ComboFix 09-01-17.04 - Michael 2009-01-18 12:02:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1245 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
FW: BitDefender Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\struct~.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\tmp.reg
.
((((((((((((((((((((((((( Files Created from 2008-12-18 to 2009-01-18 )))))))))))))))))))))))))))))))
.
2009-01-18 12:12 . 54,156 C:\WINDOWS\QTFont.qfn
2009-01-18 12:12 . 1,409 C:\WINDOWS\QTFont.for
2009-01-18 10:18 . 2009-01-18 10:18
d-------- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-18 10:18 . 2009-01-18 10:18 d-------- C:\Documents and Settings\Michael\Application Data\Malwarebytes
2009-01-18 10:18 . 2009-01-18 10:18 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-18 10:18 . 2009-01-14 16:11 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-01-18 10:18 . 2009-01-14 16:11 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2009-01-17 22:58 . 2009-01-17 22:59 d-------- C:\rsit
2009-01-16 13:10 . 2009-01-16 13:10 d-------- C:\Documents and Settings\Michael\Application Data\DivX
2009-01-16 13:08 . 2009-01-16 13:08 d-------- C:\Program Files\DivX
2009-01-15 10:22 . 2009-01-18 12:13 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2009-01-15 09:35 . 2009-01-15 10:05 260 --a------ C:\WINDOWS\system32\BDUpdateV1.xml
2009-01-05 22:40 . 2009-01-05 22:40 d-------- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Setup
2009-01-05 22:40 . 2009-01-05 22:40 d-------- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Output
2009-01-05 22:40 . 2009-01-06 12:43 0 --a------ C:\WINDOWS\system32\eFax_4_3_Port
2009-01-05 22:39 . 2009-01-05 22:41 d-------- C:\Program Files\eFax Messenger 4.3
2009-01-03 00:12 . 2009-01-03 00:12 d-------- C:\Documents and Settings\Michael\Application Data\BitDefender
2009-01-03 00:12 . 2009-01-03 00:15 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2009-01-03 00:09 . 2009-01-03 00:12 d-------- C:\Program Files\Common Files\BitDefender
2009-01-02 11:46 . 2009-01-17 01:12 121 --a------ C:\WINDOWS\bdagent.INI
2009-01-02 11:37 . 2009-01-02 11:37 850 --a------ C:\WINDOWS\system32\ProductTweaks.xml
2009-01-02 11:37 . 2009-01-02 11:37 385 --a------ C:\WINDOWS\system32\user_gensett.xml
2009-01-02 11:31 . 2009-01-03 00:12 d-------- C:\Program Files\BitDefender
2008-12-28 22:48 . 2008-03-19 11:09 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-12-28 13:06 . 2008-12-28 13:06 d-------- C:\Program Files\Microsoft Works
2008-12-25 14:47 . 2008-12-28 12:11 d--hs---- C:\Diskeeper
2008-12-25 13:40 . 2008-12-25 13:40 d-------- C:\Program Files\Common Files\Diskeeper Corporation
2008-12-25 13:40 . 2008-12-25 13:40 d-------- C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
2008-12-23 21:32 . 2008-12-23 21:32 d-------- C:\Documents and Settings\Michael\dwhelper
2008-12-22 17:48 . 2008-05-30 00:58 373,464 --a------ C:\WINDOWS\system32\TIFF32.DLL
2008-12-22 17:48 . 2008-05-30 01:05 360,168 --a------ C:\WINDOWS\system32\MCHXMoNT.dll
2008-12-22 17:48 . 2008-05-30 01:05 250,592 --a------ C:\WINDOWS\system32\MCHRmvNT.dll
2008-12-22 17:48 . 2008-05-30 00:59 230,112 --a------ C:\WINDOWS\system32\BiImgUser.dll
2008-12-22 17:48 . 2008-05-30 00:59 164,568 --a------ C:\WINDOWS\system32\JPEG32.DLL
2008-12-22 17:48 . 2008-05-30 01:05 164,568 --a------ C:\WINDOWS\system32\BuMAppNT.exe
2008-12-22 17:48 . 2008-06-23 14:21 65,248 --a------ C:\WINDOWS\system32\MCHXRsNT.dll
2008-12-22 17:48 . 2006-02-08 13:55 1,078 --a------ C:\WINDOWS\system32\display.ico
2008-12-22 17:47 . 2008-12-22 17:47 d-------- C:\WINDOWS\Crystal
2008-12-22 17:47 . 2009-01-15 22:18 d-------- C:\Program Files\MultiChx
2008-12-22 17:47 . 2008-12-22 17:47 d-------- C:\MultiCHX
2008-12-21 00:22 . 2008-12-21 00:22 d-------- C:\Program Files\Sophos
2008-12-21 00:12 . 2008-12-21 00:12 d-------- C:\Program Files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-18 17:12 --------- d-----w C:\Documents and Settings\Michael\Application Data\Skype
2009-01-18 15:14 --------- d-----w C:\Program Files\Azureus
2009-01-18 14:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2009-01-18 05:09 --------- d-----w C:\Documents and Settings\Michael\Application Data\U3
2009-01-09 00:21 --------- d-----w C:\Documents and Settings\Michael\Application Data\Azureus
2009-01-09 00:09 --------- d-----w C:\Program Files\PeerGuardian2
2009-01-08 03:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-07 01:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2009-01-06 03:39 --------- d-----w C:\Program Files\eFax Messenger 4.4
2009-01-03 17:45 --------- d-----w C:\Program Files\Yahoo!
