ComboFix 09-01-17.04 - Michael 2009-01-18 12:02:39.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1245 [GMT -5:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe AV: BitDefender Antivirus *On-access scanning disabled* (Updated) FW: BitDefender Firewall *disabled* * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\struct~.ini C:\WINDOWS\system32\bszip.dll C:\WINDOWS\system32\tmp.reg . ((((((((((((((((((((((((( Files Created from 2008-12-18 to 2009-01-18 ))))))))))))))))))))))))))))))) . 2009-01-18 12:12 . 54,156 C:\WINDOWS\QTFont.qfn 2009-01-18 12:12 . 1,409 C:\WINDOWS\QTFont.for 2009-01-18 10:18 . 2009-01-18 10:18 d-------- C:\Program Files\Malwarebytes' Anti-Malware 2009-01-18 10:18 . 2009-01-18 10:18 d-------- C:\Documents and Settings\Michael\Application Data\Malwarebytes 2009-01-18 10:18 . 2009-01-18 10:18 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2009-01-18 10:18 . 2009-01-14 16:11 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2009-01-18 10:18 . 2009-01-14 16:11 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2009-01-17 22:58 . 2009-01-17 22:59 d-------- C:\rsit 2009-01-16 13:10 . 2009-01-16 13:10 d-------- C:\Documents and Settings\Michael\Application Data\DivX 2009-01-16 13:08 . 2009-01-16 13:08 d-------- C:\Program Files\DivX 2009-01-15 10:22 . 2009-01-18 12:13 81,984 --a------ C:\WINDOWS\system32\bdod.bin 2009-01-15 09:35 . 2009-01-15 10:05 260 --a------ C:\WINDOWS\system32\BDUpdateV1.xml 2009-01-05 22:40 . 2009-01-05 22:40 d-------- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Setup 2009-01-05 22:40 . 2009-01-05 22:40 d-------- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Output 2009-01-05 22:40 . 2009-01-06 12:43 0 --a------ C:\WINDOWS\system32\eFax_4_3_Port 2009-01-05 22:39 . 2009-01-05 22:41 d-------- C:\Program Files\eFax Messenger 4.3 2009-01-03 00:12 . 2009-01-03 00:12 d-------- C:\Documents and Settings\Michael\Application Data\BitDefender 2009-01-03 00:12 . 2009-01-03 00:15 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender 2009-01-03 00:09 . 2009-01-03 00:12 d-------- C:\Program Files\Common Files\BitDefender 2009-01-02 11:46 . 2009-01-17 01:12 121 --a------ C:\WINDOWS\bdagent.INI 2009-01-02 11:37 . 2009-01-02 11:37 850 --a------ C:\WINDOWS\system32\ProductTweaks.xml 2009-01-02 11:37 . 2009-01-02 11:37 385 --a------ C:\WINDOWS\system32\user_gensett.xml 2009-01-02 11:31 . 2009-01-03 00:12 d-------- C:\Program Files\BitDefender 2008-12-28 22:48 . 2008-03-19 11:09 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-12-28 13:06 . 2008-12-28 13:06 d-------- C:\Program Files\Microsoft Works 2008-12-25 14:47 . 2008-12-28 12:11 d--hs---- C:\Diskeeper 2008-12-25 13:40 . 2008-12-25 13:40 d-------- C:\Program Files\Common Files\Diskeeper Corporation 2008-12-25 13:40 . 2008-12-25 13:40 d-------- C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation 2008-12-23 21:32 . 2008-12-23 21:32 d-------- C:\Documents and Settings\Michael\dwhelper 2008-12-22 17:48 . 2008-05-30 00:58 373,464 --a------ C:\WINDOWS\system32\TIFF32.DLL 2008-12-22 17:48 . 2008-05-30 01:05 360,168 --a------ C:\WINDOWS\system32\MCHXMoNT.dll 2008-12-22 17:48 . 2008-05-30 01:05 250,592 --a------ C:\WINDOWS\system32\MCHRmvNT.dll 2008-12-22 17:48 . 2008-05-30 00:59 230,112 --a------ C:\WINDOWS\system32\BiImgUser.dll 2008-12-22 17:48 . 2008-05-30 00:59 164,568 --a------ C:\WINDOWS\system32\JPEG32.DLL 2008-12-22 17:48 . 2008-05-30 01:05 164,568 --a------ C:\WINDOWS\system32\BuMAppNT.exe 2008-12-22 17:48 . 2008-06-23 14:21 65,248 --a------ C:\WINDOWS\system32\MCHXRsNT.dll 2008-12-22 17:48 . 2006-02-08 13:55 1,078 --a------ C:\WINDOWS\system32\display.ico 2008-12-22 17:47 . 2008-12-22 17:47 d-------- C:\WINDOWS\Crystal 2008-12-22 17:47 . 2009-01-15 22:18 d-------- C:\Program Files\MultiChx 2008-12-22 17:47 . 2008-12-22 17:47 d-------- C:\MultiCHX 2008-12-21 00:22 . 2008-12-21 00:22 d-------- C:\Program Files\Sophos 2008-12-21 00:12 . 2008-12-21 00:12 d-------- C:\Program Files\Trend Micro . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-18 17:12 --------- d-----w C:\Documents and Settings\Michael\Application Data\Skype 2009-01-18 15:14 --------- d-----w C:\Program Files\Azureus 2009-01-18 14:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink 2009-01-18 05:09 --------- d-----w C:\Documents and Settings\Michael\Application Data\U3 2009-01-09 00:21 --------- d-----w C:\Documents and Settings\Michael\Application Data\Azureus 2009-01-09 00:09 --------- d-----w C:\Program Files\PeerGuardian2 2009-01-08 03:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2009-01-07 01:03 --------- d--h--w C:\Program Files\InstallShield Installation Information 2009-01-06 03:39 --------- d-----w C:\Program Files\eFax Messenger 4.4 2009-01-03 17:45 --------- d-----w C:\Program Files\Yahoo! 