Szia!
Ő lenne az:
ComboFix 09-04-27.04 - Ági 9. 04. 28. 7:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.461 [GMT -4:00]
Running from: c:\documents and settings\Ági\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\e1000msg.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-28 )))))))))))))))))))))))))))))))
.
2009-04-28 11:03 . 2009-04-28 11:03 -------- d--h--r c:\documents and settings\Ági\Recent
2009-04-28 11:03 . 2009-04-28 11:03 -------- d--h--r c:\documents and settings\Ági\Recent
2009-04-28 02:36 . 2009-04-28 02:36 -------- d-----w c:\program files\Hijack This 2.02
2009-04-28 02:09 . 2009-04-28 02:09 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-28 02:09 . 2009-04-28 03:18 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-23 03:37 . 2009-04-23 03:37 -------- d-----w c:\documents and settings\Ági\Application Data\Nokia Multimedia Player
2009-04-23 00:59 . 2006-09-26 17:57 28672 ----a-w c:\windows\system32\AVEQT.dll
2009-04-23 00:59 . 2004-12-20 20:19 129024 ----a-w c:\windows\system32\AVERM.dll
2009-04-23 00:59 . 2009-04-23 02:58 -------- d-----w c:\program files\Allok MP3 to AMR Converter
2009-04-23 00:32 . 2009-04-23 00:58 -------- d-----w c:\documents and settings\Ági\Application Data\GetRightToGo
2009-04-22 23:52 . 2009-04-22 23:52 -------- d-----w c:\documents and settings\Ági\Phone Browser
2009-04-22 23:52 . 2009-04-22 23:52 -------- d-----w c:\documents and settings\Ági\Phone Browser
2009-04-22 23:48 . 2009-04-22 23:48 -------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2009-04-22 23:47 . 2009-04-22 23:50 -------- d-----w c:\documents and settings\Ági\Application Data\Nokia
2009-04-22 23:46 . 2009-04-22 23:46 -------- d-----w c:\program files\Common Files\PCSuite
2009-04-22 23:46 . 2009-04-22 23:46 -------- d-----w c:\program files\Common Files\Nokia
2009-04-22 23:46 . 2009-04-22 23:46 -------- d-----w c:\program files\DIFX
2009-04-22 23:46 . 2009-04-22 23:46 -------- d-----w c:\documents and settings\Ági\Application Data\PC Suite
2009-04-22 23:45 . 2009-04-22 23:45 -------- d-----w c:\program files\PC Connectivity Solution
2009-04-22 23:45 . 2007-02-22 15:15 90624 ----a-w c:\windows\system32\nmwcdcls.dll
2009-04-22 23:45 . 2009-04-22 23:46 -------- d-----w c:\program files\Nokia
2009-04-22 23:44 . 2009-04-22 23:44 -------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-04-18 13:01 . 2009-04-18 13:01 -------- d--h--w c:\windows\PIF
2009-04-17 04:35 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-17 04:35 . 2009-02-06 10:39 35328 ------w c:\windows\system32\dllcache\sc.exe
2009-04-17 04:35 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-17 04:35 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-17 04:35 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-17 04:35 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-17 04:35 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-17 04:35 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-17 04:35 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-17 04:35 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-17 04:34 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-17 04:34 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 02:24 . 2009-04-14 02:24 -------- d-----w c:\documents and settings\Ági\Local Settings\Application Data\GHISLER
2009-04-14 02:23 . 2009-04-14 02:23 -------- d-----w c:\documents and settings\Ági\Application Data\Help
2009-04-14 02:23 . 2009-04-14 02:23 -------- d-----w c:\documents and settings\Ági\Local Settings\Application Data\Help
2009-04-12 03:46 . 2009-04-12 03:51 -------- d-----w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-04-12 03:46 . 2009-04-12 03:46 27136 ----a-w c:\windows\system32\drivers\nchssvad.sys
2009-04-12 03:44 . 2009-04-12 03:44 -------- d-----w c:\program files\NCH Software
2009-04-12 03:44 . 2009-04-12 03:55 -------- d-----w c:\program files\NCH Swift Sound
2009-04-12 03:44 . 2009-04-12 03:55 -------- d-----w c:\documents and settings\Ági\Application Data\NCH Swift Sound
2009-04-10 03:36 . 2009-04-10 03:36 -------- d-----w c:\documents and settings\Ági\Application Data\AdobeUM
2009-04-10 03:35 . 2009-04-10 03:35 -------- d-----w c:\documents and settings\Ági\Local Settings\Application Data\Adobe
2009-04-10 03:34 . 2009-04-10 03:34 -------- d-----w c:\program files\Common Files\Adobe
2009-04-10 02:15 . 2009-04-10 02:15 -------- d-----w c:\documents and settings\Ági\Application Data\Ulead Systems
2009-04-10 02:12 . 2009-04-10 02:13 -------- d-----w c:\program files\Common Files\Ulead Systems
2009-04-10 02:12 . 2009-04-10 02:12 -------- d-----w c:\program files\Corel
2009-04-10 02:12 . 2009-04-10 02:13 -------- d-----w c:\documents and settings\All Users\Application Data\Ulead Systems
