ComboFix 10-06-19.01 - Shaun Gordon 06/19/2010 18:09:51.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3066.2158 [GMT -7:00] Running from: c:\documents and settings\[removed]\Desktop\zzz.exe AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Shaun Gordon\g2mdlhlpx.exe c:\windows\system32\Thumbs.db c:\windows\xpsp1hfm.log . ((((((((((((((((((((((((( Files Created from 2010-05-20 to 2010-06-20 ))))))))))))))))))))))))))))))) . 2010-06-20 00:48 . 2010-06-20 00:48 -------- d-----w- c:\documents and settings\Shaun Gordon\Application Data\Avira 2010-06-20 00:28 . 2010-06-20 00:28 -------- d-----w- c:\program files\Avira 2010-06-20 00:28 . 2010-06-20 00:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira 2010-06-20 00:28 . 2010-03-01 17:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys 2010-06-20 00:28 . 2010-02-16 21:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2010-06-20 00:28 . 2009-05-11 19:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys 2010-06-20 00:28 . 2009-05-11 19:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys 2010-06-19 07:38 . 2010-06-19 08:15 -------- d-----w- c:\documents and settings\Shaun Gordon\Application Data\vlc 2010-06-16 01:49 . 2010-06-16 01:49 -------- d-----w- c:\program files\Common Files\Java 2010-06-16 01:48 . 2010-06-16 01:48 411368 ----a-w- c:\windows\system32\deployJava1.dll 2010-06-14 20:59 . 2010-06-14 20:59 -------- d-----w- c:\documents and settings\Shaun Gordon\Application Data\Key Metric Software 2010-06-14 20:51 . 2010-06-14 20:51 -------- d-----w- c:\program files\Key Metric Software 2010-06-14 20:51 . 2010-06-14 20:51 -------- d-----w- c:\program files\Common Files\Key Metric Software 2010-06-14 20:51 . 2010-06-14 20:51 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{1C53AEFE-978A-4FA2-896E-FD4330A2EACC} 2010-06-14 20:51 . 2010-06-14 20:51 -------- d-----w- c:\documents and settings\Shaun Gordon\Local Settings\Application Data\PackageAware 2010-06-14 14:46 . 2010-06-14 14:47 1052224 ----a-w- c:\windows\wpsetup.exe 2010-06-14 14:35 . 2010-06-14 14:38 -------- d-----w- c:\windows\SxsCaPendDel 2010-06-13 16:02 . 2010-06-13 16:02 -------- d-----w- c:\program files\Common Files\Hewlett-Packard 2010-06-13 16:01 . 2004-03-18 23:56 204800 ----a-w- c:\windows\system32\HPZipr12.dll 2010-06-13 16:01 . 2004-03-18 23:55 65536 ----a-w- c:\windows\system32\HPZipm12.exe 2010-06-13 16:01 . 2004-03-18 23:39 57344 ----a-w- c:\windows\system32\HPZisn12.dll 2010-06-13 16:01 . 2004-03-18 23:39 94208 ----a-w- c:\windows\system32\HPZipt12.dll 2010-06-13 16:01 . 2004-03-18 23:38 61440 ----a-w- c:\windows\system32\HPZinw12.exe 2010-06-13 16:01 . 2004-03-18 23:53 278584 ----a-w- c:\windows\system32\HPZidr12.dll 2010-06-13 16:01 . 2010-06-13 16:01 -------- d-----w- c:\program files\HP 2010-06-13 16:00 . 2010-06-13 16:02 102032 ------w- c:\windows\hpoins04.dat 2010-06-13 16:00 . 2004-06-22 11:20 17218 ------w- c:\windows\hpomdl04.dat 2010-06-13 16:00 . 2004-03-22 12:35 21744 ----a-w- c:\windows\system32\drivers\HPZius12.sys 2010-06-13 16:00 . 2004-03-22 12:35 16496 ----a-w- c:\windows\system32\drivers\HPZipr12.sys 2010-06-13 16:00 . 2004-03-22 12:35 51088 ----a-w- c:\windows\system32\drivers\hpzid412.sys 2010-06-13 16:00 . 2004-03-14 10:34 270336 ----a-w- c:\windows\system32\HPZc3212.dll 2010-06-13 16:00 . 2004-04-13 08:10 581632 ----a-w- c:\windows\system32\hpotscl.dll 2010-06-13 16:00 . 2004-04-13 08:10 90112 ----a-w- c:\windows\system32\hpovst08.dll 2010-06-13 16:00 . 2004-03-14 10:32 278528 ----a-w- c:\windows\system32\hpgwiamd.dll 2010-06-13 16:00 . 2004-03-14 10:43 180315 ----a-w- c:\windows\system32\hpzsnt10.dll 2010-06-13 16:00 . 2004-04-07 14:34 196608 ----a-w- c:\windows\system32\hpzcoi10.dll 2010-06-13 16:00 . 2004-04-07 14:33 344064 ----a-w- c:\windows\system32\hpzcon10.dll 2010-06-13 15:48 . 2004-08-04 06:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys 2010-06-13 15:48 . 2004-08-04 06:01 25856 ----a-w- c:\windows\system32\dllcache\usbprint.sys 2010-06-13 02:07 . 2010-06-13 02:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Cisco Systems 2010-06-01 03:52 . 2010-06-16 15:23 -------- d-----w- c:\documents and settings\Shaun Gordon\Application Data\Dropbox . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-06-20 00:36 . 