ComboFix and Hijack this log files, would any expert step forward and review them please. They are from my personal computer. Its an IBM A31p Laptop running Xp Pro and AVAST antivirus. No know issues at this time except for it may be a bit weighted down with programs in the start menu for which I could also use some support. Thanks in Advance
Thomas Starich Fitchburg WI
ComboFix 07-07-30.2 - "Thomas Starich" 2007-07-30 21:58:32.1 [GMT -5:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.
True
* Created a new restore point
((((((((((((((((((((((((((
((((((((((
((( Other Deletions ))))))))))))))))))))))))))
))))))))))
))))))))))
)))
C:\WINDOWS\installer\5a3db
ff.msi
((((((((((((((((((((((((((
((((((((((
((( Drivers/Services ))))))))))))))))))))))))))
))))))))))
))))))))))
)))
-------\nm
((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-31 ))))))))))))))))))))))))))
)))))
2007-07-30 21:56 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-06-22 08:54 99,904 --------- C:\WINDOWS\system32\driver
s\AnyDVD.s
ys
2007-06-20 16:08 93,128 --------- C:\WINDOWS\system32\ElbyCD
IO.dll
2007-06-04 21:32 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLI
C~1\Winfer
no
((((((((((((((((((((((((((
((((((((((
(((( Find3M Report ))))))))))))))))))))))))))
))))))))))
))))))))))
))))))
2007-07-30 22:05 --------- d-------- C:\DOCUME~1\THOMAS~1\APPLI
C~1\Winfer
no
2007-07-30 20:36 --------- d-------- C:\Program Files\Palm
2007-07-29 13:26 --------- d-------- C:\Program Files\Quicken
2007-07-29 00:00 5427 --------- C:\WINDOWS\system32\EGATHD
RV.SYS
2007-07-27 17:07 783224 --a------ C:\WINDOWS\system32\aswBoo
t.exe
2007-07-27 17:02 94416 --a------ C:\WINDOWS\system32\driver
s\aswmon2.
sys
2007-07-27 17:02 92848 --a------ C:\WINDOWS\system32\driver
s\aswmon.s
ys
2007-07-27 17:00 23152 --a------ C:\WINDOWS\system32\driver
s\aswRdr.s
ys
2007-07-27 16:59 42912 --a------ C:\WINDOWS\system32\driver
s\aswTdi.s
ys
2007-07-27 16:58 26624 --a------ C:\WINDOWS\system32\driver
s\aavmker4
.sys
2007-07-27 16:57 95608 --a------ C:\WINDOWS\system32\AVASTS
S.scr
2007-07-24 09:29 27 --------- C:\WINDOWS\winmail1.dat
2007-07-04 16:27 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-04 13:09 --------- d-------- C:\Program Files\McAfee.com
2007-07-04 13:02 --------- d-------- C:\Program Files\McAfee
2007-06-16 22:27 --------- d-------- C:\Program Files\Documents To Go
2007-05-31 14:33 --------- d-------- C:\DOCUME~1\THOMAS~1\APPLI
C~1\Dassau
ltSystemes
2007-05-31 14:32 --------- d-------- C:\Program Files\Common Files\SolidWorks Shared
2007-05-31 14:31 --------- d-------- C:\Program Files\Common Files\eDrawings2007
2007-05-28 10:52 --------- d-------- C:\Program Files\IBM
2007-05-28 07:48 --------- d-------- C:\DOCUME~1\THOMAS~1\APPLI
C~1\TechSm
ith
2007-05-16 10:12 683520 --------- C:\WINDOWS\system32\inetco
mm.dll
2006-11-12 11:05 92368 --------- C:\DOCUME~1\THOMAS~1\APPLI
C~1\GDIPFO
NTCACHEV1.
