Data\Symantec
2009-05-17 15:36 . 2009-05-17 15:36 -------- d-----w- c:\program files\IBM ThinkVantage
2009-05-17 15:35 . 2009-05-17 15:35 -------- d-----w- c:\program files\Common Files\InterVideo
2009-05-17 15:35 . 2009-05-17 15:35 -------- d-----w- c:\program files\InterVideo
2009-05-17 15:34 . 2009-05-17 15:34 -------- d-----w- c:\program files\PC-Doctor for Windows
2009-05-17 15:34 . 2009-05-17 15:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Lenovo
2009-05-17 15:33 . 2009-05-24 05:20 -------- d-----w- c:\documents and settings\Tobola\Application Data\IBM
2009-05-17 15:33 . 2009-05-17 16:00 -------- d-----w- c:\documents and settings\Bert\Application Data\IBM
2009-05-17 15:33 . 2009-05-17 15:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\IBM
2009-05-17 15:33 . 2009-05-17 15:33 -------- d-----w- c:\program files\IBM
2009-05-17 15:32 . 2009-05-17 15:32 -------- d-----w- c:\program files\ThinkVantage
2009-05-17 15:31 . 2009-05-24 05:20 136 ----a-w- c:\documents and settings\Tobola\Local Settings\Application Data\fusioncache.dat
2009-05-17 15:31 . 2009-05-17 15:31 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2009-05-17 15:27 . 2009-05-17 15:27 -------- d-----w- c:\program files\ATI Technologies
2009-05-17 15:26 . 2009-05-17 15:26 -------- d-----w- c:\program files\Digital Line Detect
2009-05-17 15:26 . 2009-05-17 15:26 -------- d-----w- c:\program files\NetWaiting
2009-05-17 15:26 . 2009-05-17 15:26 -------- d-----w- c:\program files\CONEXANT
2009-05-17 15:26 . 2009-05-17 15:26 -------- d-----w- c:\program files\Analog Devices
2009-05-17 15:26 . 2009-05-17 15:26 0 ---ha-r- c:\windows\system32\drivers\IBM_2529_RCU_TP.MRK
2009-05-17 15:26 . 2009-05-17 15:26 -------- d-----w- c:\program files\Fingerprint Tutorial
2009-05-17 15:22 . 2009-05-17 15:22 -------- d-----w- c:\program files\ThinkVantage Fingerprint Software
2009-05-17 15:22 . 2009-05-17 15:22 -------- d-----w- c:\program files\Common Files\Virtual Token
2009-05-17 15:22 . 2009-05-17 15:22 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-17 15:05 . 2009-05-17 15:05 17801 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-05-17 15:05 . 2009-05-17 15:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2009-05-17 15:04 . 2009-05-17 15:04 -------- d-----w- c:\program files\Intel
2009-05-17 15:02 . 2009-05-17 15:02 -------- d-----w- c:\program files\Lenovo
2009-05-17 15:01 . 2009-05-17 15:01 -------- d--h--w- c:\program files\InstallShield Installation Information
.