2009-01-03 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion 2009-01-03 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo! 2009-01-02 16:23 --------- d-----w C:\Program Files\Symantec 2009-01-02 16:23 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2009-01-02 16:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec 2008-12-25 18:40 --------- d-----w C:\Program Files\Diskeeper Corporation 2008-12-24 03:46 --------- d-----w C:\Program Files\CCleaner 2008-12-20 00:14 --------- d-----w C:\Program Files\Spybot - Search & Destroy 2008-12-13 06:40 3,593,216 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll 2008-12-11 10:57 333,952 ------w C:\WINDOWS\system32\dllcache\srv.sys 2008-12-11 00:33 86,016 ----a-w C:\WINDOWS\system32\dpl100.dll 2008-12-11 00:33 200,704 ----a-w C:\WINDOWS\system32\dtu100.dll 2008-12-10 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir 2008-12-09 02:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll 2008-12-09 02:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll 2008-12-09 02:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll 2008-12-09 02:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll 2008-12-06 15:27 --------- d-----w C:\Program Files\Windows Live Safety Center 2008-12-05 17:55 --------- d-----w C:\Documents and Settings\Michael\Application Data\j2 Global 2008-12-05 17:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.4 Output 2008-12-05 16:02 --------- d-----w C:\Program Files\Java 2008-12-04 05:39 --------- d-----w C:\Program Files\Trillian 2008-12-03 04:03 --------- d-----w C:\Documents and Settings\Michael\Application Data\OfficeUpdate12 2008-12-01 23:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet 2008-11-26 21:09 --------- d-----w C:\Program Files\SSH Communications Security 2008-11-26 21:09 --------- d-----w C:\Documents and Settings\Michael\Application Data\SSH 2008-11-26 21:03 --------- d-----w C:\Program Files\NCH Swift Sound 2008-11-26 21:03 --------- d-----w C:\Documents and Settings\Michael\Application Data\NCH Swift Sound 2008-11-25 13:57 3,433 ----a-w C:\Documents and Settings\Michael\Application Data\SAS7_000.DAT 2008-11-25 02:37 --------- d-----w C:\Program Files\NCH Software 2008-11-25 02:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound 2008-11-24 22:26 --------- dc-h--w C:\Documents and Settings\All Users\Application Data\{DF6351C8-2444-425D-96EE-E35367498A3B} 2008-11-24 22:26 --------- d-----w C:\Program Files\SafeIT Security 2008-11-24 22:26 --------- d-----w C:\Program Files\Common Files\SafeIT Security 2008-11-10 10:43 410,984 ----a-w C:\WINDOWS\system32\deploytk.dll 2008-11-06 16:37 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe 2008-11-06 16:37 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2008-11-06 16:35 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll 2008-11-06 16:35 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll 2008-11-06 16:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll 2008-11-06 16:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll 2008-11-06 16:33 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll 2008-11-06 16:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll 2008-11-06 16:33 684,032 ----a-w C:\WINDOWS\system32\DivX.dll 2008-11-06 16:33 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll 2008-10-24 11:21 455,296 ------w C:\WINDOWS\system32\dllcache\mrxsmb.sys 2008-10-23 12:36 286,720 ----a-w C:\WINDOWS\system32\gdi32.dll 2008-10-23 12:36 286,720 ------w C:\WINDOWS\system32\dllcache\gdi32.dll 2008-07-20 15:10 209 ----a-w C:\Documents and Settings\All Users\Application Data\ubnbt.dll 2007-11-20 00:02 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat 2009-01-15 14:04 61,440 ----a-w C:\Program Files\mozilla firefox\components\FFComm.dll 2008-07-16 14:18 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008071620080717\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360] "TPKMAPMN"="C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe" [2004-02-04 20:39 32768] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 12:39 1289000] "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-11-07 14:31 21633320] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 03:01 110592] "TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-03-28 03:01 503808] "TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 20:39 897024] "TPHOTKEY"="C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2005-04-04 14:43 94208] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-09-15 12:57 110592] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-09-15 12:57 512000] "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 08:11 