DAT
2004-09-11 18:13:42 56 --sh--r C:\WINDOWS\system32\5A745A
B2AD.sys
2006-10-22 04:21:10 5,744 --sh--w C:\WINDOWS\system32\KGyGaA
vL.sys
((((((((((((((((((((((((((
((((((((((
( Reg Loading Points ))))))))))))))))))))))))))
))))))))))
))))))))))
))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWA
RE\Microso
ft\Windows
\CurrentVe
rsion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
4c61-B58F-
2F227FCA9A
08}\PIFSvc
.exe" [2007-03-12 18:30]
"WinfernoUpdate"="C:\Progr
am Files\Common Files\Winferno\WSCUpdtr.ex
e" [2007-01-09 13:41]
"WinFaxAppPortStarter"="wf
xsnt40.exe
" [2001-09-10 15:03 C:\WINDOWS\system32\WFXSNT
40.EXE]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"WFXSwtch"="C:\PROGRA~1\Wi
nFax\WFXSW
TCH.exe" [2001-09-10 15:03]
"UpdateManager"="C:\Progra
m Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 03:01]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\sch
eduler_pro
xy.exe" [2006-12-10 19:36]
"TrackPointSrv"="tp4serv.e
xe" [2005-07-13 04:55 C:\WINDOWS\system32\tp4ser
v.exe]
"TPKMAPHELPER"="C:\Program
Files\ThinkPad\Utilities\T
pKmapAp.ex
e" [2006-06-02 22:00]
"TPHOTKEY"="C:\PROGRA~1\Th
inkPad\Pkg
Mgr\HOTKEY
\TPHKMGR.e
xe" [2006-10-02 11:19]
"TP4EX"="tp4ex.exe" [2005-10-17 01:11 C:\WINDOWS\system32\TP4EX.
exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" [2005-03-11 12:17]
"SunJavaUpdateSched"="C:\P
rogram Files\Java\jre1.6.0_01\bin
\jusched.e
xe" [2007-03-14 03:43]
"SSBkgdUpdate"="C:\Program
Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgd
update.exe
" [2003-10-14 11:22]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.
exe" [2004-04-01 10:52]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
" [2004-08-06 08:27]
"SIE2007"="C:\Program Files\Winferno\Secure IE\SIEPulse.exe" [2006-10-12 10:22]
"SIE2004"="" []
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe"
[2002-04-17 12:42]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe
" [2004-09-18 12:43]
"PDF Converter Registry Controller"="C:\Program Files\ScanSoft\PDF Converter 2.0\\RegistryController.ex
e" [2004-08-18 03:49]
"MISAggregator"="" []
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 04:50 C:\WINDOWS\LOGI_MWX.EXE]
"HPHUPD04"="C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hph
upd04.exe"
[]
"frymxins"="C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl" []
"EZEJMNAP"="C:\PROGRA~1\Th
inkPad\UTI
LIT~1\EzEj
MnAp.Exe" [2007-03-29 02:32]
"DiskeeperSystray"="C:\Pro
gram Files\Diskeeper Corporation\Diskeeper\DkIc
on.exe" [2006-06-07 12:35]
"cssauth"="C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" [2006-07-14 19:13]
"BMMMONWND"="C:\PROGRA~1\T
hinkPad\UT
ILIT~1\Bat
InfEx.dll"
[2005-04-20 01:38]
"BMMLREF"="C:\Program Files\ThinkPad\Utilities\B
MMLREF.EXE
" [2005-04-20 01:38]
"BMMGAG"="C:\PROGRA~1\Thin
kPad\UTILI
T~1\pwrmon
it.dll" [2005-04-20 01:38]
"BLOG"="C:\PROGRA~1\ThinkP
ad\UTILIT~
1\BatLogEx
.DLL" [2005-04-20 01:38]
"avast!"="C:\PROGRA~1\ALWI
LS~1\Avast
4\ashDisp.