2009-08-15 04:45 -------- d-----w- c:\program files\Microsoft Silverlight 2010-06-20 00:26 . 2009-02-07 11:57 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-06-20 00:26 . 2009-02-07 11:57 -------- d-----w- c:\program files\Symantec 2010-06-20 00:26 . 2009-02-07 11:57 -------- d-----w- c:\program files\Symantec AntiVirus 2010-06-20 00:26 . 2009-02-07 11:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec 2010-06-20 00:23 . 2009-02-08 14:52 -------- d-----w- c:\documents and settings\Shaun Gordon\Application Data\uTorrent 2010-06-18 15:16 . 2009-02-07 01:13 256 ----a-w- c:\windows\system32\pool.bin 2010-06-16 21:02 . 2009-03-25 20:08 664 ----a-w- c:\windows\system32\d3d9caps.dat 2010-06-16 01:49 . 2010-06-16 01:49 503808 ----a-w- c:\documents and settings\Shaun Gordon\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6a7ec756-n\msvcp71.dll 2010-06-16 01:49 . 2010-06-16 01:49 499712 ----a-w- c:\documents and settings\Shaun Gordon\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6a7ec756-n\jmc.dll 2010-06-16 01:49 . 2010-06-16 01:49 348160 ----a-w- c:\documents and settings\Shaun Gordon\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6a7ec756-n\msvcr71.dll 2010-06-16 01:49 . 2010-06-16 01:49 61440 ----a-w- c:\documents and settings\Shaun Gordon\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4fe2fc35-n\decora-sse.dll 2010-06-16 01:49 . 2010-06-16 01:49 12800 ----a-w- c:\documents and settings\Shaun Gordon\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4fe2fc35-n\decora-d3d.dll 2010-06-14 14:43 . 2008-11-28 06:40 -------- d-----w- c:\program files\Java 2010-06-14 14:35 . 2009-07-02 14:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2010-06-01 03:52 . 2010-06-01 03:52 89831 ----a-w- c:\documents and settings\Shaun Gordon\Application Data\Dropbox\bin\Uninstall.exe 2010-05-27 12:20 . 2008-11-28 07:01 -------- d-----w- c:\program files\Microsoft SQL Server 2010-05-27 12:17 . 2008-11-28 06:58 -------- d-----w- c:\program files\Microsoft.NET 2010-05-27 12:02 . 2009-02-08 14:52 -------- d-----w- c:\program files\uTorrent 2010-05-25 01:55 . 2009-03-02 18:14 -------- d-----w- c:\documents and settings\Shaun Gordon\Application Data\Skype 2010-05-10 18:57 . 2010-03-15 17:40 -------- d-----w- c:\documents and settings\Shaun Gordon\Application Data\Research In Motion 2010-05-07 16:11 . 2009-02-07 14:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-05-07 13:14 . 2009-11-28 18:16 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-05-07 12:56 . 2008-11-28 06:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-05-03 01:15 . 2009-02-07 13:58 -------- d-----w- c:\documents and settings\Shaun Gordon\Application Data\Apple Computer 2010-04-29 19:39 . 2009-02-07 14:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-29 19:39 . 2009-02-07 14:14 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-04-27 12:45 . 2009-03-14 13:37 -------- d-----w- c:\documents and settings\Shaun Gordon\Application Data\ZoomBrowser EX 2010-04-27 12:45 . 2009-10-10 23:15 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser 2010-03-31 16:17 . 2010-03-31 16:17 426704 ----a-w- c:\windows\system32\uc_wepic_launching.dll 2009-11-16 15:55 . 2009-11-03 03:31 80 --sh--r- c:\windows\system32\492FE6226D.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Shaun Gordon\Application Data\Dropbox\bin\DropboxExt.13.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Shaun Gordon\Application Data\Dropbox\bin\DropboxExt.13.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Shaun Gordon\Application Data\Dropbox\bin\DropboxExt.13.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GladinetIconOverlay] @="{3C3DC57A-7535-48AF-BB9E-C3576A4F34D0}" [HKEY_CLASSES_ROOT\CLSID\{3C3DC57A-7535-48AF-BB9E-C3576A4F34D0}] 2010-03-18 06:02 192232 ----a-w- c:\program files\Gladinet\Gladinet Cloud Desktop\GlOverlayIcon.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GladinetUploading] @="{959A18D3-9CC9-41e8-B76F-34ED9A89D4EA}" [HKEY_CLASSES_ROOT\CLSID\{959A18D3-9CC9-41e8-B76F-34ED9A89D4EA}] 2010-03-18 06:03 192232 ----a-w- c:\program files\Gladinet\Gladinet Cloud Desktop\GlOverlayIconU.