2009-04-09 03:46 . 2009-04-09 03:46 -------- d-----w c:\program files\MSXML 6.0
2009-04-08 12:05 . 2008-10-16 18:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-04-08 12:05 . 2008-10-16 18:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-04-08 00:24 . 2009-04-08 00:24 -------- d-----w c:\windows\Sun
2009-04-08 00:21 . 2009-04-08 00:21 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-08 00:21 . 2009-04-08 00:21 -------- d-----w c:\documents and settings\Ági\Application Data\Sun
2009-04-07 23:50 . 2009-04-28 11:17 -------- d-----w c:\documents and settings\Ági\Tracing
2009-04-07 23:50 . 2009-04-28 11:17 -------- d-----w c:\documents and settings\Ági\Tracing
2009-04-07 23:49 . 2009-04-07 23:49 -------- d-----w c:\program files\Microsoft Sync Framework
2009-04-07 23:49 . 2009-04-07 23:49 -------- d-----w c:\program files\Microsoft
2009-04-07 23:48 . 2009-04-07 23:48 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-07 23:48 . 2009-04-07 23:50 -------- d-----w c:\program files\Windows Live
2009-04-07 23:46 . 2009-04-07 23:46 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-02 16:34 . 2009-04-02 16:34 -------- d-----w c:\windows\system32\LogFiles
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-28 02:37 . 2009-03-23 09:16 -------- d-----w c:\program files\Windows Media Connect 2
2009-04-28 02:36 . 2009-03-24 02:33 -------- d-----w c:\program files\MagicISO
2009-04-28 02:27 . 2009-03-23 09:30 -------- d-----w c:\program files\PCDR5
2009-04-28 02:27 . 2009-03-23 09:22 -------- d-----w c:\program files\NetWaiting
2009-04-26 04:00 . 2009-03-23 09:35 5427 ----a-w c:\windows\system32\EGATHDRV.SYS
2009-04-10 11:45 . 2009-03-23 09:48 82168 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-10 02:14 . 2009-03-23 09:19 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-09 03:46 . 2009-03-23 09:49 -------- d-----w c:\program files\Microsoft SQL Server
2009-04-08 00:21 . 2009-03-23 09:27 -------- d-----w c:\program files\Java
2009-04-07 23:50 . 2009-03-23 13:25 -------- d-----w c:\program files\Windows Live Toolbar
2009-03-24 03:12 . 2009-03-24 03:11 -------- d-----w c:\program files\Microsoft Expression
2009-03-24 03:02 . 2009-03-24 03:02 -------- d-----w c:\program files\MSBuild
2009-03-24 02:58 . 2009-03-24 02:58 -------- d-----w c:\program files\Microsoft Visual Studio 8
2009-03-24 02:29 . 2009-03-24 02:29 -------- d-----w c:\program files\DAEMON Tools Toolbar
2009-03-24 02:29 . 2009-03-24 02:29 -------- d-----w c:\program files\DAEMON Tools Lite
2009-03-24 02:22 . 2009-03-24 02:22 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-03-24 01:31 . 2009-03-24 01:31 -------- d-----w c:\program files\NeroInstall.bak
2009-03-24 01:14 . 2009-03-24 01:13 -------- d-----w c:\program files\Common Files\Nero
2009-03-24 01:13 . 2009-03-24 01:13 -------- d-----w c:\program files\Nero
2009-03-24 00:31 . 2009-03-24 00:30 -------- d-----w c:\program files\Google
2009-03-23 23:11 . 2009-03-23 23:12 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-03-23 23:09 . 2009-03-23 23:09 -------- d-----w c:\program files\SMPlayer
2009-03-23 22:44 . 2009-03-23 22:44 -------- d-----w c:\program files\Lavasoft
2009-03-23 22:38 . 2009-03-23 22:37 -------- d-----w c:\program files\iTunes
2009-03-23 22:37 . 2009-03-23 22:37 -------- d-----w c:\program files\iPod
2009-03-23 22:37 . 2009-03-23 22:37 -------- d-----w c:\program files\Bonjour
2009-03-23 22:37 . 2009-03-23 22:36 -------- d-----w c:\program files\QuickTime
2009-03-23 22:36 . 2009-03-23 22:36 -------- d-----w c:\program files\Apple Software Update
2009-03-23 22:36 . 2009-03-23 22:36 -------- d-----w c:\program files\Common Files\Apple
2009-03-23 22:35 . 2009-03-23 22:35 -------- d-----w c:\program files\CCleaner
2009-03-23 22:30 . 2009-03-23 22:30 -------- d-----w c:\program files\uTorrent
2009-03-23 22:25 . 2009-03-23 22:25 0 ----a-w c:\windows\nsreg.dat
2009-03-23 13:30 . 2009-03-23 13:30 -------- d-----r c:\program files\Skype
2009-03-23 13:25 . 2009-03-23 13:25 50 ----a-w c:\windows\system32\drivers\LENOVO_1952_VL5.MRK
2009-03-23 12:50 . 2009-03-23 10:36 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-03-23 12:50 . 2009-03-23 10:36 325128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-23 11:27 . 2006-04-30 07:12 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-23 10:35 . 2009-03-23 10:35 -------- d-----w c:\program files\AVG
2009-03-23 09:51 . 2009-03-23 09:51 -------- d-----w c:\program files\Microsoft Small Business
2009-03-23 09:48 . 2009-03-23 13:25 68456 ----a-w c:\documents and settings\Ági\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-23 09:46 . 2009-03-23 09:46 -------- d-----w c:\program files\Activation Assistant for the 2007 Microsoft Office suites
2009-03-23 09:45 . 2009-03-23 09:45 -------- d-----w c:\program files\Microsoft Works
