<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Virus] Sending Spam in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r22469955</link>
<description></description>
<language>en</language>
<pubDate>Thu, 10 Dec 2009 11:08:32 EDT</pubDate>
<lastBuildDate>Thu, 10 Dec 2009 11:08:32 EDT</lastBuildDate>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22513960</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : I see you may have Maplestory installed. The program is known to cause problems, and unless you really want to keep it on your system, I recommend uninstalling it.<br><br>Please go to Start -> Run -> <b>cmd</b> and press Enter.  At the command prompt type <b>sfc /scannow</b>, making sure to put a space between the "c" and the slash, and then press Enter.  This will run the System File Checker.  Follow the prompts, and insert your Windows installation CD if requested.  Then please restart your computer.<br><br>Download the latest version of Kaspersky Virus Removal Tool <br><textarea name="code" class="text" cols=50 rows=10>ftp://downloads2.kaspersky-labs.com/devbuilds/AVPTool/index.html&#012;</textarea><!--end code block-->- Disconnect from the Internet (pull your connection cable).<br>- Reboot to <A HREF="http://www.pchell.com/support/safemode.shtml">Safe mode</a>.<br>- Close all other applications and double-click and run the installer.<br>- When AVPTool starts, select all the scanable items except for CD-ROM drives and click the <b>Scan</b> button.<br>- If malware is detected, place a checkmark in the<b> Apply to all</b> box, and click the <b>Delete</b> button (or <b>Disinfect</b> if the button is active).<br>- After the scan finishes, if any threat remains in the Scan window (Red exclamation point), click the <b>Neutralize all</b> button<br>- In the window that opens, place a checkmark in the <b>Apply to all</b> box, and click the <b>Delete</b> button (or <b>Disinfect</b> if the button is active).<br>- If advised that a special disinfection procedure is required which demands system reboot: click the <b>Ok</b> button to close the window.<br>- In the Scan window click the <b>Reports</b> button and select <b>Save to file</b>.<br>- Name the report <b>AVPT.txt</b>, and save it to the Desktop.<br>- Close AVPTool.<br>- You will be prompted if you want to uninstall the program; click <b>Yes</b>.<br>- You will then be prompted that to complete the uninstallation, the computer must be restarted. Select <b>Yes</b> to restart the system.<br>- Reconnect to the Internet.<br>- Copy and paste the <b>first part</b> of the report (<b>Detected</b>) that you saved in your next reply. Do not include the longer list marked <b>Events</b>.<br><br>Please post a new HijackThis log, the requested portion of the Kaspersky log, and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22513960</guid>
<pubDate>Mon, 08 Jun 2009 06:00:13 EDT</pubDate>
</item>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22513729</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Sorry, was out of town for a while.<br><br>And no, I didn't add that. That's a bit odd.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22513729</guid>
<pubDate>Mon, 08 Jun 2009 02:49:43 EDT</pubDate>
</item>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22481882</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : <div class="bquote"><small>said by Superman1234 :</small><br><br><b>ComboFix Log:</b><br>Infected copy of c:\windows\system32\drivers\ndis.sys was found and disinfected <br>Restored copy from - The cat ate it :)<br></div>Did you edit that line?<br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22481882</guid>
<pubDate>Tue, 02 Jun 2009 08:52:54 EDT</pubDate>
</item>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22481143</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : <b>ComboFix Log:</b><br>ComboFix 09-05-31.06 - ATL 06/02/2009  0:39.3 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1022.542 [GMT -7:00]<br>Running from: c:\documents and settings\ATL\Desktop\ComboFix.exe<br>Command switches used :: c:\documents and settings\ATL\Desktop\CFScript.txt<br>AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}<br>FW: Symantec Client Firewall *disabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187}<br><br>FILE ::<br>"c:\windows\system32\barufutu.exe"<br>"c:\windows\system32\BITA20.tmp"<br>"c:\windows\system32\BITA21.tmp"<br>"c:\windows\system32\BITA22.tmp"<br>"c:\windows\system32\fujayagi.dll"<br>"c:\windows\system32\ligenisa.exe"<br>"c:\windows\system32\limehabe.exe"<br>"c:\windows\system32\lonazaki.exe"<br>"c:\windows\system32\ludojila.exe"<br>"c:\windows\system32\malodoso.exe"<br>"c:\windows\system32\nokadeno.exe"<br>"c:\windows\system32\nopededo.dll"<br>"c:\windows\system32\pisabupe.dll"<br>"c:\windows\system32\ratijipe.exe"<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>---- Previous Run -------<br>.<br>c:\documents and settings\All Users\Application Data\Viewpoint<br>c:\windows\system32\barufutu.exe<br>c:\windows\system32\BITA20.tmp<br>c:\windows\system32\BITA21.tmp<br>c:\windows\system32\BITA22.tmp<br>c:\windows\system32\limehabe.exe<br>c:\windows\system32\nopededo.dll<br>c:\windows\system32\pisabupe.dll<br>c:\windows\system32\ratijipe.exe<br><br>Infected copy of c:\windows\system32\drivers\ndis.sys was found and disinfected <br>Restored copy from - The cat ate it :)<br>.<br>(((((((((((((((((((((((((   Files Created from 2009-05-02 to 2009-06-02  )))))))))))))))))))))))))))))))<br>.<br><br>2009-06-01 20:22 . 2009-06-01 23:57&#9;520224&#9;--sha-w-&#9;c:\windows\system32\drivers\fidbox.dat<br>2009-05-31 21:45 . 2009-03-06 14:00&#9;284160&#9;------w-&#9;c:\windows\system32\dllcache\pdh.dll<br>2009-05-31 21:45 . 2005-07-26 04:20&#9;60416&#9;------w-&#9;c:\windows\system32\dllcache\colbact.dll<br>2009-05-31 21:45 . 2009-02-09 10:01&#9;473088&#9;------w-&#9;c:\windows\system32\dllcache\fastprox.dll<br>2009-05-31 21:45 . 2009-02-09 10:01&#9;401408&#9;------w-&#9;c:\windows\system32\dllcache\rpcss.dll<br>2009-05-31 21:45 . 2009-02-06 10:22&#9;110592&#9;------w-&#9;c:\windows\system32\dllcache\services.exe<br>2009-05-31 21:45 . 2009-02-06 09:54&#9;35328&#9;------w-&#9;c:\windows\system32\dllcache\sc.exe<br>2009-05-31 21:45 . 2009-02-06 09:41&#9;227840&#9;------w-&#9;c:\windows\system32\dllcache\wmiprvse.exe<br>2009-05-31 21:45 . 2009-02-09 10:01&#9;617984&#9;------w-&#9;c:\windows\system32\dllcache\advapi32.dll<br>2009-05-31 21:45 . 2009-02-09 10:01&#9;715264&#9;------w-&#9;c:\windows\system32\dllcache\ntdll.dll<br>2009-05-31 21:44 . 2008-04-21 10:02&#9;215552&#9;------w-&#9;c:\windows\system32\dllcache\wordpad.exe<br>2009-05-30 18:32 . 2009-05-30 18:32&#9;--------&#9;dc----w-&#9;c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}<br>2009-05-30 16:51 . 2009-05-30 16:51&#9;--------&#9;d-----w-&#9;c:\program files\Trend Micro<br>2009-05-30 16:43 . 2009-05-26 20:20&#9;40160&#9;----a-w-&#9;c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-05-30 16:43 . 2009-05-30 16:43&#9;--------&#9;d-----w-&#9;c:\program files\Malwarebytes' Anti-Malware<br>2009-05-30 16:43 . 2009-05-26 20:19&#9;19096&#9;----a-w-&#9;c:\windows\system32\drivers\mbam.sys<br>2009-05-22 00:47 . 2009-05-22 00:47&#9;--------&#9;d-s---w-&#9;c:\windows\system32\config\systemprofile\UserData<br>2009-05-21 10:34 . 2009-05-21 10:36&#9;--------&#9;d-----w-&#9;c:\program files\Spybot - Search & Destroy<br>2009-05-21 10:34 . 2009-05-21 10:36&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy<br>2009-05-05 07:13 . 2009-05-05 07:13&#9;--------&#9;d-----w-&#9;c:\documents and settings\ATL\Application Data\Malwarebytes<br>2009-05-05 07:13 . 2009-05-05 07:13&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\Malwarebytes<br>2009-05-03 08:05 . 2009-05-03 08:05&#9;45056&#9;----a-r-&#9;c:\documents and settings\ATL\Application Data\Microsoft\Installer\{8BF863F9-7739-4DA4-B40A-2AD76D571B82}\MapleStory.exe_DB457427E7B9425292170DC5FADE980F.exe<br>2009-05-03 08:05 . 2009-05-03 08:05&#9;45056&#9;----a-r-&#9;c:\documents and settings\ATL\Application Data\Microsoft\Installer\{8BF863F9-7739-4DA4-B40A-2AD76D571B82}\MapleStory.exe1_DB457427E7B9425292170DC5FADE980F.exe<br>2009-05-03 08:05 . 2009-05-03 08:05&#9;10134&#9;----a-r-&#9;c:\documents and settings\ATL\Application Data\Microsoft\Installer\{8BF863F9-7739-4DA4-B40A-2AD76D571B82}\ARPPRODUCTICON.exe<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-06-02 07:42 . 2008-08-07 06:35&#9;40&#9;----a-w-&#9;c:\windows\system32\profile.dat<br>2009-06-02 07:28 . 1980-01-01 07:00&#9;182912&#9;----a-w-&#9;c:\windows\system32\drivers\ndis.sys<br>2009-06-01 23:57 . 2009-06-01 20:22&#9;7172&#9;--sha-w-&#9;c:\windows\system32\drivers\fidbox.idx<br>2009-06-01 20:01 . 