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112] "Google Update"="c:\documents and settings\Shaun Gordon\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-10 133104] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "FingerPrintSoftware"="c:\program files\Lenovo Fingerprint Software\fpapp.exe \s" [X] "BigDogPath323"="Bigdog.exe Lenovo USB WebCam(Video)" [X] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2008-07-03 118784] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-03 1323008] "picon"="c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2008-11-14 357400] "TPFNF7"="c:\progra~1\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-01-07 60704] "TpShocks"="TpShocks.exe" [2008-06-07 181536] "TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-10-01 68976] "EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-06-04 242976] "TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-05-15 487424] "LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2008-08-31 165208] "LPMailChecker"="c:\progra~1\THINKV~1\PrdCtr\LPMLCHK.exe" [2008-08-31 124248] "PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2008-09-18 331776] "BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2008-09-18 208896] "ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-10-27 425984] "ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-10-27 143360] "cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2008-06-14 3073336] "CardScanAgent"="c:\program files\CardScan\CardScan\CardScanAgent.exe" [2008-08-27 152824] "EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-02-19 591696] "TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352] "AirPort Base Station Agent"="c:\program files\AirPort\APAgent.exe" [2009-05-27 753664] "Message Center Plus"="c:\program files\LENOVO\Message Center Plus\MCPLaunch.exe" [2009-05-28 49976] "LenovoTray"="LenovoTray.exe" [2007-04-20 393216] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-04-02 40368] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2008-3-28 596584] Gladinet Cloud Desktop.lnk - c:\windows\Installer\{C630DAAE-F222-48AB-9055-835591011B8F}\_F53F342E66155566A1DC89.exe [2010-4-20 188478] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ATFUS] 2008-10-27 02:41 180224 ------w- c:\windows\system32\FpWinlogonNp.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2] 2006-09-07 00:37 34344 ------w- c:\program files\Lenovo\HOTKEY\notifyf2.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey] 2008-08-08 10:14 28672 ------w- c:\program files\Lenovo\HOTKEY\tphklock.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Shaun Gordon^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk] path=c:\documents and settings\Shaun Gordon\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2010-03-24 18:17 952768 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2010-04-02 18:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM] 2006-08-01 20:35 67112 ------w- c:\progra~1\AIM\aim.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service] 2009-10-10 17:32 203264 ------w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate] 2009-11-20 03:12 623960 ----a-w- c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boingo Wi-Fi] 2009-12-28 21:57 2179 ----a-w- c:\program files\Boingo\Boingo Wi-Fi\Boingo.lnk [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2009-08-10 14:11 133104 -----tw- c:\documents and settings\Shaun Gordon\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM] 2008-10-24 14:14 206112 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2004-08-04 08:06 1667584 ------w- c:\program files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2009-11-11 04:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray] 2009-07-08 17:31 236016 ----a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC] 2008-01-21 20:17 61440 ------w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2009-03-04 16:20 185896 ------w- c:\program files\Common Files\Real\Update_OB\realsched.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\AIM\\aim.