-02 12:34 -------- d-----w- c:\program files\HP
2009-07-18 01:35 . 2009-07-02 12:35 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-07-15 04:45 . 2009-07-02 12:38 -------- d-----w- c:\program files\Yahoo!
2009-07-06 06:12 . 2009-05-04 11:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-03 06:44 . 2009-05-04 11:14 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-03 06:32 . 2009-07-03 06:32 -------- d-----w- c:\program files\AGES
2009-07-03 06:29 . 2009-07-03 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-07-03 06:15 . 2009-07-03 06:15 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-07-03 05:44 . 2009-07-03 05:44 -------- d-----w- c:\program files\Zondervan
2009-07-03 04:50 . 2009-07-03 04:50 -------- d-----w- c:\program files\MSXML 4.0
2009-07-03 04:14 . 2009-07-02 12:44 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\HP
2009-07-02 12:47 . 2009-07-02 12:47 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\Yahoo!
2009-07-02 12:47 . 2009-07-02 12:47 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2009-07-02 12:43 . 2009-07-02 12:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-07-02 12:35 . 2009-07-02 12:35 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-07-02 04:08 . 2009-05-04 11:28 342864 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-02 04:06 . 2009-05-04 11:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-07-02 01:05 . 2009-07-02 01:05 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-02 01:05 . 2009-07-02 01:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-02 01:05 . 2009-07-02 01:05 -------- d-----w- c:\program files\Bonjour
2009-07-02 01:05 . 2009-07-02 01:04 -------- d-----w- c:\program files\QuickTime
2009-07-02 01:04 . 2009-07-02 01:04 -------- d-----w- c:\program files\Apple Software Update
2009-07-02 01:04 . 2009-07-02 01:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-07-02 00:46 . 2009-07-02 00:46 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-07-02 00:45 . 2009-07-02 00:45 -------- d-----w- c:\program files\Common Files\Skype
2009-07-02 00:45 . 2009-07-02 00:45 -------- d-----r- c:\program files\Skype
2009-07-02 00:45 . 2009-07-02 00:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-07-02 00:28 . 2009-07-02 00:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Windows Live Toolbar
2009-07-02 00:28 . 2009-07-02 00:22 -------- d-----w- c:\documents and settings\Chris Uhles\Application Data\ID Vault
2009-07-02 00:26 . 2009-07-02 00:26 -------- d-----w- c:\documents and settings\All Users\Application Data\IsolatedStorage
2009-07-02 00:26 . 2009-07-02 00:26 -------- d-----w- c:\documents and settings\All Users\Application Data\GuardID Systems
2009-06-01 17:43 . 2009-06-01 17:43 5500 ----a-w- c:\windows\Fonts\SWMacro.otf
2009-05-28 21:39 . 2009-05-28 21:39 127984 ----a-w- c:\windows\Fonts\Swkeys1.ttf
2009-05-13 05:15 . 2004-08-04 20:00 915456 ----a-w- c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-06-06 17:46 241752 ----a-w- c:\windows\system32\IcnOvrly.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-02 24264488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-04-09 1512744]
"IdeaNotesUser"="c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe" [2009-01-17 234160]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"BisonMnt"="c:\windows\BisonC07\BisonM07.exe" [2008-10-14 32768]
"VeriFaceManager"="c:\program files\Lenovo\VeriFaceIII\PManage.exe" [2009-06-06 323584]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2009-01-04 4462464]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2008-12-26 1277952]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-15 623992]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-06-01 1501064]
"AT&T Communication Manager"="c:\program files\AT&T\Communication Manager\ATTCM.exe" [2008-12-01 33280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-03-24 17567744]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-7-20 809488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 04:30 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"= 8085:TCP:browserctl