2008-08-07 06:35&#9;--------&#9;d-----w-&#9;c:\program files\Common Files\Symantec Shared<br>2009-05-31 06:14 . 2009-03-30 09:42&#9;--------&#9;d-----w-&#9;c:\documents and settings\ATL\Application Data\PC Tools<br>2009-05-03 08:34 . 2009-03-30 09:42&#9;--------&#9;d---a-w-&#9;c:\documents and settings\All Users\Application Data\TEMP<br>2009-05-03 06:35 . 2009-05-03 06:34&#9;--------&#9;d-----w-&#9;c:\documents and settings\All Users\Application Data\PMB Files<br>2009-05-03 06:34 . 2009-05-03 06:34&#9;--------&#9;d-----w-&#9;c:\program files\Pando Networks<br>2009-05-02 21:01 . 2008-08-13 01:49&#9;--------&#9;d-----w-&#9;c:\program files\Warcraft III<br>2009-03-23 08:02 . 2009-03-23 08:02&#9;75048&#9;----a-w-&#9;c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.0.52\SetupAdmin.exe<br>2009-03-20 05:34 . 2008-08-13 01:53&#9;77691&#9;----a-w-&#9;c:\windows\War3Unin.dat<br>2009-03-06 23:45 . 2009-03-30 09:43&#9;130424&#9;----a-w-&#9;c:\windows\system32\drivers\PCTCore.sys<br>2009-03-06 14:00 . 1980-01-01 07:00&#9;284160&#9;----a-w-&#9;c:\windows\system32\pdh.dll<br>2009-03-06 06:59 . 2009-03-23 08:05&#9;1900544&#9;----a-w-&#9;c:\windows\system32\usbaaplrc.dll<br>2009-03-06 06:59 . 2008-12-26 20:30&#9;36864&#9;----a-w-&#9;c:\windows\system32\drivers\usbaapl.sys<br>.<br><br>------- Sigcheck -------<br><br>[-] 2008-04-14 00:12&#9;507904&#9;ED0EF0A136DEC83DF69F04118870003E&#9;c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\winlogon.exe<br>[-] 2008-08-26 05:33&#9;502784&#9;B359DE33041BA9ACAB6392745C3F81ED&#9;c:\windows\system32\winlogon.exe<br><br>[-] 2008-04-14 00:12&#9;295424&#9;FF3477C03BE7201C294C35F684B3479F&#9;c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\termsrv.dll<br>[-] 2008-08-26 05:33&#9;295424&#9;40FFC19A8D4875E9E19CECDC76EF9201&#9;c:\windows\system32\termsrv.dll<br>.<br>(((((((((((((((((((((((((((((   SnapShot@2009-05-31_06.57.42   )))))))))))))))))))))))))))))))))))))))))<br>.<br>+ 2009-06-02 07:19 . 2009-06-02 07:19&#9;16384              c:\windows\Temp\Perflib_Perfdata_75c.dat<br>+ 2009-06-02 07:43 . 2009-06-02 07:43&#9;16384              c:\windows\Temp\Perflib_Perfdata_6e8.dat<br>+ 2009-06-02 07:43 . 2009-06-02 07:43&#9;16384              c:\windows\Temp\Perflib_Perfdata_198.dat<br>+ 2008-08-07 06:12 . 2008-07-09 07:38&#9;26488              c:\windows\system32\spupdsvc.exe<br>- 2008-08-07 06:12 . 2007-11-30 11:18&#9;26488              c:\windows\system32\spupdsvc.exe<br>- 2008-08-07 06:05 . 2007-11-30 11:18&#9;17272              c:\windows\system32\spmsg.dll<br>+ 2008-08-07 06:05 . 2007-11-30 12:39&#9;17272              c:\windows\system32\spmsg.dll<br>+ 1980-01-01 07:00 . 2009-02-03 20:08&#9;55808              c:\windows\system32\secur32.dll<br>- 1980-01-01 07:00 . 2004-08-04 12:00&#9;55808              c:\windows\system32\secur32.dll<br>+ 1980-01-01 07:00 . 2009-02-06 09:54&#9;35328              c:\windows\system32\sc.exe<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;39424              c:\windows\system32\pngfilt.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:12&#9;39424              c:\windows\system32\pngfilt.dll<br>- 1980-01-01 07:00 . 2009-03-12 03:19&#9;63682              c:\windows\system32\perfc009.dat<br>+ 1980-01-01 07:00 . 2009-06-01 20:01&#9;63682              c:\windows\system32\perfc009.dat<br>+ 2004-08-09 17:51 . 2008-06-12 14:16&#9;91648              c:\windows\system32\mtxoci.dll<br>+ 1980-01-01 07:00 . 2008-06-12 14:16&#9;66560              c:\windows\system32\mtxclu.dll<br>- 1980-01-01 07:00 . 2006-03-01 19:42&#9;66560              c:\windows\system32\mtxclu.dll<br>+ 2004-08-09 17:51 . 2008-06-12 14:16&#9;58880              c:\windows\system32\msdtclog.dll<br>- 2004-08-09 17:51 . 2004-08-04 12:00&#9;58880              c:\windows\system32\msdtclog.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:11&#9;16384              c:\windows\system32\jsproxy.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;16384              c:\windows\system32\jsproxy.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;96256              c:\windows\system32\inseng.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:11&#9;96256              c:\windows\system32\inseng.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;81920              c:\windows\system32\ieencode.dll<br>- 1980-01-01 07:00 . 2004-08-04 12:00&#9;81920              c:\windows\system32\ieencode.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;55808              c:\windows\system32\extmgr.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:11&#9;55808              c:\windows\system32\extmgr.dll<br>+ 2009-02-03 20:08 . 2009-02-03 20:08&#9;55808              c:\windows\system32\dllcache\secur32.dll<br>- 2008-06-23 16:12 . 2008-06-23 16:12&#9;39424              c:\windows\system32\dllcache\pngfilt.dll<br>+ 2008-06-23 16:12 . 2009-02-20 08:14&#9;39424              c:\windows\system32\dllcache\pngfilt.dll<br>+ 2008-06-12 14:16 . 2008-06-12 14:16&#9;91648              c:\windows\system32\dllcache\mtxoci.dll<br>+ 2008-06-12 14:16 . 2008-06-12 14:16&#9;66560              c:\windows\system32\dllcache\mtxclu.dll<br>+ 2008-06-12 14:16 . 2008-06-12 14:16&#9;58880              c:\windows\system32\dllcache\msdtclog.dll<br>- 2008-06-23 16:11 . 2008-06-23 16:11&#9;16384              c:\windows\system32\dllcache\jsproxy.dll<br>+ 2008-06-23 16:11 . 2009-02-20 08:14&#9;16384              c:\windows\system32\dllcache\jsproxy.dll<br>+ 2008-06-23 16:11 . 2009-02-20 08:14&#9;96256              c:\windows\system32\dllcache\inseng.dll<br>- 2008-06-23 16:11 . 2008-06-23 16:11&#9;96256              c:\windows\system32\dllcache\inseng.dll<br>+ 2009-02-20 08:14 . 2009-02-20 08:14&#9;81920              c:\windows\system32\dllcache\ieencode.dll<br>+ 2008-06-23 09:53 . 2009-02-19 09:50&#9;18432              c:\windows\system32\dllcache\iedw.exe<br>- 2008-06-23 09:53 . 2008-06-23 09:53&#9;18432              c:\windows\system32\dllcache\iedw.exe<br>- 2008-06-23 16:11 . 2008-06-23 16:11&#9;55808              c:\windows\system32\dllcache\extmgr.dll<br>+ 2008-06-23 16:11 . 2009-02-20 08:14&#9;55808              c:\windows\system32\dllcache\extmgr.dll<br>- 2009-05-22 00:47 . 2009-05-31 06:47&#9;32768              c:\windows\system32\config\systemprofile\UserData\index.dat<br>+ 2009-05-22 00:47 . 2009-06-02 07:39&#9;32768              c:\windows\system32\config\systemprofile\UserData\index.dat<br>+ 2009-06-02 07:04 . 2009-06-02 07:39&#9;32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009060220090603\index.dat<br>+ 2009-06-01 17:26 . 2009-06-02 02:27&#9;32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009060120090602\index.dat<br>+ 2009-06-01 17:26 . 2009-06-01 17:26&#9;32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009052520090601\index.dat<br>- 2008-08-07 06:47 . 2009-05-31 06:47&#9;32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat<br>+ 2008-08-07 06:47 . 2009-06-02 07:39&#9;32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat<br>- 2008-08-07 06:47 . 2009-05-31 06:47&#9;49152              c:\windows\system32\config\systemprofile\Cookies\index.dat<br>+ 2008-08-07 06:47 . 2009-06-02 07:39&#9;49152              c:\windows\system32\config\systemprofile\Cookies\index.dat<br>+ 2004-08-09 17:51 . 2005-07-26 04:20&#9;60416              c:\windows\system32\colbact.dll<br>- 2004-08-09 17:51 . 2005-07-26 04:39&#9;60416              c:\windows\system32\colbact.dll<br>+ 2008-08-07 06:05 . 2009-02-19 09:47&#9;351744              c:\windows\system32\xpsp3res.dll<br>- 2008-08-07 06:05 . 2008-07-03 09:14&#9;351744              c:\windows\system32\xpsp3res.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;668160              c:\windows\system32\wininet.dll<br>+ 1980-01-01 07:00 . 2008-12-16 12:47&#9;351232              c:\windows\system32\winhttp.dll<br>- 1980-01-01 07:00 . 2004-08-04 12:00&#9;351232              c:\windows\system32\winhttp.dll<br>+ 2009-03-11 05:18 . 2009-03-11 05:18&#9;934792              c:\windows\system32\WgaTray.exe<br>+ 2009-03-11 05:18 . 2009-03-11 05:18&#9;239496              c:\windows\system32\WgaLogon.dll<br>+ 2004-08-09 17:51 . 2009-02-06 09:41&#9;227840              c:\windows\system32\wbem\wmiprvse.exe<br>+ 2004-08-09 17:51 . 2009-02-11 01:31&#9;453120              c:\windows\system32\wbem\wmiprvsd.dll<br>+ 2004-08-09 17:51 . 2009-02-09 10:01&#9;473088              c:\windows\system32\wbem\fastprox.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;619520              c:\windows\system32\urlmon.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:12&#9;474112              c:\windows\system32\shlwapi.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;474112              c:\windows\system32\shlwapi.dll<br>+ 1980-01-01 07:00 . 