2009-03-23 09:44 . 2009-03-23 09:44 -------- d-----w c:\program files\Microsoft.NET
2009-03-23 09:36 . 2009-03-23 09:30 -------- d-----w c:\program files\Common Files\Lenovo
2009-03-23 09:36 . 2009-03-23 09:21 -------- d-----w c:\program files\Lenovo
2009-03-23 09:35 . 2009-03-23 09:35 23552 ----a-w c:\windows\system32\drivers\psasrv.exe
2009-03-23 09:35 . 2009-03-23 09:35 -------- d-----w c:\program files\SMI2
2009-03-23 09:35 . 2009-03-23 09:35 -------- d-----w c:\program files\TVT SMBus
2009-03-23 09:35 . 2009-03-23 09:35 7012 ----a-w c:\windows\system32\drivers\pmemnt.sys
2009-03-23 09:35 . 2006-11-16 23:14 17536 ----a-w c:\windows\system32\drivers\psadd.sys
2009-03-23 09:34 . 2009-03-23 09:19 -------- d-----w c:\program files\ThinkPad
2009-03-23 09:34 . 2009-03-23 09:34 -------- d-----w c:\program files\Diskeeper Corporation
2009-03-23 09:30 . 2009-03-23 09:30 -------- d-----w c:\program files\Sonic Icons for Lenovo
2009-03-23 09:30 . 2009-03-23 09:17 -------- d-----w c:\program files\Common Files\Installshield
2009-03-23 09:30 . 2009-03-23 09:30 -------- d-----w c:\program files\Common Files\SureThing Shared
2009-03-23 09:30 . 2009-03-23 09:30 -------- d-----w c:\program files\Sonic
2009-03-23 09:30 . 2009-03-23 09:30 -------- d-----w c:\program files\Multimedia Center for Think Offerings
2009-03-23 09:30 . 2009-03-23 09:29 -------- d-----w c:\program files\Common Files\Sonic Shared
2009-03-23 09:28 . 2009-03-23 09:28 -------- d-----w c:\program files\Common Files\InterVideo
2009-03-23 09:28 . 2009-03-23 09:28 -------- d-----w c:\program files\InterVideo
2009-03-23 09:27 . 2009-03-23 09:26 -------- d-----w c:\program files\ThinkVantage
2009-03-23 09:27 . 2009-03-23 09:27 -------- d-----w c:\program files\Common Files\Java
2009-03-23 09:22 . 2009-03-23 09:22 -------- d-----w c:\program files\Digital Line Detect
2009-03-23 09:22 . 2009-03-23 09:22 -------- d-----w c:\program files\CONEXANT
2009-03-23 09:22 . 2009-03-23 09:12 -------- d-----w c:\program files\Analog Devices
2009-03-23 09:21 . 2009-03-23 09:21 0 ---ha-r c:\windows\system32\drivers\IBM_1952_VL5_TP.MRK
2009-03-23 09:21 . 2009-03-23 09:21 -------- d-----w c:\program files\ThinkVantage Fingerprint Software
2009-03-23 09:21 . 2009-03-23 09:21 -------- d-----w c:\program files\Common Files\ThinkVantage Fingerprint Software
2009-03-23 09:21 . 2009-03-23 09:21 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-23 09:20 . 2009-03-23 09:20 21419 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-03-23 09:20 . 2009-03-23 09:20 -------- d-----w c:\program files\Intel
2009-03-23 09:19 . 2009-03-23 09:19 -------- d-----w c:\program files\Synaptics
2009-03-23 09:19 . 2009-03-23 09:19 -------- d-----w c:\program files\MSXML 4.0
2009-03-06 14:22 . 2006-04-30 06:55 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-06 03:59 . 2009-03-23 22:36 36864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-06 03:59 . 2009-03-23 22:36 1900544 ----a-w c:\windows\system32\usbaaplrc.dll
2009-03-03 00:18 . 2006-04-30 06:56 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2006-04-30 06:55 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2006-04-30 06:55 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2006-04-30 06:55 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2006-04-30 06:55 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2006-04-30 06:55 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2006-04-30 06:55 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 22:52 . 2009-02-06 22:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 11:11 . 2006-04-30 06:55 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2006-04-30 06:55 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2006-04-30 06:55 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-03 22:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2006-04-30 06:55 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-05-25 151552]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-05-25 208896]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2006-02-14 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-02-14 512000]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2006-02-23 237568]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2006-06-03 856064]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-07-25 94208]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-07-25 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-07-25 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-07-25 118784]
"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2006-07-04 110592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-08 148888]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2006-07-15 503808]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 196696]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2007-02-19 409600]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2007-02-19 110592]