R?2 browserctl;browserctl;c:\windows\sySTEM32\SvchoSt.ExE -k browserctl [8/4/2004 4:00 PM 14336]
R1 browserctldrv;browserctldrv;c:\program files\BrowserCtl\BrowserCtl.sys [8/5/2009 11:43 PM 9472]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [1/11/2008 5:50 AM 30312]
R2 DDNIMSGService;DDNIMSGService;c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [1/17/2009 2:59 AM 185008]
R2 DDNIService;DDNIService;c:\program files\DDNI\DIBS\DDNIService.exe [5/4/2009 7:52 AM 164528]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\qstart.sys\config\DVMExportService.exe [3/25/2009 10:20 PM 315392]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [7/20/2009 5:33 PM 10384]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [5/4/2009 7:17 AM 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [5/4/2009 7:17 AM 48192]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [6/6/2009 1:50 PM 9472]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [5/4/2009 7:10 AM 1684736]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [11/20/2008 10:07 PM 113152]
S3 CEUSBAUD;DigiTech USB MIDI Driver;c:\windows\system32\drivers\ceusbaud.sys [8/5/2009 6:40 PM 17920]
S3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\drivers\Gt51Ip.sys [2/18/2008 4:14 PM 106624]
S3 GT72UBUS;GT 72 U BUS;c:\windows\system32\drivers\gt72ubus.sys [2/8/2008 12:00 PM 59648]
S3 GTPTSER;GT PT SER;c:\windows\system32\drivers\gtptser.sys [3/30/2007 12:38 PM 8064]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [4/13/2006 10:07 PM 28933976]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [5/4/2009 7:11 AM 165888]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [5/4/2009 7:17 AM 81192]
S4 Norton Internet Security;Norton Internet Security;"c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe" /s "Norton Internet Security" /m "c:\program files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll" /prefetch:1 --> c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
browserctl REG_MULTI_SZ browserctl

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-07 c:\windows\Tasks\User_Feed_Synchronization-{E0937533-BB98-490D-955D-A0280C0E943C}.job
- c:\windows\system32\msfeedssync.exe [2009-05-04 10:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: bmnet.dll
FF - ProfilePath - c:\documents and settings\Chris Uhles\Application Data\Mozilla\Firefox\Profiles\yd3krwjc.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-06 20:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BisonMnt = c:\windows\BisonC07\BisonM07.exe????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????`????v?|?????????????S??????????x????x?|???????????????????????|?????????????????X?w???

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(860)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(916)
c:\windows\system32\bmnet.dll

- - - - - - - > 'explorer.exe'(3436)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\windows\system32\IcnOvrly.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-08-07 20:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-07 00:37

Pre-Run: 65,010,696,192 bytes free
Post-Run: 65,808,887,808 bytes free

399

~~`~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

and the HJT file:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:26:06 PM, on 8/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\sySTEM32\SvchoSt.ExE
C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe
C:\Program Files\DDNI\DIBS\DDNIService.exe
C:\QSTART.SYS\config\DVMExportService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\BisonC07\BisonM07.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IdeaNotesUser] C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [BisonMnt] C:\WINDOWS\BisonC07\BisonM07.exe
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin...indows-i586.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AT&T RcAppSvc (ATTRcAppSvc) - SmithMicro Inc. - C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DDNIMSGService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe
O23 - Service: DDNIService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\DIBS\DDNIService.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM - C:\QSTART.SYS\config\DVMExportService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe

--
End of file - 8623 bytes

#4 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:21 PM

Posted 07 August 2009 - 01:05 PM

Hello,

You're welcome. :thumbup2:

Please download Malwarebytes' Anti-Malware from one of these places:
http://www.majorgeeks.com/Malwarebytes_Ant...ware_d5756.html
http://www.besttechie.net/mbam/mbam-setup.exe

Double Click mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Quick Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy&Paste the entire report in your next reply along with a fresh HijackThis log.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

I notice that you do not seem to be running Antivirus software. This is somewhat suicidal in today's digital world. That's why I want you to install one!!

AVG, Avira OR Avast are good FREE antivirus.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#5 cmuhles

cmuhles
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:21 PM

Posted 18 August 2009 - 01:56 PM

Hey Tea...sorry it took so long to accomplish this task and get back to you...I was travelling and didn't have the extra time until today....