2009-02-06 10:22&#9;110592              c:\windows\system32\services.exe<br>+ 1980-01-01 07:00 . 2009-02-09 10:01&#9;401408              c:\windows\system32\rpcss.dll<br>- 1980-01-01 07:00 . 2009-03-12 03:19&#9;406396              c:\windows\system32\perfh009.dat<br>+ 1980-01-01 07:00 . 2009-06-01 20:01&#9;406396              c:\windows\system32\perfh009.dat<br>+ 1980-01-01 07:00 . 2009-02-09 10:01&#9;715264              c:\windows\system32\ntdll.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;532480              c:\windows\system32\mstime.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:12&#9;532480              c:\windows\system32\mstime.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;146432              c:\windows\system32\msrating.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:12&#9;146432              c:\windows\system32\msrating.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:12&#9;449024              c:\windows\system32\mshtmled.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;449024              c:\windows\system32\mshtmled.dll<br>+ 2004-08-09 17:51 . 2008-06-12 14:16&#9;161792              c:\windows\system32\msdtcuiu.dll<br>+ 2004-08-09 17:51 . 2008-06-12 14:16&#9;956928              c:\windows\system32\msdtctm.dll<br>+ 2004-08-09 17:51 . 2008-06-12 14:16&#9;428032              c:\windows\system32\msdtcprx.dll<br>+ 1980-01-01 07:00 . 2009-02-09 10:01&#9;728576              c:\windows\system32\lsasrv.dll<br>+ 1980-01-01 07:00 . 2009-03-21 14:18&#9;986112              c:\windows\system32\kernel32.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:11&#9;251904              c:\windows\system32\iepeers.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;251904              c:\windows\system32\iepeers.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;205312              c:\windows\system32\dxtrans.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:11&#9;205312              c:\windows\system32\dxtrans.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;357888              c:\windows\system32\dxtmsft.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:11&#9;357888              c:\windows\system32\dxtmsft.dll<br>+ 2009-02-11 01:31 . 2009-02-11 01:31&#9;453120              c:\windows\system32\dllcache\wmiprvsd.dll<br>+ 2008-06-23 16:12 . 2009-02-20 08:14&#9;668160              c:\windows\system32\dllcache\wininet.dll<br>+ 2008-12-16 12:47 . 2008-12-16 12:47&#9;351232              c:\windows\system32\dllcache\winhttp.dll<br>+ 2009-03-11 05:18 . 2009-03-11 05:18&#9;934792              c:\windows\system32\dllcache\WgaTray.exe<br>+ 2009-03-11 05:18 . 2009-03-11 05:18&#9;239496              c:\windows\system32\dllcache\wgaLogon.dll<br>+ 2008-06-23 16:12 . 2009-02-20 08:14&#9;619520              c:\windows\system32\dllcache\urlmon.dll<br>+ 2008-06-23 16:12 . 2009-02-20 08:14&#9;474112              c:\windows\system32\dllcache\shlwapi.dll<br>- 2008-06-23 16:12 . 2008-06-23 16:12&#9;474112              c:\windows\system32\dllcache\shlwapi.dll<br>+ 1980-01-01 07:00 . 2004-08-04 12:00&#9;182912              c:\windows\system32\dllcache\ndis.sys<br>+ 2008-06-23 16:12 . 2009-02-20 08:14&#9;532480              c:\windows\system32\dllcache\mstime.dll<br>- 2008-06-23 16:12 . 2008-06-23 16:12&#9;532480              c:\windows\system32\dllcache\mstime.dll<br>+ 2008-06-23 16:12 . 2009-02-20 08:14&#9;146432              c:\windows\system32\dllcache\msrating.dll<br>- 2008-06-23 16:12 . 2008-06-23 16:12&#9;146432              c:\windows\system32\dllcache\msrating.dll<br>+ 2008-06-23 16:12 . 2009-02-20 08:14&#9;449024              c:\windows\system32\dllcache\mshtmled.dll<br>- 2008-06-23 16:12 . 2008-06-23 16:12&#9;449024              c:\windows\system32\dllcache\mshtmled.dll<br>+ 2008-06-12 14:16 . 2008-06-12 14:16&#9;161792              c:\windows\system32\dllcache\msdtcuiu.dll<br>+ 2008-06-12 14:16 . 2008-06-12 14:16&#9;956928              c:\windows\system32\dllcache\msdtctm.dll<br>+ 2008-06-12 14:16 . 2008-06-12 14:16&#9;428032              c:\windows\system32\dllcache\msdtcprx.dll<br>+ 2007-11-07 09:50 . 2009-02-09 10:01&#9;728576              c:\windows\system32\dllcache\lsasrv.dll<br>+ 2007-04-16 15:52 . 2009-03-21 14:18&#9;986112              c:\windows\system32\dllcache\kernel32.dll<br>- 2008-06-23 16:11 . 2008-06-23 16:11&#9;251904              c:\windows\system32\dllcache\iepeers.dll<br>+ 2008-06-23 16:11 . 2009-02-20 08:14&#9;251904              c:\windows\system32\dllcache\iepeers.dll<br>+ 2008-06-23 16:11 . 2009-02-20 08:14&#9;205312              c:\windows\system32\dllcache\dxtrans.dll<br>- 2008-06-23 16:11 . 2008-06-23 16:11&#9;205312              c:\windows\system32\dllcache\dxtrans.dll<br>+ 2008-06-23 16:11 . 2009-02-20 08:14&#9;357888              c:\windows\system32\dllcache\dxtmsft.dll<br>- 2008-06-23 16:11 . 2008-06-23 16:11&#9;357888              c:\windows\system32\dllcache\dxtmsft.dll<br>+ 2008-06-23 16:11 . 2009-02-20 08:14&#9;151040              c:\windows\system32\dllcache\cdfview.dll<br>- 2008-06-23 16:11 . 2008-06-23 16:11&#9;151040              c:\windows\system32\dllcache\cdfview.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:11&#9;151040              c:\windows\system32\cdfview.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;151040              c:\windows\system32\cdfview.dll<br>+ 1980-01-01 07:00 . 2009-02-09 10:01&#9;617984              c:\windows\system32\advapi32.dll<br>+ 1980-01-01 07:00 . 2009-03-02 23:27&#9;1499136              c:\windows\system32\shdocvw.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:12&#9;1499136              c:\windows\system32\shdocvw.dll<br>- 1980-01-01 07:00 . 2008-05-07 05:18&#9;1287680              c:\windows\system32\quartz.dll<br>+ 1980-01-01 07:00 . 2008-12-20 22:43&#9;1287680              c:\windows\system32\quartz.dll<br>- 1980-01-01 07:00 . 2008-08-14 09:55&#9;2142720              c:\windows\system32\ntoskrnl.exe<br>+ 1980-01-01 07:00 . 2009-02-06 10:29&#9;2142720              c:\windows\system32\ntoskrnl.exe<br>- 2004-08-04 05:59 . 2008-08-14 09:18&#9;2020864              c:\windows\system32\ntkrnlpa.exe<br>+ 2004-08-04 05:59 . 2009-02-06 09:49&#9;2020864              c:\windows\system32\ntkrnlpa.exe<br>+ 1980-01-01 07:00 . 2009-02-20 21:44&#9;3067904              c:\windows\system32\mshtml.dll<br>+ 2009-03-11 05:18 . 2009-03-11 05:18&#9;1482112              c:\windows\system32\LegitCheckControl.dll<br>+ 2008-06-23 16:12 . 2009-03-02 23:27&#9;1499136              c:\windows\system32\dllcache\shdocvw.dll<br>- 2008-06-23 16:12 . 2008-06-23 16:12&#9;1499136              c:\windows\system32\dllcache\shdocvw.dll<br>+ 2008-08-27 07:22 . 2008-12-20 22:43&#9;1287680              c:\windows\system32\dllcache\quartz.dll<br>- 2008-08-27 07:22 . 2008-05-07 05:18&#9;1287680              c:\windows\system32\dllcache\quartz.dll<br>+ 2008-10-15 20:21 . 2009-02-06 10:32&#9;2186112              c:\windows\system32\dllcache\ntoskrnl.exe<br>+ 2008-10-15 20:21 . 2009-02-06 09:49&#9;2020864              c:\windows\system32\dllcache\ntkrpamp.exe<br>- 2008-10-15 20:21 . 2008-08-14 09:18&#9;2020864              c:\windows\system32\dllcache\ntkrpamp.exe<br>- 2008-10-15 20:21 . 2008-08-14 09:18&#9;2062976              c:\windows\system32\dllcache\ntkrnlpa.exe<br>+ 2008-10-15 20:21 . 2009-02-06 09:49&#9;2062976              c:\windows\system32\dllcache\ntkrnlpa.exe<br>- 2008-10-15 20:21 . 2008-08-14 09:55&#9;2142720              c:\windows\system32\dllcache\ntkrnlmp.exe<br>+ 2008-10-15 20:21 . 2009-02-06 10:29&#9;2142720              c:\windows\system32\dllcache\ntkrnlmp.exe<br>+ 2008-06-23 16:11 . 2009-02-20 21:44&#9;3067904              c:\windows\system32\dllcache\mshtml.dll<br>+ 2008-06-23 16:11 . 2009-02-20 08:14&#9;1054208              c:\windows\system32\dllcache\danim.dll<br>- 2008-06-23 16:11 . 2008-06-23 16:11&#9;1054208              c:\windows\system32\dllcache\danim.dll<br>+ 2008-06-23 16:11 . 2009-02-20 08:14&#9;1024000              c:\windows\system32\dllcache\browseui.dll<br>- 2008-06-23 16:11 . 2008-06-23 16:11&#9;1024000              c:\windows\system32\dllcache\browseui.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;1054208              c:\windows\system32\danim.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:11&#9;1054208              c:\windows\system32\danim.dll<br>+ 1980-01-01 07:00 . 2009-02-20 08:14&#9;1024000              c:\windows\system32\browseui.dll<br>- 1980-01-01 07:00 . 2008-06-23 16:11&#9;1024000              c:\windows\system32\browseui.dll<br>+ 2008-08-07 06:09 . 2009-02-06 10:32&#9;2186112              c:\windows\Driver Cache\i386\ntoskrnl.exe<br>+ 2008-08-07 06:09 . 