2009-01-03 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2009-01-03 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2009-01-02 16:23 --------- d-----w C:\Program Files\Symantec
2009-01-02 16:23 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2009-01-02 16:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-12-25 18:40 --------- d-----w C:\Program Files\Diskeeper Corporation
2008-12-24 03:46 --------- d-----w C:\Program Files\CCleaner
2008-12-20 00:14 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-12-13 06:40 3,593,216 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-12-11 10:57 333,952 ------w C:\WINDOWS\system32\dllcache\srv.sys
2008-12-11 00:33 86,016 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-12-10 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
2008-12-09 02:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-12-09 02:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-12-09 02:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-12-09 02:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-12-06 15:27 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-12-05 17:55 --------- d-----w C:\Documents and Settings\Michael\Application Data\j2 Global
2008-12-05 17:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.4 Output
2008-12-05 16:02 --------- d-----w C:\Program Files\Java
2008-12-04 05:39 --------- d-----w C:\Program Files\Trillian
2008-12-03 04:03 --------- d-----w C:\Documents and Settings\Michael\Application Data\OfficeUpdate12
2008-12-01 23:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-11-26 21:09 --------- d-----w C:\Program Files\SSH Communications Security
2008-11-26 21:09 --------- d-----w C:\Documents and Settings\Michael\Application Data\SSH
2008-11-26 21:03 --------- d-----w C:\Program Files\NCH Swift Sound
2008-11-26 21:03 --------- d-----w C:\Documents and Settings\Michael\Application Data\NCH Swift Sound
2008-11-25 13:57 3,433 ----a-w C:\Documents and Settings\Michael\Application Data\SAS7_000.DAT
2008-11-25 02:37 --------- d-----w C:\Program Files\NCH Software
2008-11-25 02:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-11-24 22:26 --------- dc-h--w C:\Documents and Settings\All Users\Application Data\{DF6351C8-2444-425D-96EE-E35367498A3B}
2008-11-24 22:26 --------- d-----w C:\Program Files\SafeIT Security
2008-11-24 22:26 --------- d-----w C:\Program Files\Common Files\SafeIT Security
2008-11-10 10:43 410,984 ----a-w C:\WINDOWS\system32\deploytk.dll
2008-11-06 16:37 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-11-06 16:37 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-11-06 16:35 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-11-06 16:35 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-11-06 16:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-11-06 16:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-11-06 16:33 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-11-06 16:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-11-06 16:33 684,032 ----a-w C:\WINDOWS\system32\DivX.dll
2008-11-06 16:33 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-10-24 11:21 455,296 ------w C:\WINDOWS\system32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-10-23 12:36 286,720 ------w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-07-20 15:10 209 ----a-w C:\Documents and Settings\All Users\Application Data\ubnbt.dll
2007-11-20 00:02 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2009-01-15 14:04 61,440 ----a-w C:\Program Files\mozilla firefox\components\FFComm.dll
2008-07-16 14:18 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008071620080717\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"TPKMAPMN"="C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe" [2004-02-04 20:39 32768]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 12:39 1289000]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-11-07 14:31 21633320]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 03:01 110592]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-03-28 03:01 503808]
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 20:39 897024]
"TPHOTKEY"="C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2005-04-04 14:43 94208]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-09-15 12:57 110592]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-09-15 12:57 512000]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 08:11 1388544]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-28 21:29 32768]