1388544] "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-28 21:29 32768] "PWRMGRTR"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-05-26 01:13 151552] "PSQLLauncher"="C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" [2006-04-25 18:03 31232] "EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-11-17 01:22 237568] "BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-05-26 01:13 208896] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-01-21 20:00 344064] "PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-11 12:01 30248] "IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-11 11:58 46632] "PPort11reminder"="C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2006-11-16 10:01 35368] "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2007-05-17 09:53 780312] "SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2007-03-26 07:43 210472] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13 385024] "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 21:38 623992] "PrettyMay"="C:\Program Files\PrettyMayBusiness\PrettyMay.exe" [2008-09-29 04:49 3067904] "IntelZeroConfig"="C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-07-10 19:30 1351680] "IntelWireless"="C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2008-07-10 19:13 1191936] "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-03-07 03:05 122939] "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 14:07 188416] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 15:15 221184] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-12-12 15:27 81920] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048] "Nuance PDF Professional 5-reminder"="C:\Program Files\Nuance\PDF Professional 5\Ereg\Ereg.exe" [2007-08-31 08:02 328992] "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-05-17 09:52 505368] "PDF5 Registry Controller"="C:\Program Files\Nuance\PDF Professional 5\RegistryController.exe" [2008-02-27 01:20 58656] "PDFHook"="C:\Program Files\Nuance\PDF Professional 5\pdfpro5hook.exe" [2008-02-27 01:21 795936] "WFXSwtch"="C:\PROGRA~1\WinFax\WFXSWTCH.exe" [2002-12-12 07:45 28160] "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-11-10 05:43 136600] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 01:04 39792] "BDAgent"="C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe" [2009-01-15 09:04 741376] "BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe" [2008-10-17 17:02 69632] "eFax 4.3"="C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" [2007-03-06 12:21 116224] "TpShocks"="TpShocks.exe" [2008-06-06 17:21 181536 C:\WINDOWS\system32\TpShocks.exe] "TP4EX"="tp4ex.exe" [2004-11-12 03:07 40960 C:\WINDOWS\system32\TP4EX.exe] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 19:12 110592 C:\WINDOWS\system32\bthprops.cpl] "WD Button Manager"="WDBtnMgr.exe" [2008-05-03 14:01 364544 C:\WINDOWS\system32\WDBtnMgr.exe] "WinFaxAppPortStarter"="wfxsnt40.exe" [2002-12-12 07:45 45568 C:\WINDOWS\system32\WFXSNT40.EXE] C:\Documents and Settings\Michael\Start Menu\Programs\Startup\ Trillian.lnk - C:\Program Files\Trillian\trillian.exe [2008-11-26 1873280] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Polycom Communicator.lnk - C:\Program Files\Polycom\Communicator_for_skype\Application\Polycom_Communicator.exe [2008-08-15 20:42:56 225364] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{A213B520-C6C2-11d0-AF9D-008029E1027E}"= "C:\Program Files\WinFax\WfxSeh32.Dll" [1998-07-27 03:54 38400] "{93994DE8-8239-4655-B1D1-5F4E91300429}"= "C:\PROGRA~1\DVDREG~1\DVDShell.dll" [2004-10-09 14:18 49152] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus] 2006-04-25 18:20 40448 C:\WINDOWS\system32\psqlpwd.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey] 2004-08-12 22:11 24576 C:\WINDOWS\system32\tphklock.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli psqlpwd [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] --a------ 2005-09-09 00:18 57344 C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoNotify] --a------ 2006-07-11 07:24 341504 C:\Program Files\TiVo\Desktop\TiVoNotify.