2009-02-06 09:49&#9;2020864              c:\windows\Driver Cache\i386\ntkrpamp.exe<br>- 2008-08-07 06:09 . 2008-08-14 09:18&#9;2020864              c:\windows\Driver Cache\i386\ntkrpamp.exe<br>+ 2008-08-07 06:09 . 2009-02-06 09:49&#9;2062976              c:\windows\Driver Cache\i386\ntkrnlpa.exe<br>- 2008-08-07 06:09 . 2008-08-14 09:18&#9;2062976              c:\windows\Driver Cache\i386\ntkrnlpa.exe<br>- 2008-08-07 06:09 . 2008-08-14 09:55&#9;2142720              c:\windows\Driver Cache\i386\ntkrnlmp.exe<br>+ 2008-08-07 06:09 . 2009-02-06 10:29&#9;2142720              c:\windows\Driver Cache\i386\ntkrnlmp.exe<br>.<br>-- Snapshot reset to current date --<br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]<br>"Google Update"="c:\documents and settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-11 133104]<br>"aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-09-15 110592]<br>"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-09-15 512000]<br>"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2005-10-29 864256]<br>"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-11-17 237568]<br>"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-03-09 94208]<br>"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-12-15 925696]<br>"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]<br>"suScheduler"="c:\program files\ThinkVantage\SystemUpdate\UCLauncher.exe" [2005-08-02 40960]<br>"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2006-01-25 106496]<br>"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2005-11-14 487424]<br>"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-08-01 122940]<br>"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]<br>"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]<br>"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752]<br>"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2005-10-28 335872]<br>"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-11-29 196696]<br>"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2006-04-17 409600]<br>"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-04-17 98304]<br>"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-12-07 151552]<br>"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-12-07 208896]<br>"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-31 136600]<br>"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]<br>"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]<br>"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2005-11-07 106496]<br>"TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2005-10-17 65536]<br><br>c:\documents and settings\All Users\Start Menu\Programs\Startup\<br>Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]<br>Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2005-11-1 581693]<br>Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-6 24576]<br><br>[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]<br>"DisallowRun"= 0 (0x0)<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]<br>2006-04-17 20:01&#9;32768&#9;----a-w-&#9;c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]<br>2005-12-08 21:59&#9;39936&#9;----a-w-&#9;c:\windows\system32\psqlpwd.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]<br>2005-07-06 06:45&#9;28672&#9;----a-w-&#9;c:\windows\system32\notifyf2.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]<br>2005-12-01 03:16&#9;24576&#9;----a-w-&#9;c:\windows\system32\tphklock.dll<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]<br>Notification Packages&#9;REG_MULTI_SZ   &#9;scecli psqlpwd<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]<br>@=""<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]<br>@=""<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"c:\\Program Files\\ThinkVantage\\SystemUpdate\\jre\\bin\\javaw.exe"=<br>"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=<br>"c:\\Program Files\\AIM6\\aim6.exe"=<br>"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=<br>"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=<br>"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=<br>"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=<br>"c:\\Program Files\\iTunes\\iTunes.exe"=<br>"c:\\Program Files\\iTunes\\iTunesHelper.exe"=<br>"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br>"56823:TCP"= 56823:TCP:Pando Media Booster<br>"56823:UDP"= 56823:UDP:Pando Media Booster<br><br>R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/30/2009 2:43 AM 130424]<br>R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [8/6/2008 11:19 PM 85760]<br>R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [8/6/2008 11:19 PM 4736]<br>R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [8/6/2008 11:42 PM 4442]<br>R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [12/8/2005 2:44 PM 3328]<br>S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [8/18/2005 5:22 PM 124608]<br>S3 sdAuxService;PC Tools Auxiliary Service;c:\nexon\Spyware Doctor\pctsAuxs.exe --> c:\nexon\Spyware Doctor\pctsAuxs.exe [?]<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2009-05-02 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]<br><br>2009-06-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-881565578-3357626825-4007795620-1005.job<br>- c:\documents and settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 10:27]<br><br>2009-06-02 c:\windows\Tasks\PMTask.job<br>- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-08-07 08:12]<br><br>2008-08-07 c:\windows\Tasks\Symantec NetDetect.job<br>- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2008-08-07 00:32]<br>.<br>.<br>------- Supplementary Scan -------<br>.<br>uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8<br>uInternet Connection Wizard,ShellNext = iexplore<br>uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br>FF - ProfilePath - c:\documents and settings\ATL\Application Data\Mozilla\Firefox\Profiles\qwywtq3l.default\<br>FF - plugin: c:\documents and settings\ATL\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll<br>FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll<br>FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll<br>FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2009-06-02 00:44<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ...  <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ...  <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>- - - - - - - > 'winlogon.exe'(968)<br>c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll<br>c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll<br>c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll<br>c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll<br>c:\windows\system32\Ati2evxx.dll<br>c:\windows\system32\psqlpwd.dll<br>c:\program files\ThinkVantage Fingerprint Software\infra.dll<br>c:\program files\ThinkVantage Fingerprint Software\homefus2.dll<br>c:\windows\system32\biologon.dll<br>c:\program files\ThinkVantage Fingerprint Software\homepass.dll<br>c:\program files\ThinkVantage Fingerprint Software\bio.dll<br>c:\program files\ThinkVantage Fingerprint Software\remote.dll<br>c:\program files\ThinkVantage Fingerprint Software\ps2css.dll<br>c:\windows\system32\tphklock.dll<br><br>- - - - - - - > 'lsass.exe'(1024)<br>c:\windows\system32\psqlpwd.dll<br>c:\program files\ThinkVantage Fingerprint Software\infra.dll<br>c:\program files\ThinkVantage Fingerprint Software\homefus2.dll<br><br>- - - - - - - > 'explorer.exe'(3592)<br>c:\windows\system32\PROCHLP.DLL<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>c:\windows\system32\ibmpmsvc.exe<br>c:\windows\system32\ati2evxx.exe<br>c:\program files\Intel\Wireless\Bin\EvtEng.exe<br>c:\program files\Intel\Wireless\Bin\S24EvMon.exe<br>c:\program files\Common Files\Symantec Shared\ccProxy.exe<br>c:\program files\Common Files\Symantec Shared\ccSetMgr.exe<br>c:\program files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe<br>c:\program files\Common Files\Symantec Shared\SNDSrvc.exe<br>c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe<br>c:\windows\system32\IPSSVC.EXE<br>c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br>c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>c:\program files\Bonjour\mDNSResponder.exe<br>c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br>c:\program files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe<br>c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe<br>c:\program files\Java\jre6\bin\jqs.exe<br>c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>c:\program files\Intel\Wireless\Bin\RegSrvc.exe<br>c:\program files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe<br>c:\windows\system32\TPHDEXLG.exe<br>c:\windows\system32\TpKmpSvc.exe<br>c:\program files\ThinkVantage\SystemUpdate\UCLauncherService.exe<br>c:\windows\system32\wdfmgr.exe<br>c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe<br>c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe<br>c:\windows\system32\wscntfy.exe<br>c:\windows\system32\ati2evxx.exe<br>c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe<br>c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe<br>c:\program files\ThinkPad\UltraNav Wizard\UNavTray.exe<br>c:\windows\system32\rundll32.exe<br>c:\progra~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE<br>c:\program files\iPod\bin\iPodService.exe<br>c:\windows\system32\wbem\wmiapsrv.