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\EpsonNet\\EpsonNet Config V3\\ENConfig.exe"= "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\AirPort\\APAgent.exe"= "c:\\Documents and Settings\\Shaun Gordon\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= "c:\\Documents and Settings\\Shaun Gordon\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Airfoil\\Airfoil.exe"= "c:\\Program Files\\Airfoil\\AirfoilSpeakers.exe"= "c:\\WINDOWS\\Downloaded Program Files\\ijjiOptimizer.exe"= "c:\\ijji\\ENGLISH\\AVA\\binaries\\AVA.exe"= "c:\\Program Files\\Gladinet\\Gladinet Cloud Desktop\\GladinetClient.exe"= "c:\\Program Files\\ijji\\ijji REACTOR\\ijjiOptimizer.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Documents and Settings\\Shaun Gordon\\Application Data\\Dropbox\\bin\\Dropbox.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5353:UDP"= 5353:UDP:Bonjour "57071:TCP"= 57071:TCP:Pando Media Booster "57071:UDP"= 57071:UDP:Pando Media Booster R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [5/14/2008 5:21 PM 19496] R1 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [5/9/2008 6:50 AM 46144] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/19/2010 5:28 PM 135336] R2 ATService;AuthenTec Fingerprint Service;c:\windows\system32\AtService.exe [10/26/2008 7:33 PM 1676536] R2 dtsvc;Data Transfer Service;c:\windows\system32\DTS.exe [10/26/2008 7:38 PM 98304] R2 FingerprintServer;Fingerprint Server;c:\windows\system32\FpLogonServ.exe [10/26/2008 7:41 PM 118784] R2 GladFileMonSvc;GladFileMonSvc;c:\program files\Gladinet\Gladinet Cloud Desktop\GladFileMonSvc.exe [3/17/2010 11:37 PM 25320] R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [11/27/2008 11:47 PM 94208] R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [5/14/2008 5:25 PM 520192] R2 TVT_UpdateMonitor;TVT Windows Update Monitor;c:\program files\Lenovo\Rescue and Recovery\UpdateMonitor.exe [5/9/2008 6:50 AM 360448] R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [11/27/2008 11:25 PM 2058776] R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\drivers\ATSwpWDF.sys [11/27/2008 11:36 PM 482176] R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [11/27/2008 11:04 PM 243856] R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2/22/2008 4:54 PM 37312] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?] S3 ADMonitor;AD Monitor;c:\windows\system32\ADMonitor.exe [10/26/2008 7:38 PM 106496] S3 NANMp50;NANMp50 NDIS Protocol Driver;c:\windows\system32\drivers\NANMp50.sys [2/23/2009 5:50 AM 28224] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [4/25/2008 9:15 AM 1120752] S3 SessionLauncher;SessionLauncher;c:\docume~1\ADMINI~1\LOCALS~1\Temp\DX9\SessionLauncher.exe --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\DX9\SessionLauncher.exe [?] S3 vmfilter323;325 Primax filter service name;c:\windows\system32\drivers\vmfilter323.sys [7/30/2009 3:43 AM 474752] S3 ZSMC326;Lenovo USB Webcam;c:\windows\system32\drivers\usbvm323.sys [7/30/2009 3:43 AM 226816] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelper REG_MULTI_SZ getPlusHelper [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2B219ADB-2CEB-47B6-8170-D5AA85B365A0}] 2009-03-10 21:45 87424 ------w- c:\program files\Capital IQ\Excel Plug-in\CIQControlUtilityCLI.exe . Contents of the 'Scheduled Tasks' folder 2010-06-14 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34] 2010-06-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2209375187-2678357675-3513037540-1008Core.job - c:\documents and settings\Shaun Gordon\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-10 14:11] 2010-06-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2209375187-2678357675-3513037540-1008UA.job - c:\documents and settings\Shaun Gordon\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-10 14:11] 2010-05-25 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job - c:\program files\PCDR5\pcdr5cuiw32.exe [2008-12-12 23:32] 2010-06-20 c:\windows\Tasks\PMTask.job - c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-11-28 16:46] . . ------- Supplementary Scan ------- . uStart Page = hxxp://lenovo.live.com uInternet Connection Wizard,ShellNext = hxxp://www.onlineregister.com/lenovo/?PAGE=thx&LANG=EN&CTRY=United%20States&MODL=2765T6U&PRNM=Lenovo&SRNM=L3AEW1K uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm FF - ProfilePath - c:\documents and settings\Shaun Gordon\Application Data\Mozilla\Firefox\Profiles\574jigcu.