exe" [2007-07-27 17:03]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-11-16 21:00]
"AEIWLSTA.EXE"="AEIWLSTA.e
xe" [2001-12-29 00:33 C:\WINDOWS\system32\AEIWLS
TA.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 02:18]
"AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 09:53 C:\WINDOWS\AGRSMMSG.exe]
[HKEY_CURRENT_USER\SOFTWAR
E\Microsof
t\Windows\
CurrentVer
sion\Run]
"TPKMAPMN"="C:\Program Files\ThinkPad\Utilities\T
pKmapMn.ex
e" [2006-06-02 22:00]
"MSKAGENTEXE"="C:\PROGRA~1
\McAfee\SP
AMKI~1\MSK
Agent.exe"
[]
"CommCtr"="C:\PROGRA~1\NET
2PH~1\Comm
Ctr.exe" [2004-05-20 18:43]
"ClickYes Pro"="C:\Program Files\ClickYes Pro\ClickYesPro.exe" [2006-03-07 15:21]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDV
D.exe" [2007-06-23 06:13]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\runo
nce]
"PixelInstall"=1 (0x1)
"Reboot"=1 (0x1)
[HKEY_USERS\.default\softw
are\micros
oft\window
s\currentv
ersion\run
]
"DWQueuedReporting"="C:\PR
OGRA~1\COM
MON~1\MICR
OS~1\DW\dw
trig20.exe
" -t
C:\Documents and Settings\Thomas Starich\Start Menu\Programs\Startup\
Shortcut to mobmeter.exe.lnk - C:\Program Files\Mobile Meter\mobmeter.exe [2004-12-14 08:40:24]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26]
DataViz Inc Messenger.lnk - C:\Program Files\Common Files\DataViz\DvzIncMsgr.e
xe [2006-07-29 18:13:43]
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\Palm\Hotsync.exe [2004-06-09 14:27:34]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Wireless-G Notebook Adapter Utility.lnk - C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe [2006-09-04 22:35:40]
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\polic
ies\system
]
"NoColorChoice"=0 (0x0)
"NoSizeChoice"=0 (0x0)
"NoDispScrSavPage"=0 (0x0)
"NoDispCPL"=0 (0x0)
"NoVisualStyleChoice"=0 (0x0)
"NoDispSettingsPage"=0 (0x0)
"NoDispAppearancePage"=0 (0x0)
"NoDispBackgroundPage"=0 (0x0)
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\poli
cies\explo
rer]
"NoActiveDesktopChanges"=0
(0x0)
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\polic
ies\explor
er]
"NoSaveSettings"=0 (0x0)
"NoThemesTab"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWA
RE\Microso
ft\Windows
\CurrentVe
rsion\Expl
orer\Shell
ExecuteHoo
ks]
"{A213B520-C6C2-11d0-AF9D-
008029E102
7E}"= C:\Program Files\WinFax\WfxSeh32.Dll [1998-07-27 06:54 38400]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\winlogon
\notify\tp
fnf2]
notifyf2.dll 2005-07-05 23:45 28672 C:\WINDOWS\system32\notify
f2.dll
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\winlogon
\notify\tp
hotkey]
tphklock.dll 2006-02-01 16:09 24576 C:\WINDOWS\system32\tphklo
ck.dll
R0 sbp2port;SBP-2 Transport/Protocol Bus Driver;C:\WINDOWS\system32
\DRIVERS\s
bp2port.sy
s
R1 ElbyCDIO;ElbyCDIO Driver;C:\WINDOWS\system32
\Drivers\E
lbyCDIO.sy
s
R1 PQNTDrv;PQNTDrv;C:\WINDOWS
\system32\
drivers\PQ
NTDrv.sys
R1 TPHKDRV;TPHKDRV;C:\WINDOWS
\system32\
drivers\TP
HKDRV.sys
R1 TPPWR;TPPWR;C:\WINDOWS\sys
tem32\driv
ers\Tppwr.
sys
R1 TSMAPIP;TSMAPIP;C:\WINDOWS
\system32\
drivers\TS
MAPIP.SYS
R1 vobcom;vobcom;C:\WINDOWS\s
ystem32\dr
ivers\vobc
om.sys
R1 vobiw;vobiw;C:\WINDOWS\sys
tem32\driv
ers\vobiw.