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2009-06-02  0:48 - machine was rebooted<br>ComboFix-quarantined-files.txt  2009-06-02 07:48<br>ComboFix2.txt  2009-06-01 02:48<br>ComboFix3.txt  2009-05-31 06:58<br><br>Pre-Run: 64,348,688,384 bytes free<br>Post-Run: 64,385,593,344 bytes free<br><br>WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe<br>[boot loader]<br>timeout=2<br>default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS<br>[operating systems]<br>c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons<br>multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect<br><br>442&#9;--- E O F ---&#9;2009-06-01 10:02<br><br><b>HijackThis Log:</b><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 12:54:55 AM, on 6/2/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\ibmpmsvc.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe<br>C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\IPSSVC.EXE<br>C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br>C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe<br>C:\WINDOWS\System32\TPHDEXLG.EXE<br>C:\WINDOWS\system32\TpKmpSVC.exe<br>C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br>C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>C:\WINDOWS\system32\TpShocks.exe<br>C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br>C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe<br>C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe<br>C:\Program Files\ThinkVantage\AMSG\Amsg.exe<br>C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe<br>C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\Picasa2\PicasaMediaDetector.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br>C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE<br>C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Documents and Settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe<br>C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\WINDOWS\explorer.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br>O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br>O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll<br>O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper<br>O4 - HKLM\..\Run: [TpShocks] TpShocks.exe<br>O4 - HKLM\..\Run: [TP4EX] tp4ex.exe<br>O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br>O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe<br>O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay<br>O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER<br>O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe<br>O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe<br>O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br>O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe<br>O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"<br>O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br>O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br>O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor<br>O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c<br>O4 - HKCU\..\Run: [aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Bluetooth.lnk = ?<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O11 - Options group: [JAVA_IBM] Java (IBM)<br>O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)<br>O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br>O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br>O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE<br>O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Nexon\Spyware Doctor\pctsAuxs.exe (file missing)<br>O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - C:\Nexon\Spyware Doctor\pctsSvc.exe (file missing)<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe<br>O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe<br>O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE<br>O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe<br>O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe<br><br>--<br>End of file - 11373 bytes<br><br>Again, thank you for helping. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22481143</guid>
<pubDate>Tue, 02 Jun 2009 06:06:24 EDT</pubDate>
</item>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22480765</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Not only has Kaspersky's Virus Removal Tool removes several infections, it has shown the apparent source of at least part of your infections - downloading infected files with LimeWire. As I pointed out in my previous post, even if you replace LimeWire with a clean P2P program, that only means that the program is clean, it doesn't mean that the files that you download will be, and you have infected mp3 files that were downloaded with it.<br><br>If you uninstalled LimeWire as recommended, then you should also delete the following folder, but first you will need to be sure you have hidden files and folders showing.<br><br>Reconfigure Windows XP to show hidden files:<br>Click Start. Open My Computer. <br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading select "Show hidden files and folders". <br>Uncheck the "Hide protected operating system files (recommended)" option. <br>Uncheck the "Hide file extensions for known file types" option.<br>Click Yes to confirm. Click OK.<br><br>c:\documents and settings\ATL\Application Data\<b>LimeWire</b><br><br>Now you need to hide the files you un-hid earlier:<br>Click Start. Open My Computer.<br>Select the Tools menu and click Folder Options. Select the View Tab. <br>Under the Hidden files and folders heading unselect "Show hidden files and folders". <br>Check the "Hide protected operating system files (recommended)" option. <br>Click Yes to confirm. Click OK.<br><br>If you uninstalled Limewire as recommended, also do this:<br><br>Please run Notepad and paste the following text in the Quote box (between the lines) into a new file:<br><br>  <blockquote><small>quote:</small><hr>REGEDIT4<br><br>HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"c:\\Program Files\\LimeWire\\LimeWire.exe"=-<br><hr></blockquote><br><br>Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files". Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry. A window will open and quickly close.<br><br>We need to make sure you have the most recent version of ComboFix.<br><b>Delete</b> your current copy of ComboFix.exe.<br>Download <b>ComboFix&copy; by sUBs</b> from one of these links:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Save the file to your Desktop.<br>Close any open browsers.<br>Close your AntiVirus and any anti-spyware programs you may be running.<br><br>For this next step, please <b>ensure that ComboFix.exe is on your desktop:</b><br><br>Please open <b>Notepad</b>*Do Not Use Wordpad!*(Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:<br>Save this as <b>"CFScript.txt"</b> and change the "Save as type" to "All Files" and place it on your <b>desktop</b>.<br><br>  <blockquote><small>quote:</small><hr>File::<br>c:\windows\system32\BITA21.tmp<br>c:\windows\system32\BITA22.tmp<br>c:\windows\system32\BITA20.tmp<br>c:\windows\system32\barufutu.exe<br>c:\windows\system32\ratijipe.exe<br>c:\windows\system32\pisabupe.dll<br>c:\windows\system32\nopededo.dll<br>c:\windows\system32\limehabe.exe<br>c:\windows\system32\fujayagi.dll<br>c:\windows\system32\ligenisa.exe<br>c:\windows\system32\lonazaki.exe<br>c:\windows\system32\ludojila.exe<br>c:\windows\system32\malodoso.exe<br>c:\windows\system32\nokadeno.exe<br><br>Folder::<br>c:\documents and settings\All Users\Application Data\Viewpoint<br><hr></blockquote><br><br>Save this as <b>CFScript.txt</b>, in the same location as ComboFix.exe<br><br> <IMG SRC="http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif">  <br><br>Referring to the picture above, drag CFScript into ComboFix.exe<br>When finished, it will produce a log for you at <b>C:\ComboFix.txt</b>. Please post that log in your next reply.<br><br>Please post a new HijackThis log, the log from ComboFix (combofix.txt), and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22480765</guid>
<pubDate>Mon, 01 Jun 2009 23:20:20 EDT</pubDate>