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?source=gama&hl=en FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll FF - plugin: c:\documents and settings\Shaun Gordon\Application Data\Move Networks\plugins\npqmp071505000010.dll FF - plugin: c:\documents and settings\Shaun Gordon\Application Data\Move Networks\plugins\npqmp071505000011.dll FF - plugin: c:\documents and settings\Shaun Gordon\Application Data\Mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\Shaun Gordon\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMFireLauncher.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); . - - - - ORPHANS REMOVED - - - - WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file) Notify-NavLogon - (no file) MSConfigStartUp-Ad-Watch - c:\program files\Lavasoft\Ad-Aware\AAWTray.exe MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe AddRemove-Bloomberg SFD Data Dictionary - c:\blp\API\unwise.exe AddRemove-PC-Doctor for Windows - c:\program files\PCDR5\uninst.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-06-19 18:17 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-2209375187-2678357675-3513037540-1008\Software\SecuROM\License information*] "datasecu"=hex:b3,87,d1,6e,bb,88,dc,54,0f,25,70,8f,ac,30,7f,ce,85,78,90,79,dd, 7c,23,53,23,16,15,c0,cb,98,9d,15,bb,47,20,6c,1e,e9,cf,8e,a4,bd,c3,d5,a0,06,\ "rkeysecu"=hex:c1,7e,78,66,bb,51,01,08,59,27,ae,bb,5b,14,50,d5 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1004) c:\windows\system32\FpWinLogonNp.dll c:\program files\Lenovo Fingerprint Software\ATCSSINT.dll c:\program files\Lenovo Fingerprint Software\SharedResources.dll c:\program files\Lenovo Fingerprint Software\FPResource.dll c:\program files\Lenovo\Client Security Solution\CSS_Enroll.dll c:\program files\Lenovo\Client Security Solution\css_banner.dll c:\windows\system32\cssuserdatadispatcher.dll c:\windows\system32\tvttsp.dll c:\windows\system32\tcsrpc.dll c:\windows\system32\Ati2evxx.dll c:\program files\Lenovo\HOTKEY\tphklock.dll - - - - - - - > 'explorer.exe'(4708) c:\documents and settings\Shaun Gordon\Application Data\Dropbox\bin\DropboxExt.13.dll c:\program files\Gladinet\Gladinet Cloud Desktop\GlOverlayIcon.dll c:\program files\Gladinet\Gladinet Cloud Desktop\GlOverlayIconU.dll c:\windows\system32\btmmhook.dll c:\program files\Windows Desktop Search\deskbar.dll c:\program files\Windows Desktop Search\en-us\dbres.dll.mui c:\program files\Windows Desktop Search\dbres.dll c:\program files\Windows Desktop Search\wordwheel.dll c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui c:\program files\Windows Desktop Search\msnlExtRes.dll c:\windows\system32\msi.dll c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ibmpmsvc.exe c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe c:\program files\Intel\WiFi\bin\S24EvMon.exe c:\program files\Common Files\EPSON\eEBAPI\eEBSVC.exe c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Intel\WiFi\bin\EvtEng.exe c:\program files\Flip Video\FlipShare\FlipShareService.exe c:\program files\Avira\AntiVir Desktop\avshadow.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Intel\AMT\LMS.exe c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe c:\windows\System32\TPHDEXLG.exe c:\windows\system32\TpKmpSVC.exe c:\program files\Lenovo\Client Security Solution\tvttcsd.exe c:\program files\Lenovo\Rescue and Recovery\rrservice.exe c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\SearchIndexer.exe c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe c:\program files\lenovo\system update\suservice.exe c:\windows\system32\wscntfy.exe c:\windows\system32\TpShocks.exe c:\program files\Lenovo\HOTKEY\TPONSCR.exe c:\program files\Lenovo\Zoom\TpScrex.exe c:\windows\system32\rundll32.exe c:\windows\Bigdog.exe c:\windows\LenovoTray.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Gladinet\Gladinet Cloud Desktop\GladinetClient.exe c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe c:\program files\Gladinet\Gladinet Cloud Desktop\GladinetPluginHost.exe . ************************************************************************** . Completion time: 2010-06-19 18:21:34 - machine was rebooted ComboFix-quarantined-files.txt 2010-06-20 01:21 Pre-Run: 16,001,470,464 bytes free Post-Run: 15,943,282,688 bytes free - - End Of File - - CF92631B3E150E55391BF2C9B79617B8