------- Sigcheck -------
[7] 2004-08-04 12:00 182912 558635D3AF1C7546D26067D5D9B6959E c:\windows\$NtServicePackUninstall$\ndis.sys
[7] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE71721130D c:\windows\ServicePackFiles\i386\ndis.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2009-07-13 25600]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2009-07-13 25600]
"amsg"="c:\program files\ThinkVantage\AMSG\Amsg .exe" [2005-08-02 475136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2009-07-13 25600]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-13 25600]
"ControlCenter"="c:\program files\ThinkVantage Fingerprint Software\ctlcntr.exe" [2005-07-12 125026]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2009-07-13 25600]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2009-07-13 25600]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-07-29 344064]
"suScheduler"="c:\program files\ThinkVantage\SystemUpdate\UCLauncher.exe" [2005-08-02 40960]
"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2009-07-13 25600]
"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2009-07-13 25600]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2009-07-13 25600]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"cssauth"="c:\program files\IBM ThinkVantage\Client Security Solution\cssauth.exe" [2005-08-03 1988144]
"PDService.exe"="c:\program files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe" [2005-07-07 49152]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-09-26 196696]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2009-07-13 25600]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2009-07-13 25600]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-08-10 139264]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-08-10 208896]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2005-08-12 864256]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2009-07-13 25600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2005-06-23 86016]
"TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2005-08-02 40960]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-07-12 16:45 109664 ----a-w- c:\program files\ThinkVantage Fingerprint Software\psfus.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2005-12-16 00:14 32768 ----a-w- c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 06:45 28672 ----a-w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-06-17 05:23 24576 ----a-w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli csspwntfy
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ThinkVantage\\SystemUpdate\\jre\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11108:TCP"= 11108:TCP:BitComet 11108 TCP
"11108:UDP"= 11108:UDP:BitComet 11108 UDP
"8085:TCP"= 8085:TCP:sfx
R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [5/17/2009 11:02 AM 59904]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [5/17/2009 11:02 AM 4736]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [5/17/2009 11:46 AM 4442]
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [8/2/2005 9:15 PM 13184]
R2 PrivateDisk;PrivateDisk;c:\program files\IBM ThinkVantage\SafeGuard PrivateDisk\privatediskm.sys [6/28/2005 11:26 AM 46142]
R2 smi2;smi2;c:\program files\SMI2\smi2.sys [8/2/2005 8:47 PM 3968]
R2 SmiHlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [7/12/2005 12:37 PM 3328]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-07-13 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2009-05-17 08:10]
2009-05-17 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2009-05-17 00:32]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MSMSGS - c:\program files\Messenger\msmsgs.exe
Notify-NavLogon - (no file)
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uInternet Settings,ProxyOverride = *.local
IE: Send To &Bluetooth - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-13 14:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\ctfmon.exe182 15360 bytes executable
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(292)
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\ThinkVantage Fingerprint Software\psfus.dll
c:\program files\Common Files\Virtual Token\psutil.dll
c:\windows\system32\tphklock.dll
- - - - - - - > 'lsass.exe'(348)
c:\program files\IBM ThinkVantage\Client Security Solution\csspwntfy.dll
c:\program files\IBM ThinkVantage\Client Security Solution\ibmtsp.dll
c:\program files\IBM ThinkVantage\Client Security Solution\tcsrpc.dll
c:\program files\IBM ThinkVantage\Client Security Solution\cssuserdatadispatcher.dll
- - - - - - - > 'explorer.exe'(2616)
c:\windows\system32\WININET.dll
c:\windows\system32\PROCHLP.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Virtual Token\vtserver.exe
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\TPHDEXLG.exe
c:\windows\system32\TpKmpSvc.exe
c:\program files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
c:\program files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
c:\program files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
c:\program files\ThinkVantage\SystemUpdate\UCLauncherService.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\IBM ThinkVantage\Common\Logger\logmon.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\program files\ThinkPad\ConnectUtilities\AcMurocHlpr.exe
c:\windows\system32\rundll32.exe
c:\progra~1\ThinkPad\UTILIT~1\ezejmnap .exe
c:\windows\system32\ctfmon.exe182Classes\exefile\shell\open
c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
c:\program files\ThinkPad\Bluetooth Software\BTTray.exe
c:\program files\Digital Line Detect\DLG.exe
c:\program files\Synaptics\SynTP\syntplpr .exe
c:\progra~1\THINKV~2\PrdCtr\lpmgr .exe
c:\progra~1\Lenovo\PkgMgr\HOTKEY\tphkmgr .exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\Windows Media Player\wmpnscfg .exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2009-07-13 14:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-13 18:27
Pre-Run: 10,259,243,008 bytes free
Post-Run: 10,784,980,992 bytes free
358 --- E O F --- 2009-06-15 02:06