</item>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22478811</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : <b>HijackThis Log:</b><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 5:07:33 PM, on 6/1/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\ibmpmsvc.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe<br>C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\IPSSVC.EXE<br>C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br>C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe<br>C:\WINDOWS\System32\TPHDEXLG.EXE<br>C:\WINDOWS\system32\TpKmpSVC.exe<br>C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br>C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>C:\WINDOWS\system32\TpShocks.exe<br>C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br>C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe<br>C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe<br>C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe<br>C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe<br>C:\Program Files\ThinkVantage\AMSG\Amsg.exe<br>C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\Program Files\Picasa2\PicasaMediaDetector.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Documents and Settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\system32\wbem\wmiapsrv.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br>O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br>O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll<br>O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper<br>O4 - HKLM\..\Run: [TpShocks] TpShocks.exe<br>O4 - HKLM\..\Run: [TP4EX] tp4ex.exe<br>O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br>O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe<br>O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay<br>O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER<br>O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe<br>O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe<br>O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br>O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe<br>O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"<br>O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br>O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br>O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor<br>O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c<br>O4 - HKCU\..\Run: [aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Bluetooth.lnk = ?<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O11 - Options group: [JAVA_IBM] Java (IBM)<br>O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)<br>O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br>O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br>O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE<br>O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Nexon\Spyware Doctor\pctsAuxs.exe (file missing)<br>O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - C:\Nexon\Spyware Doctor\pctsSvc.exe (file missing)<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe<br>O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe<br>O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE<br>O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe<br>O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe<br><br>--<br>End of file - 11633 bytes<br><br><b>Kasperky:</b><br>Scan<br>----<br>Scanned:&#9;898505<br>Detected:&#9;35<br>Untreated:&#9;0<br>Start time:&#9;6/1/2009 1:23:02 PM<br>Duration:&#9;03:12:43<br>Finish time:&#9;6/1/2009 4:35:45 PM<br><br>Detected<br>--------<br>Status&#9;Object<br>------&#9;------<br>disinfected: Trojan program Trojan-Downloader.WMA.GetCodec.r&#9;File: C:\Documents and Settings\ATL\My Documents\LimeWire\Incomplete\T-5745425-great escape (unplugged version).mp3<br>disinfected: Trojan program Trojan-Downloader.WMA.GetCodec.u&#9;File: C:\Documents and Settings\ATL\My Documents\LimeWire\Saved\baptism of solitude.mp3<br>disinfected: Trojan program Trojan-Downloader.WMA.GetCodec.n&#9;File: C:\Documents and Settings\ATL\My Documents\LimeWire\Saved\great escape boys like girls - greatest hits.mp3<br>disinfected: Trojan program Trojan-Downloader.WMA.GetCodec.r&#9;File: C:\Documents and Settings\ATL\My Documents\LimeWire\Saved\little too not over you.mp3<br>deleted: Trojan program Trojan-Downloader.Win32.Small.akgk&#9;File: C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0ED00000.VBN//CryptZ<br>deleted: virus Email-Worm.Win32.Zhelatin.vl&#9;File: C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\14540001.VBN//CryptZ<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\Qoobox\Quarantine\C\WINDOWS\system32\rayizanu.exe.vir<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\Qoobox\Quarantine\C\WINDOWS\system32\vakakayu.exe.vir<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065112.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065113.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065118.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065120.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065124.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065132.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065141.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065143.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065146.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065152.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065156.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP146\A0065165.dll<br>deleted: Trojan program Backdoor.Win32.NewRest.z&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP147\A0069292.sys<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP148\A0071430.exe<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP148\A0071433.exe<br>deleted: Trojan program Packed.Win32.Krap.n&#9;File: C:\WINDOWS\system32\fujayagi.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\WINDOWS\system32\ligenisa.exe<br>deleted: Trojan program Trojan-Dropper.Win32.Xpiut.hq&#9;File: C:\WINDOWS\system32\lonazaki.exe<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\WINDOWS\system32\ludojila.exe<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\WINDOWS\system32\malodoso.exe<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\WINDOWS\system32\nokadeno.exe<br>deleted: Trojan program Packed.Win32.Krap.n&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP150\A0075721.dll<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP150\A0075722.exe<br>deleted: Trojan program Trojan-Dropper.Win32.Xpiut.hq&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP150\A0075723.exe<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP150\A0075724.exe<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP150\A0075725.exe<br>deleted: Trojan program Packed.Win32.Krap.q&#9;File: C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP150\A0075726.exe<br><br><b>Combofix:</b><br>ComboFix 09-05-30.03 - ATL 05/31/2009 19:38.2 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1022.558 [GMT -7:00]<br>Running from: c:\documents and settings\ATL\Desktop\pppp.exe<br>Command switches used :: c:\documents and settings\ATL\Desktop\CFScript.txt<br>AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}<br>FW: Symantec Client Firewall *enabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187}<br><br>FILE ::<br>"c:\windows\system32\drivers\19afffad.sys"<br>"c:\windows\system32\drivers\df90d040.sys"<br>.<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>c:\windows\system32\drivers\19afffad.sys<br><br>.<br>(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>-------\Service_19afffad<br>-------\Service_df90d040<br><br>(((((((((((((((((((((((((   Files Created from 2009-05-01 to 2009-06-01  )))))))))))))))))))))))))))))))<br>.<br><br>2009-05-31 06:38 . 2009-05-31 06:46&#9;--------&#9;d-s---w&#9;C:\ComboFix<br>2009-05-30 18:32 . 2009-05-30 18:32&#9;--------&#9;dc----w&#9;c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}<br>2009-05-30 16:51 . 2009-05-30 16:51&#9;--------&#9;d-----w&#9;c:\program files\Trend Micro<br>2009-05-30 16:43 . 2009-05-26 20:20&#9;40160&#9;----a-w&#9;c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-05-30 16:43 . 2009-05-30 16:43&#9;--------&#9;d-----w&#9;c:\program files\Malwarebytes' Anti-Malware<br>2009-05-30 16:43 . 2009-05-26 20:19&#9;19096&#9;----a-w&#9;c:\windows\system32\drivers\mbam.sys<br>2009-05-22 00:47 . 2009-05-22 00:47&#9;--------&#9;d-s---w&#9;c:\windows\system32\config\systemprofile\UserData<br>2009-05-21 10:34 . 2009-05-21 10:36&#9;--------&#9;d-----w&#9;c:\program files\Spybot - Search & Destroy<br>2009-05-21 10:34 . 2009-05-21 10:36&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy<br>2009-05-05 07:13 . 