"PDService.exe"="c:\program files\Lenovo\SafeGuard PrivateDisk\pdservice.exe" [2006-03-13 41472]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-15 2341632]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-23 1601304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360]
"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2006-03-16 106496]
"TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2005-10-17 65536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2006-5-31 622653]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-3-23 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2007-02-19 23:03 32768 ----a-w c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-23 12:50 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-04-26 02:20 40448 ----a-w c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 14:45 28672 ----a-w c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 11:16 24576 ----a-w c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd ACGina
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"94:TCP"= 94:TCP:VRS Recording System Web Control Panel
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-23 951632]
R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-25 29263712]
R3 PAC207;VideoCAM GE111;c:\windows\system32\DRIVERS\pfc027.sys [2005-04-08 162176]
R3 VRSService;VRS Recording System;c:\program files\NCH Swift Sound\VRS\vrs.exe [2009-04-12 794628]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-23 64160]
S0 Shockprf;Shockprf; [x]
S1 ANC;ANC;c:\windows\system32\drivers\ANC.SYS [2005-11-08 11520]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-23 325128]
S1 IBMTPCHK;IBMTPCHK;c:\windows\system32\Drivers\IBMBLDID.sys [2006-01-13 6016]
S1 ShockMgr;ShockMgr; [x]
S1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\Tppwrif.sys [2006-05-25 4442]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-23 298264]
S2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-11 30312]
S2 PrivateDisk;PrivateDisk;c:\program files\Lenovo\SafeGuard PrivateDisk\PrivateDiskM.sys [2006-03-13 58368]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 smi2;smi2;c:\program files\SMI2\smi2.sys [2006-07-14 3968]
S2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [2006-04-26 3456]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{394ba7b3-17f8-11de-8d35-000000000000}]
\Shell\AutoRun\command - wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2009-04-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 23:11]
2009-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-04-28 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2009-03-23 16:13]
.
- - - - ORPHANS REMOVED - - - -
BHO-{6fce5b32-8658-41a9-ad8e-94f28031b82f} - (no file)
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://lenovo.live.com
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Ági\Application Data\Mozilla\Firefox\Profiles\tkdrf1r0.default\
FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-28 07:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1360)
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\windows\system32\biologon.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\remote.dll
c:\program files\ThinkVantage Fingerprint Software\ps2css.dll
c:\windows\system32\tphklock.dll
- - - - - - - > 'lsass.exe'(1416)
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkPad\ConnectUtilities\ACGina.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACON.dll
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgr.dll
c:\program files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll
c:\program files\ThinkPad\ConnectUtilities\ACTurinSupport.dll
c:\program files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\PAStiSvc.exe
c:\program files\Lenovo\System Update\SUService.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\windows\system32\TPHDEXLG.exe
c:\windows\system32\TpKmpSvc.exe
c:\program files\Lenovo\Client Security Solution\tvttcsd.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files\Lenovo\Rescue and Recovery\ADM\IUService.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\Lenovo\Logger\logmon.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\windows\system32\rundll32.exe
c:\program files\ThinkPad\UltraNav Wizard\UNavTray.exe
c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\progra~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Completion time: 2009-04-28 7:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-28 11:19
Pre-Run: 8 246 448 128 bytes free
Post-Run: 8 145 588 224 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
374 --- E O F --- 2009-04-17 07:05