It looks like it worked! I'll let you be the final judge of that, butthe malware program seemed to get it all! thanks a bunch!

Here's the logs you requested:
Malwarebytes' Anti-Malware 1.40
Database version: 2650
Windows 5.1.2600 Service Pack 3

8/18/2009 2:41:04 PM
mbam-log-2009-08-18 (14-41-04).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 183364
Time elapsed: 45 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 12

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\program files\browserctl\browserctl.dll (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\browserctl (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\browserctl (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\browserctl (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\browserctldrv (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\browserctl (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\BrowserCtl (Trojan.Agent) -> Delete on reboot.

Files Infected:
c:\program files\browserctl\browserctl.dll (Trojan.Agent) -> Delete on reboot.
C:\Program Files\BrowserCtl\BrowserCtl.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\freddy56.exe.vir (Worm.Koobface) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\ld12.exe.vir (Worm.Koobface) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\mstre19.exe.vir (Worm.Koobface) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\pp10.exe.vir (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8136B96-1D4C-4145-839F-7B8F940A9052}\RP49\A0008534.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8136B96-1D4C-4145-839F-7B8F940A9052}\RP49\A0008536.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8136B96-1D4C-4145-839F-7B8F940A9052}\RP49\A0008537.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8136B96-1D4C-4145-839F-7B8F940A9052}\RP49\A0008538.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\sodinpix1249530210.ExE (Spyware.LdPinch) -> Quarantined and deleted successfully.
C:\WINDOWS\prxid93ps.dat (Malware.Trace) -> Quarantined and deleted successfully.

and the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:52:32 PM, on 8/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe
C:\Program Files\DDNI\DIBS\DDNIService.exe
C:\QSTART.SYS\config\DVMExportService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\BisonC07\BisonM07.exe
C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IdeaNotesUser] C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [BisonMnt] C:\WINDOWS\BisonC07\BisonM07.exe
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AT&T RcAppSvc (ATTRcAppSvc) - SmithMicro Inc. - C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DDNIMSGService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe
O23 - Service: DDNIService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\DIBS\DDNIService.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM - C:\QSTART.SYS\config\DVMExportService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe

--
End of file - 8486 bytes


thanks again...let me know if you see anything else!!
chris

#6 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:21 PM

Posted 21 August 2009 - 04:23 PM

Hello.

Teacup is currently unavailable so I will continue to help you here.

I need to see an update of the condition of your system so please do the following:

Download and run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results soon.
  • Follow the instructions that pop up for posting the results and then click Ok.
  • The black and message box window shall then disappear.
  • Please save both log files on your desktop and post the DDS.txt and zip up and attach Attach.txt as instructed.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

Download and run RootRepeal CR

Please download RootRepeal from the following location and save it to your desktop.
  • Unzip the RootRepeal.zip file it to it's own folder. (If you did not use the "Direct Download" mirror to download RootRepeal).
  • Close/Disable all other programs especially your security programs (anti-spyware, anti-virus, and firewall) Refer to this page, if you are unsure how.
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Double-click on RootRepeal.exe to run it. If you are using Vista, please right-click and run as Administrator...
  • Click the Posted Image tab at the bottom.
  • Now press the Posted Image button.
  • A box will pop up, check the boxes beside All Seven options/scan area
    Posted Image
  • Now click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button. Posted Image
  • Save it as RepealScan and save it to your desktop
  • Reconnect to the internet.
  • Post the contents of that log in your reply please.
Post those logs back in your next reply.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#7 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:21 PM

Posted 24 August 2009 - 02:56 PM

Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 from the last day I replied initially, the topic will need to be closed.

Thanks for understanding.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#8 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:21 PM

Posted 27 August 2009 - 03:44 PM

Hello.

Due to Lack of feedback, this topic is now Closed

If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic in the Hijackthis-Malware Removal forum.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users