sys
R2 AdobeActiveFileMonitor4.0;
Adobe Active File Monitor V4;C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileA
gent.exe
R2 EGATHDRV;IBM Access Support;\??\C:\WINDOWS\SYS
TEM32\EGAT
HDRV.SYS
R2 PMEM;PMEM;\??\C:\WINDOWS\S
ystem32\dr
ivers\PMEM
NT.SYS
R2 smi2;smi2;\??\C:\Program Files\SMI2\smi2.sys
R2 SoundMAX Agent Service (default);SoundMAX Agent Service;C:\Program Files\Analog Devices\SoundMAX\SMAgent.e
xe
R2 tvtfilter;tvtfilter;\??\C:
\WINDOWS\s
ystem32\dr
ivers\tvtf
ilter.sys
R2 wfxsvc;WinFax PRO;C:\WINDOWS\System32\WF
XSVC.EXE
R3 AnyDVD;AnyDVD;C:\WINDOWS\s
ystem32\Dr
ivers\AnyD
VD.sys
R3 ASAPIW2K;ASAPIW2K;C:\WINDO
WS\system3
2\Drivers\
ASAPIW2K.s
ys
R3 atmeltpm;atmeltpm;C:\WINDO
WS\system3
2\DRIVERS\
atmeltpm.s
ys
R3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\syst
em32\CBTND
IS5.SYS
R3 cdrdrv;Cdrdrv;C:\WINDOWS\s
ystem32\Dr
ivers\Cdrd
rv.sys
R3 DUSBCamera;IBM UltraPort Camera;C:\WINDOWS\system32
\Drivers\I
BM_501B.SY
S
R3 E100B;Intel(R) PRO Adapter Driver;C:\WINDOWS\system32
\DRIVERS\e
100b325.sy
s
R3 hexmagic;hexmagic;\??\C:\W
INDOWS\sys
tem32\driv
ers\hexmag
ic.sys
R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system
32\DRIVERS
\odysseyIM
3.sys
R3 phildecn;Philips WDM Video Decoder (PHILDECN);C:\WINDOWS\syst
em32\DRIVE
RS\phildec
n.sys
R3 psadd;Lenovo Parties Service Access Device Driver;C:\WINDOWS\system32
\DRIVERS\p
sadd.sys
R3 TNET1130x;Wireless-G Notebook Adapter v.2.0;C:\WINDOWS\system32\
DRIVERS\tn
et1130x.sy
s
R3 Tp4Track;PS/2 TrackPoint Driver;C:\WINDOWS\system32
\DRIVERS\t
p4track.sy
s
R3 TVTPktFilter;TVT Packet Filter Service;C:\WINDOWS\system3
2\DRIVERS\
tvtpktfilt
er.sys
S2 KC180;IBM UltraPORT IrDA;C:\WINDOWS\system32\D
rivers\kci
rusb.sys
S2 NICSer_WPC54G;NICSer_WPC54
G;C:\Progr
am Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
S3 AEIWL;High Rate Wireless LAN MiniPCI Combo Card Driver;C:\WINDOWS\system32
\DRIVERS\A
EIWLNDS.sy
s
S3 Bridge;MAC Bridge;C:\WINDOWS\system32
\DRIVERS\b
ridge.sys
S3 BridgeMP;MAC Bridge Miniport;C:\WINDOWS\system
32\DRIVERS
\bridge.sy
s
S3 BTWDNDIS;Bluetooth LAN Access Server;C:\WINDOWS\system32
\DRIVERS\b
twdndis.sy
s
S3 Dot4 HPH11;Dot4 HPH11;C:\WINDOWS\system32\
DRIVERS\hp
hid411.sys
S3 Dot4;MS IEEE-1284.4 Driver;C:\WINDOWS\system32
\DRIVERS\D
ot4.sys
S3 Dot4Print HPH11;Print Class Driver for IEEE-1284.4 HPH11;C:\WINDOWS\system32\
DRIVERS\hp
hipr11.sys
S3 Dot4Print;Print Class Driver for IEEE-1284.4;C:\WINDOWS\sys
tem32\DRIV
ERS\Dot4Pr
t.sys
S3 Dot4Storage HPH11;Storage Class Driver for IEEE-1284.4 (HPH11);C:\WINDOWS\system3
2\Drivers\
hphs2k11.s
ys
S3 dot4ufd;HP Dot4USB Filter;C:\WINDOWS\system32
\DRIVERS\h
ppaufd0.sy
s
S3 Dot4Usb HPH11;Dot4Usb HPH11;C:\WINDOWS\system32\
drivers\hp
hius11.sys
S3 grmnusb;grmnusb;C:\WINDOWS
\system32\
drivers\gr
mnusb.sys
S3 HPZs2k12;Storage Class Driver for IEEE-1284.4 (HPZ12);C:\WINDOWS\system3
2\Drivers\
hpzs2k12.s
ys
S3 ISLNDIS5;ISLNDIS5 Protocol Driver;\??\C:\PROGRA~1\IBM
\Updater\s
ession\680
1\RECOGN~1
\ISLNDIS5.