2009-05-05 07:13&#9;--------&#9;d-----w&#9;c:\documents and settings\ATL\Application Data\Malwarebytes<br>2009-05-05 07:13 . 2009-05-05 07:13&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\Malwarebytes<br>2009-05-03 08:05 . 2009-05-03 08:05&#9;45056&#9;----a-r&#9;c:\documents and settings\ATL\Application Data\Microsoft\Installer\{8BF863F9-7739-4DA4-B40A-2AD76D571B82}\MapleStory.exe_DB457427E7B9425292170DC5FADE980F.exe<br>2009-05-03 08:05 . 2009-05-03 08:05&#9;45056&#9;----a-r&#9;c:\documents and settings\ATL\Application Data\Microsoft\Installer\{8BF863F9-7739-4DA4-B40A-2AD76D571B82}\MapleStory.exe1_DB457427E7B9425292170DC5FADE980F.exe<br>2009-05-03 08:05 . 2009-05-03 08:05&#9;10134&#9;----a-r&#9;c:\documents and settings\ATL\Application Data\Microsoft\Installer\{8BF863F9-7739-4DA4-B40A-2AD76D571B82}\ARPPRODUCTICON.exe<br>2009-05-03 06:34 . 2009-05-03 08:31&#9;--------&#9;d-----w&#9;c:\documents and settings\ATL\Local Settings\Application Data\PMB Files<br>2009-05-03 06:34 . 2009-05-03 06:35&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\PMB Files<br>2009-05-03 06:34 . 2009-05-03 06:34&#9;--------&#9;d-----w&#9;c:\program files\Pando Networks<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-06-01 02:41 . 2008-08-07 06:35&#9;40&#9;----a-w&#9;c:\windows\system32\profile.dat<br>2009-06-01 02:17 . 2008-08-09 02:21&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\Viewpoint<br>2009-05-31 06:14 . 2009-03-30 09:42&#9;--------&#9;d-----w&#9;c:\documents and settings\ATL\Application Data\PC Tools<br>2009-05-30 18:52 . 2008-08-07 06:35&#9;--------&#9;d-----w&#9;c:\program files\Common Files\Symantec Shared<br>2009-05-03 08:34 . 2009-03-30 09:42&#9;--------&#9;d---a-w&#9;c:\documents and settings\All Users\Application Data\TEMP<br>2009-05-03 08:12 . 2009-05-03 08:12&#9;87552&#9;---ha-w&#9;c:\windows\system32\BITA21.tmp<br>2009-05-03 08:12 . 2009-05-03 08:12&#9;79872&#9;---ha-w&#9;c:\windows\system32\BITA22.tmp<br>2009-05-03 08:12 . 2009-05-03 08:12&#9;50688&#9;---ha-w&#9;c:\windows\system32\BITA20.tmp<br>2009-05-02 21:01 . 2008-08-13 01:49&#9;--------&#9;d-----w&#9;c:\program files\Warcraft III<br>2009-05-01 21:04 . 1980-01-01 07:00&#9;212480&#9;----a-w&#9;c:\windows\system32\drivers\ndis.sys<br>2009-04-29 07:28 . 2008-12-31 09:09&#9;--------&#9;d-----w&#9;c:\documents and settings\ATL\Application Data\LimeWire<br>2009-04-14 04:03 . 2009-04-14 04:03&#9;2713&#9;--sh--w&#9;c:\windows\system32\barufutu.exe<br>2009-04-10 22:37 . 2009-04-10 22:37&#9;2713&#9;--sh--w&#9;c:\windows\system32\ratijipe.exe<br>2009-04-09 22:37 . 2009-04-09 22:37&#9;15644&#9;--sha-w&#9;c:\windows\system32\pisabupe.dll<br>2009-04-09 08:36 . 2009-04-09 08:36&#9;2713&#9;--sh--w&#9;c:\windows\system32\nopededo.dll<br>2009-04-09 08:36 . 2009-04-09 08:36&#9;2713&#9;--sh--w&#9;c:\windows\system32\limehabe.exe<br>2009-04-01 05:55 . 2009-04-01 05:55&#9;10866&#9;--sha-w&#9;c:\windows\system32\fujayagi.dll<br>2009-03-23 08:02 . 2009-03-23 08:02&#9;75048&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.0.52\SetupAdmin.exe<br>2009-03-20 05:34 . 2008-08-13 01:53&#9;77691&#9;----a-w&#9;c:\windows\War3Unin.dat<br>2009-03-06 23:45 . 2009-03-30 09:43&#9;130424&#9;----a-w&#9;c:\windows\system32\drivers\PCTCore.sys<br>2009-03-06 06:59 . 2009-03-23 08:05&#9;1900544&#9;----a-w&#9;c:\windows\system32\usbaaplrc.dll<br>2009-03-06 06:59 . 2008-12-26 20:30&#9;36864&#9;----a-w&#9;c:\windows\system32\drivers\usbaapl.sys<br>2009-02-01 08:42 . 2009-02-01 08:42&#9;50688&#9;--sha-w&#9;c:\windows\system32\ligenisa.exe<br>2009-01-12 21:16 . 2009-01-12 21:16&#9;51200&#9;--sha-w&#9;c:\windows\system32\lonazaki.exe<br>2009-02-02 19:53 . 2009-02-02 19:53&#9;51200&#9;--sha-w&#9;c:\windows\system32\ludojila.exe<br>2009-02-04 04:48 . 2009-02-04 04:48&#9;50688&#9;--sha-w&#9;c:\windows\system32\malodoso.exe<br>2009-02-03 08:12 . 2009-02-03 08:12&#9;50688&#9;--sha-w&#9;c:\windows\system32\nokadeno.exe<br>.<br><br>------- Sigcheck -------<br><br>[-] 2008-04-14 00:12&#9;507904&#9;ED0EF0A136DEC83DF69F04118870003E&#9;c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\winlogon.exe<br>[-] 2008-08-26 05:33&#9;502784&#9;B359DE33041BA9ACAB6392745C3F81ED&#9;c:\windows\system32\winlogon.exe<br><br>[-] 2008-04-13 19:20&#9;182656&#9;1DF7F42665C94B825322FAE71721130D&#9;c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ndis.sys<br>[-] 2009-05-01 21:04&#9;212480&#9;791778A1F54D4B3F36773F11783A53FC&#9;c:\windows\system32\dllcache\ndis.sys<br>[-] 2009-05-01 21:04&#9;212480&#9;791778A1F54D4B3F36773F11783A53FC&#9;c:\windows\system32\drivers\ndis.sys<br><br>[-] 2008-04-14 00:12&#9;295424&#9;FF3477C03BE7201C294C35F684B3479F&#9;c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\termsrv.dll<br>[-] 2008-08-26 05:33&#9;295424&#9;40FFC19A8D4875E9E19CECDC76EF9201&#9;c:\windows\system32\termsrv.dll<br>.<br>(((((((((((((((((((((((((((((   SnapShot@2009-05-31_06.57.42   )))))))))))))))))))))))))))))))))))))))))<br>.<br>+ 2009-06-01 02:21 . 2009-06-01 02:21&#9;16384              c:\windows\Temp\Perflib_Perfdata_6f0.dat<br>+ 2009-05-22 00:47 . 2009-06-01 02:30&#9;32768              c:\windows\system32\config\systemprofile\UserData\index.dat<br>- 2009-05-22 00:47 . 2009-05-31 06:47&#9;32768              c:\windows\system32\config\systemprofile\UserData\index.dat<br>+ 2009-05-31 21:44 . 2009-06-01 02:30&#9;32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009053120090601\index.dat<br>+ 2008-08-07 06:47 . 2009-06-01 02:30&#9;32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat<br>- 2008-08-07 06:47 . 2009-05-31 06:47&#9;32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat<br>+ 2008-08-07 06:47 . 2009-06-01 02:30&#9;49152              c:\windows\system32\config\systemprofile\Cookies\index.dat<br>- 2008-08-07 06:47 . 2009-05-31 06:47&#9;49152              c:\windows\system32\config\systemprofile\Cookies\index.dat<br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]<br>"Google Update"="c:\documents and settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-11 133104]<br>"aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-09-15 110592]<br>"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-09-15 512000]<br>"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2005-10-29 864256]<br>"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-11-17 237568]<br>"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-03-09 94208]<br>"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-12-15 925696]<br>"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]<br>"suScheduler"="c:\program files\ThinkVantage\SystemUpdate\UCLauncher.exe" [2005-08-02 40960]<br>"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2006-01-25 106496]<br>"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2005-11-14 487424]<br>"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-08-01 122940]<br>"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]<br>"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]<br>"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752]<br>"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2005-10-28 335872]<br>"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-11-29 196696]<br>"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2006-04-17 409600]<br>"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-04-17 98304]<br>"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-12-07 151552]<br>"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-12-07 208896]<br>"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-31 136600]<br>"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]<br>"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]<br>"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2005-11-07 106496]<br>"TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2005-10-17 65536]<br><br>c:\documents and settings\All Users\Start Menu\Programs\Startup\<br>Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]<br>Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2005-11-1 581693]<br>Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-6 24576]<br><br>[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]<br>"DisallowRun"= 0 (0x0)<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]<br>2006-04-17 20:01&#9;32768&#9;----a-w&#9;c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]<br>2005-12-08 21:59&#9;39936&#9;----a-w&#9;c:\windows\system32\psqlpwd.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]<br>2005-07-06 06:45&#9;28672&#9;----a-w&#9;c:\windows\system32\notifyf2.