"PWRMGRTR"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-05-26 01:13 151552]
"PSQLLauncher"="C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" [2006-04-25 18:03 31232]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-11-17 01:22 237568]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-05-26 01:13 208896]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-01-21 20:00 344064]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-11 12:01 30248]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-11 11:58 46632]
"PPort11reminder"="C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2006-11-16 10:01 35368]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2007-05-17 09:53 780312]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2007-03-26 07:43 210472]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13 385024]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 21:38 623992]
"PrettyMay"="C:\Program Files\PrettyMayBusiness\PrettyMay.exe" [2008-09-29 04:49 3067904]
"IntelZeroConfig"="C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-07-10 19:30 1351680]
"IntelWireless"="C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2008-07-10 19:13 1191936]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-03-07 03:05 122939]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 14:07 188416]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 15:15 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-12-12 15:27 81920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
"Nuance PDF Professional 5-reminder"="C:\Program Files\Nuance\PDF Professional 5\Ereg\Ereg.exe" [2007-08-31 08:02 328992]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-05-17 09:52 505368]
"PDF5 Registry Controller"="C:\Program Files\Nuance\PDF Professional 5\RegistryController.exe" [2008-02-27 01:20 58656]
"PDFHook"="C:\Program Files\Nuance\PDF Professional 5\pdfpro5hook.exe" [2008-02-27 01:21 795936]
"WFXSwtch"="C:\PROGRA~1\WinFax\WFXSWTCH.exe" [2002-12-12 07:45 28160]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-11-10 05:43 136600]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 01:04 39792]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe" [2009-01-15 09:04 741376]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe" [2008-10-17 17:02 69632]
"eFax 4.3"="C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" [2007-03-06 12:21 116224]
"TpShocks"="TpShocks.exe" [2008-06-06 17:21 181536 C:\WINDOWS\system32\TpShocks.exe]
"TP4EX"="tp4ex.exe" [2004-11-12 03:07 40960 C:\WINDOWS\system32\TP4EX.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 19:12 110592 C:\WINDOWS\system32\bthprops.cpl]
"WD Button Manager"="WDBtnMgr.exe" [2008-05-03 14:01 364544 C:\WINDOWS\system32\WDBtnMgr.exe]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2002-12-12 07:45 45568 C:\WINDOWS\system32\WFXSNT40.EXE]
C:\Documents and Settings\Michael\Start Menu\Programs\Startup\
Trillian.lnk - C:\Program Files\Trillian\trillian.exe [2008-11-26 1873280]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Polycom Communicator.lnk - C:\Program Files\Polycom\Communicator_for_skype\Application\Polycom_Communicator.exe [2008-08-15 20:42:56 225364]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= "C:\Program Files\WinFax\WfxSeh32.Dll" [1998-07-27 03:54 38400]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "C:\PROGRA~1\DVDREG~1\DVDShell.dll" [2004-10-09 14:18 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-04-25 18:20 40448 C:\WINDOWS\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2004-08-12 22:11 24576 C:\WINDOWS\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-09-09 00:18 57344 C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoNotify]
--a------ 2006-07-11 07:24 341504 C:\Program Files\TiVo\Desktop\TiVoNotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoServer]
--a------ 2006-07-11 07:26 1313792 C:\Program Files\TiVo\Desktop\TiVoServer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoTransfer]
--a------ 2006-07-11 07:23 1174528 C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TivoBeacon2"=2 (0x2)
"aawservice"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 otman5;Open Transation Manager;C:\WINDOWS\system32\drivers\otman5.sys [2004-05-12 13:47:10 65295]
R0 Shockprf;Shockprf;C:\WINDOWS\system32\drivers\ApsX86.sys [2008-05-14 15:21:16 114728]
R0 TPDIGIMN;TPDIGIMN;C:\WINDOWS\system32\drivers\ApsHM86.sys [2008-05-14 15:21:16 19496]