SYS
S3 KCIRDA;%KCIRDA.ServiceDesc
%;C:\WINDO
WS\system3
2\DRIVERS\
KCIrNet.sy
s
S3 NAL;Nal Service ;\??\C:\WINDOWS\system32\D
rivers\iqv
w32.sys
S3 PalmUSBD;PalmUSBD;C:\WINDO
WS\system3
2\drivers\
PalmUSBD.s
ys
S3 PCDRDRV;Pcdr CPU Helper Driver;C:\WINDOWS\system32
\drivers\P
CDRDRV.sys
S3 PcdrNt;PcdrNt;C:\WINDOWS\s
ystem32\dr
ivers\Pcdr
Nt.sys
S3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\WINDOWS\system32
\Drivers\R
ootMdm.sys
S3 wltwo48b;2Wire Wireless PC Card Driver;C:\WINDOWS\system32
\DRIVERS\w
ltwo48b.sy
s
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\{35
ae1389-b4c
1-11db-959
3-00028a21
b9cd}]
AutoRun\command- F:\setupSNK.exe
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\{3c
569993-5d6
4-11db-8b4
0-00028a21
b9cd}]
AutoRun\command- F:\setupSNK.exe
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\{5a
0336e0-92c
d-11db-948
5-00028a21
b9cd}]
AutoRun\command- F:\setupSNK.exe
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\{5a
18ab60-f25
8-11da-87c
1-00028a21
b9cd}]
AutoRun\command- F:\setupSNK.exe
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\{d4
97667a-a2a
4-11db-b65
9-00028a21
b9cd}]
AutoRun\command- F:\setupSNK.exe
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\{dd
0de6f0-9af
1-11db-b64
e-00028a21
b9cd}]
AutoRun\command- F:\setupSNK.exe
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\{dd
0de700-9af
1-11db-b64
e-00028a21
b9cd}]
AutoRun\command- F:\setupSNK.exe
*Newly Created Service* - HEXMAGIC
Contents of the 'Scheduled Tasks' folder
2007-07-31 03:13:13 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe
**************************
**********
**********
**********
**********
********
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-30 22:12:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWA
RE\Microso
ft\Windows
NT\CurrentVersion\Prefetch
er]
"TracesProcessed"=dword:00
000217
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
**********
**********
**********
**********
********
Completion time: 2007-07-30 22:17:37 - machine was rebooted
C:\ComboFix-quarantined-fi
les.txt ... 2007-07-30 22:16
--- E O F ---
**************************
**********
*****HIJAC
K THIS Log file *********************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:41:50 PM, on 7/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\ibmpms
vc.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
xe
C:\Program Files\Alwil Software\Avast4\ashServ.ex
e
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileA
gent.exe
C:\Program Files\Symantec\LiveUpdate\
ALUSchedul
erSvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkSe
rvice.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
4c61-B58F-
2F227FCA9A
08}\PIFSvc
.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.e
xe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
C:\Program Files\Common Files\Lenovo\tvt_reg_monit
or_svc.exe
C:\WINDOWS\system32\TpKmpS
VC.exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\Program Files\ThinkPad\Utilities\T
pKmapMn.ex
e
C:\Program Files\ThinkPad\Utilities\T
pKmapMn.ex
e
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Lenovo\Scheduler\tvt
sched.exe
C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
C:\Program Files\Common Files\Lenovo\Logger\logmon
.exe
C:\WINDOWS\System32\WFXSVC
.EXE
C:\Program Files\WinFax\WFXMOD32.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
xe
C:\Program Files\Alwil Software\Avast4\ashWebSv.e
xe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
4c61-B58F-
2F227FCA9A
08}\PIFSvc
.exe
C:\WINDOWS\system32\wfxsnt
40.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\System32\svchos
t.exe
C:\PROGRA~1\WinFax\WFXSWTC
H.exe
C:\WINDOWS\system32\wscntf
y.exe
C:\Program Files\Common Files\Lenovo\Scheduler\sch
eduler_pro
xy.exe
C:\WINDOWS\system32\tp4ser
v.exe
C:\PROGRA~1\ThinkPad\PkgMg
r\HOTKEY\T
PHKMGR.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\Java\jre1.6.0_01\bin
\jusched.e
xe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.