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoServer] --a------ 2006-07-11 07:26 1313792 C:\Program Files\TiVo\Desktop\TiVoServer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TivoTransfer] --a------ 2006-07-11 07:23 1174528 C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "TivoBeacon2"=2 (0x2) "aawservice"=2 (0x2) "iPod Service"=3 (0x3) "Apple Mobile Device"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009 "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service R0 otman5;Open Transation Manager;C:\WINDOWS\system32\drivers\otman5.sys [2004-05-12 13:47:10 65295] R0 Shockprf;Shockprf;C:\WINDOWS\system32\drivers\ApsX86.sys [2008-05-14 15:21:16 114728] R0 TPDIGIMN;TPDIGIMN;C:\WINDOWS\system32\drivers\ApsHM86.sys [2008-05-14 15:21:16 19496] R0 TPDiskPM;TPDiskPM;C:\WINDOWS\system32\drivers\TPDiskPM.sys [2006-04-18 14:50:13 14848] R1 TPPWRIF;TPPWRIF;C:\WINDOWS\system32\drivers\TPPWRIF.SYS [2007-01-31 16:21:06 4442] R3 bdfm;BDFM;C:\WINDOWS\system32\drivers\bdfm.sys [2008-09-18 11:09:12 111112] R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\drivers\bdfndisf.sys [2008-10-17 14:01:04 104328] R3 PlcmAEC;Polycom Communicator;C:\WINDOWS\system32\drivers\PlcmAEC.sys [2008-07-28 10:49:34 512896] R3 TPInput;TPInput;C:\WINDOWS\system32\drivers\TPInput.sys [2006-04-18 14:50:13 6528] R3 TPM11;NSC Integrated Trusted Platform Module 1.1;C:\WINDOWS\system32\drivers\nsctpm11.sys [1980-01-01 02:00:00 14336] R4 BDVEDISK;BDVEDISK;C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-09-04 16:33:26 82696] R4 PDFProFiltSrv;PDFProFiltSrv;C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe [2008-02-27 01:21:48 144672] R4 SlingAgentService;SlingAgent Service;C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe [2008-12-10 18:05:58 88576] R4 SmiHlp;SMI helper driver;C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2006-04-25 18:00:00 3456] R4 XobniService;XobniService;C:\Program Files\Xobni\XobniService.exe [2008-05-16 16:01:16 36352] R4 YahooAUService;Yahoo! Updater;C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 15:48:14 602392] S3 Arrakis3;BitDefender Arrakis Server;C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 12:06:56 118784] S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\system32\drivers\ASPI32.SYS [2006-05-26 15:07:40 16512] S3 ICDSX;Sony IC Recorder (SX);C:\WINDOWS\system32\drivers\IcdSX.sys [2006-04-19 07:57:35 31744] S3 MEMSWEEP2;MEMSWEEP2;\??\C:\WINDOWS\system32\2508.tmp --> C:\WINDOWS\system32\2508.tmp [?] S4 TivoBeacon2;TiVo Beacon;C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe [2006-07-11 07:22:40 857088] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bdx REG_MULTI_SZ scan [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a051f0ee-1409-11dd-8a24-000e9b9da0c1}] \Shell\AutoRun\command - wd_windows_tools\WDEULA.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e75d4ee0-3a8b-11dd-8a67-000e9b9da0c1}] \Shell\AutoRun\command - E:\LaunchU3.exe -a . Contents of the 'Scheduled Tasks' folder 2009-01-18 C:\WINDOWS\Tasks\PMTask.job - C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2006-05-26 01:13] 2009-01-18 C:\WINDOWS\Tasks\User_Feed_Synchronization-{2620EAD7-BC1C-4251-AAE1-29259DC03806}.job - C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 12:58] . . ------- Supplementary Scan ------- . uStart Page = hxxp://my.yahoo.com/ uInternet Settings,ProxyOverride = localhost IE: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm IE: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm IE: Append the content of the link to existing PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML IE: Append the content of the selected links to existing PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML IE: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Append to existing PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML IE: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Create PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML IE: Create PDF file from the content of the link - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML IE: Create PDF files from the selected links - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Open with Nuance PDF Converter 5.0 - C:\Program Files\Nuance\PDF Professional 5\cnvres_eng.dll /100 IE: Send To &Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm Trusted Zone: www.runaware.com C:\WINDOWS\Downloaded Program Files\ssrclicense.txt - C:\WINDOWS\Downloaded Program Files\vnchooks.dll C:\WINDOWS\Downloaded Program Files\ssrc.dll O16 -: {01118F00-3E00-11D2-8470-0060089874ED} hxxp://symantec.atgnow.com/sdccommon/download/ssrc.cab C:\WINDOWS\Downloaded Program Files\ssrc.inf C:\WINDOWS\Downloaded Program Files\sprtctlln.dll - O16 -: {01119400-3E00-11D2-8470-0060089874ED} hxxp://symantec.atgnow.com/sdccommon/download/sprtctlln.cab C:\WINDOWS\Downloaded Program Files\sprtctlln.inf C:\WINDOWS\system32\capicom.dll - C:\WINDOWS\Downloaded Program Files\acpir2.dll O16 -: {2DAD3559-2923-4935-AD49-B673D2539944} hxxps://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab C:\WINDOWS\Downloaded Program Files\acpir.inf C:\WINDOWS\Downloaded Program Files\RtspVapgDecoder.dll - O16 -: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} hxxp://192.168.0.11/RtspVaPgDec.cab FF - ProfilePath - C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\m1avtbsq.default\ FF - component: C:\Program Files\Mozilla Firefox\components\FFComm.dll .