R0 TPDiskPM;TPDiskPM;C:\WINDOWS\system32\drivers\TPDiskPM.sys [2006-04-18 14:50:13 14848]
R1 TPPWRIF;TPPWRIF;C:\WINDOWS\system32\drivers\TPPWRIF.SYS [2007-01-31 16:21:06 4442]
R3 bdfm;BDFM;C:\WINDOWS\system32\drivers\bdfm.sys [2008-09-18 11:09:12 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\drivers\bdfndisf.sys [2008-10-17 14:01:04 104328]
R3 PlcmAEC;Polycom Communicator;C:\WINDOWS\system32\drivers\PlcmAEC.sys [2008-07-28 10:49:34 512896]
R3 TPInput;TPInput;C:\WINDOWS\system32\drivers\TPInput.sys [2006-04-18 14:50:13 6528]
R3 TPM11;NSC Integrated Trusted Platform Module 1.1;C:\WINDOWS\system32\drivers\nsctpm11.sys [1980-01-01 02:00:00 14336]
R4 BDVEDISK;BDVEDISK;C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-09-04 16:33:26 82696]
R4 PDFProFiltSrv;PDFProFiltSrv;C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe [2008-02-27 01:21:48 144672]
R4 SlingAgentService;SlingAgent Service;C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe [2008-12-10 18:05:58 88576]
R4 SmiHlp;SMI helper driver;C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2006-04-25 18:00:00 3456]
R4 XobniService;XobniService;C:\Program Files\Xobni\XobniService.exe [2008-05-16 16:01:16 36352]
R4 YahooAUService;Yahoo! Updater;C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 15:48:14 602392]
S3 Arrakis3;BitDefender Arrakis Server;C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 12:06:56 118784]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\system32\drivers\ASPI32.SYS [2006-05-26 15:07:40 16512]
S3 ICDSX;Sony IC Recorder (SX);C:\WINDOWS\system32\drivers\IcdSX.sys [2006-04-19 07:57:35 31744]
S3 MEMSWEEP2;MEMSWEEP2;\??\C:\WINDOWS\system32\2508.tmp --> C:\WINDOWS\system32\2508.tmp [?]
S4 TivoBeacon2;TiVo Beacon;C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe [2006-07-11 07:22:40 857088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a051f0ee-1409-11dd-8a24-000e9b9da0c1}]
\Shell\AutoRun\command - wd_windows_tools\WDEULA.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e75d4ee0-3a8b-11dd-8a67-000e9b9da0c1}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-01-18 C:\WINDOWS\Tasks\PMTask.job
- C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2006-05-26 01:13]
2009-01-18 C:\WINDOWS\Tasks\User_Feed_Synchronization-{2620EAD7-BC1C-4251-AAE1-29259DC03806}.job
- C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 12:58]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com/
uInternet Settings,ProxyOverride = localhost
IE: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
IE: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
IE: Append the content of the link to existing PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Append the content of the selected links to existing PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
IE: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Append to existing PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Create PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF file from the content of the link - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF files from the selected links - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Open with Nuance PDF Converter 5.0 - C:\Program Files\Nuance\PDF Professional 5\cnvres_eng.dll /100
IE: Send To &Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
Trusted Zone: www.runaware.com
C:\WINDOWS\Downloaded Program Files\ssrclicense.txt - C:\WINDOWS\Downloaded Program Files\vnchooks.dll
C:\WINDOWS\Downloaded Program Files\ssrc.dll
O16 -: {01118F00-3E00-11D2-8470-0060089874ED}
hxxp://symantec.atgnow.com/sdccommon/download/ssrc.cab
C:\WINDOWS\Downloaded Program Files\ssrc.inf
C:\WINDOWS\Downloaded Program Files\sprtctlln.dll - O16 -: {01119400-3E00-11D2-8470-0060089874ED}
hxxp://symantec.atgnow.com/sdccommon/download/sprtctlln.cab
C:\WINDOWS\Downloaded Program Files\sprtctlln.inf
C:\WINDOWS\system32\capicom.dll - C:\WINDOWS\Downloaded Program Files\acpir2.dll
O16 -: {2DAD3559-2923-4935-AD49-B673D2539944}
hxxps://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab
C:\WINDOWS\Downloaded Program Files\acpir.inf
C:\WINDOWS\Downloaded Program Files\RtspVapgDecoder.dll - O16 -: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2}
hxxp://192.168.0.11/RtspVaPgDec.cab
FF - ProfilePath - C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\m1avtbsq.default\
FF - component: C:\Program Files\Mozilla Firefox\components\FFComm.dll
.