exe
C:\Program Files\ThinkPad\PkgMgr\HOTK
EY\TPONSCR
.exe
C:\Program Files\ThinkPad\PkgMgr\HOTK
EY_1\TpScr
ex.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Winferno\Secure IE\SIEPulse.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\Logi_MwX.Exe
C:\PROGRA~1\ThinkPad\UTILI
T~1\EzEjMn
Ap.Exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\WINDOWS\system32\RunDll
32.exe
C:\PROGRA~1\ALWILS~1\Avast
4\ashDisp.
exe
C:\WINDOWS\system32\AEIWLS
TA.EXE
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ThinkPad\Utilities\T
pKmapMn.ex
e
C:\Program Files\ClickYes Pro\ClickYesPro.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.e
xe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\SlySoft\AnyDVD\AnyDV
D.exe
C:\Program Files\Mobile Meter\mobmeter.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54Cfg.exe
C:\WINDOWS\system32\notepa
d.exe
C:\PROGRA~1\Winferno\SECUR
E~2\Secure
IE.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-F
CE54AD9C20
8} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d
ll
O2 - BHO: Ipswitch.WsftpBrowserHelpe
r - {601ED020-FB6C-11D3-87D8-0
050DA59922
B} - C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre1.6.0_01\bin
\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-B
A8D5E23E04
5} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D
2AAB95CABE
3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-1
7FE6E806AA
0} - (no file)
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
4c61-B58F-
2F227FCA9A
08}\PIFSvc
.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
4c61-B58F-
2F227FCA9A
08}\AlertE
ng.dll"
O4 - HKLM\..\Run: [WinfernoUpdate] "C:\Program Files\Common Files\Winferno\WSCUpdtr.ex
e"
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\WinFax\WFXSWTC
H.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\sch
eduler_pro
xy.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\T
pKmapAp.ex
e -helper
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMg
r\HOTKEY\T
PHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin
\jusched.e
xe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgd
update.exe
" -Embedding -boot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.
exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
" /tray
O4 - HKLM\..\Run: [SIE2007] "C:\Program Files\Winferno\Secure IE\SIEPulse.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [PDF Converter Registry Controller] "C:\Program Files\ScanSoft\PDF Converter 2.0\\RegistryController.ex
e"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hph
upd04.exe"
O4 - HKLM\..\Run: [frymxins] "C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl"
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILI
T~1\EzEjMn
Ap.Exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIc
on.exe"
O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILI
T~1\BatInf
Ex.dll,BMM
AutonomicM
onitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\B
MMLREF.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILI
T~1\pwrmon
it.dll,Sta
rtPwrMonit
or
O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILI
T~1\BatLog
Ex.DLL,Sta
rtBattLog
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast
4\ashDisp.
exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AEIWLSTA.EXE] AEIWLSTA.EXE START
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\RunOnce: [PixelInstall]
O4 - HKLM\..\RunOnce: [Reboot]
O4 - HKCU\..\Run: [TPKMAPMN] C:\Program Files\ThinkPad\Utilities\T
pKmapMn.ex
e
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~
1\MSKAgent
.exe
O4 - HKCU\..\Run: [CommCtr] C:\PROGRA~1\NET2PH~1\CommC
tr.exe -auto
O4 - HKCU\..\Run: [ClickYes Pro] C:\Program Files\ClickYes Pro\ClickYesPro.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDV
D.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICR
OS~1\DW\dw
trig20.exe
" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICR
OS~1\DW\dw
trig20.exe
" -t (User 'Default user')
O4 - Startup: Shortcut to mobmeter.exe.lnk = C:\Program Files\Mobile Meter\mobmeter.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.e
xe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless-G Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe
O8 - Extra context menu item: &Download File - C:\PROGRA~1\Winferno\SECUR
E~2\Script
s\AddToTra
nsferQueue
.htm
O8 - Extra context menu item: &Highlight - C:\PROGRA~1\Winferno\SECUR
E~2\Script
s\highligh
t.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Open PDF in Word (PDF Converter 2.0) - res://C:\Program Files\ScanSoft\PDF Converter 2.0\IEShellExt.dll /100
O8 - Extra context menu item: Zoom &In - C:\PROGRA~1\Winferno\SECUR
E~2\Script
s\zoomin.h
tm
O8 - Extra context menu item: Zoom O&ut - C:\PROGRA~1\Winferno\SECUR
E~2\Script
s\zoomout.
htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_01\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_01\bin
\ssv.dll
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E
8409F9A0BC
5} - C:\Program Files\ThinkPad\PkgMgr\\Pkg
Mgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://www.kodakgallery.comO15 - Trusted Zone: *.mcafee.com
O15 - Trusted Zone:
www.paypal.comO15 - Trusted Zone: ptaweb.state.wi.us
O16 - DPF: {01118F00-3E00-11D2-8470-0
060089874E
D} (SupportSoft RemoteControl Class) -
http://symantec.atgnow.com/sdccommon/download/ssrc.cabO16 - DPF: {01119400-3E00-11D2-8470-0
060089874E
D} (SupportSoft Listener Control) -
http://symantec.atgnow.com/sdccommon/download/sprtctlln.cabO16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {2DAD3559-2923-4935-AD49-B
673D253994
4} (IASRunner Class) -
https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cabO16 - DPF: {474F00F5-3853-492C-AC3A-4
76512BBC33
6} (UploadListView Class) -
http://picasaweb.google.com/s/v/19.11/uploader2.cabO16 - DPF: {4C39376E-FA9D-4349-BACC-D
305C1750EF
3} (EPUImageControl Class) -
http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cabO16 - DPF: {5D6F45B3-9043-443D-A792-1
15447494D2
4} (UnoCtrl Class) -
http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165412271616O16 - DPF: {644E432F-49D3-41A1-8DD5-E
099162EEEC
5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {74FFE28D-2378-11D5-990C-0
0609423508
4} (IBM Access Support) -
https://www.lenovo.com/support/access/aslibmain/content/IbmEgath.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3
EE46475B07
2} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cabO16 - DPF: {E598AC61-4C6F-4F4D-877F-F
AC49CA91FA
3} (acpRunner Class) -
https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpControl.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-F
B9E207A39E
6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5086/mcfscan.cabO23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0
) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileA
gent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
xe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
xx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\
ALUSchedul
erSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.ex
e
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
xe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.e
xe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkSe
rvice.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpms
vc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\1050\Inte
l 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
P~1\LUCOMS
~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-
4c61-B58F-
2F227FCA9A
08}\PIFSvc
.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSv
c.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm
11.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: Lenovo PSA Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv
.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksL
icensing.e
xe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.e
xe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
O23 - Service: ThinkVantage Registry Monitor Service - Unknown owner - C:\Program Files\Common Files\Lenovo\tvt_reg_monit
or_svc.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpS
VC.exe
O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvt
sched.exe
O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\System32\WFXSVC
.EXE
--
End of file - 15823 bytes