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]<br>2005-12-01 03:16&#9;24576&#9;----a-w&#9;c:\windows\system32\tphklock.dll<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]<br>Notification Packages&#9;REG_MULTI_SZ   &#9;scecli psqlpwd<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]<br>@=""<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]<br>@=""<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"c:\\Program Files\\ThinkVantage\\SystemUpdate\\jre\\bin\\javaw.exe"=<br>"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=<br>"c:\\Program Files\\AIM6\\aim6.exe"=<br>"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=<br>"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=<br>"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=<br>"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=<br>"c:\\Program Files\\iTunes\\iTunes.exe"=<br>"c:\\Program Files\\iTunes\\iTunesHelper.exe"=<br>"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br>"56823:TCP"= 56823:TCP:Pando Media Booster<br>"56823:UDP"= 56823:UDP:Pando Media Booster<br><br>R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/30/2009 2:43 AM 130424]<br>R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [8/6/2008 11:19 PM 85760]<br>R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [8/6/2008 11:19 PM 4736]<br>R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [8/6/2008 11:42 PM 4442]<br>R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [12/8/2005 2:44 PM 3328]<br>S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [8/18/2005 5:22 PM 124608]<br>S3 sdAuxService;PC Tools Auxiliary Service;c:\nexon\Spyware Doctor\pctsAuxs.exe --> c:\nexon\Spyware Doctor\pctsAuxs.exe [?]<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2009-05-02 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]<br><br>2009-05-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-881565578-3357626825-4007795620-1005.job<br>- c:\documents and settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 10:27]<br><br>2009-06-01 c:\windows\Tasks\PMTask.job<br>- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-08-07 08:12]<br><br>2008-08-07 c:\windows\Tasks\Symantec NetDetect.job<br>- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2008-08-07 00:32]<br>.<br>.<br>------- Supplementary Scan -------<br>.<br>uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8<br>uInternet Connection Wizard,ShellNext = iexplore<br>uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br>FF - ProfilePath - c:\documents and settings\ATL\Application Data\Mozilla\Firefox\Profiles\qwywtq3l.default\<br>FF - plugin: c:\documents and settings\ATL\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll<br>FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll<br>FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll<br>FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2009-05-31 19:44<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ...  <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ...  <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>- - - - - - - > 'winlogon.exe'(960)<br>c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll<br>c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll<br>c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll<br>c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll<br>c:\windows\system32\Ati2evxx.dll<br>c:\windows\system32\psqlpwd.dll<br>c:\program files\ThinkVantage Fingerprint Software\infra.dll<br>c:\program files\ThinkVantage Fingerprint Software\homefus2.dll<br>c:\windows\system32\biologon.dll<br>c:\program files\ThinkVantage Fingerprint Software\homepass.dll<br>c:\program files\ThinkVantage Fingerprint Software\bio.dll<br>c:\program files\ThinkVantage Fingerprint Software\remote.dll<br>c:\program files\ThinkVantage Fingerprint Software\ps2css.dll<br>c:\windows\system32\tphklock.dll<br><br>- - - - - - - > 'lsass.exe'(1020)<br>c:\windows\system32\psqlpwd.dll<br>c:\program files\ThinkVantage Fingerprint Software\infra.dll<br>c:\program files\ThinkVantage Fingerprint Software\homefus2.dll<br><br>- - - - - - - > 'explorer.exe'(5692)<br>c:\windows\system32\PROCHLP.DLL<br>.<br>------------------------ Other Running Processes ------------------------<br>.<br>c:\windows\system32\ibmpmsvc.exe<br>c:\windows\system32\ati2evxx.exe<br>c:\program files\Intel\Wireless\Bin\EvtEng.exe<br>c:\program files\Intel\Wireless\Bin\S24EvMon.exe<br>c:\program files\Common Files\Symantec Shared\ccProxy.exe<br>c:\program files\Common Files\Symantec Shared\ccSetMgr.exe<br>c:\program files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe<br>c:\program files\Common Files\Symantec Shared\SNDSrvc.exe<br>c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe<br>c:\windows\system32\IPSSVC.EXE<br>c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br>c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>c:\program files\Bonjour\mDNSResponder.exe<br>c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br>c:\program files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe<br>c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe<br>c:\program files\Java\jre6\bin\jqs.exe<br>c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>c:\program files\Intel\Wireless\Bin\RegSrvc.exe<br>c:\program files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe<br>c:\windows\system32\TPHDEXLG.exe<br>c:\windows\system32\TpKmpSvc.exe<br>c:\program files\ThinkVantage\SystemUpdate\UCLauncherService.exe<br>c:\windows\system32\wdfmgr.exe<br>c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe<br>c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe<br>c:\windows\system32\wscntfy.exe<br>c:\windows\system32\ati2evxx.exe<br>c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe<br>c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe<br>c:\windows\system32\rundll32.exe<br>c:\progra~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE<br>c:\program files\iPod\bin\iPodService.exe<br>c:\windows\system32\wbem\wmiapsrv.exe<br>.<br>**************************************************************************<br>.<br>Completion time: 2009-06-01 19:48 - machine was rebooted<br>ComboFix-quarantined-files.txt  2009-06-01 02:48<br>ComboFix2.txt  2009-05-31 06:58<br><br>Pre-Run: 64,674,787,328 bytes free<br>Post-Run: 64,641,310,720 bytes free<br><br>271&#9;--- E O F ---&#9;2009-03-13 10:02]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22478811</guid>
<pubDate>Mon, 01 Jun 2009 17:12:50 EDT</pubDate>
</item>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22475899</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Go to Start > Settings > Control Panel > Internet Options > Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.<br>In Firefox in Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection.<br><br>Download the latest version of Kaspersky Virus Removal Tool <br><textarea name="code" class="text" cols=50 rows=10>ftp://downloads2.kaspersky-labs.com/devbuilds/AVPTool/index.html&#012;</textarea><!--end code block-->- Close all other applications and double-click and run the installer.<br>- When AVPTool starts, select all the scanable items except for CD-ROM drives and click the <b>Scan</b> button.<br>- If malware is detected, place a checkmark in the<b> Apply to all</b> box, and click the <b>Delete</b> button (or <b>Disinfect</b> if the button is active).<br>- After the scan finishes, if any threat remains in the Scan window (Red exclamation point), click the <b>Neutralize all</b> button<br>- In the window that opens, place a checkmark in the <b>Apply to all</b> box, and click the <b>Delete</b> button (or <b>Disinfect</b> if the button is active).<br>- If advised that a special disinfection procedure is required which demands system reboot: click the <b>Ok</b> button to close the window.<br>- In the Scan window click the <b>Reports</b> button and select <b>Save to file</b>.<br>- Name the report <b>AVPT.txt</b>, and save it to the Desktop.<br>- Close AVPTool.<br>- You will be prompted if you want to uninstall the program; click <b>Yes</b>.<br>- You will then be prompted that to complete the uninstallation, the computer must be restarted. Select <b>Yes</b> to restart the system.<br>- Copy and paste the <b>first part</b> of the report (<b>Detected</b>) that you saved in your next reply. Do not include the longer list marked <b>Events</b>.<br><br>Please post a new HijackThis log, the requested portion of the log from Kaspersky's Virus Removal Tool, and the ComboFix log from the last set of instructions.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22475899</guid>
<pubDate>Mon, 01 Jun 2009 08:18:12 EDT</pubDate>
</item>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22475144</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Two things:<br><br>1. This is the second time you've posted for me to deactivate Spyware Doctor, but I'm 99% positive I don't have it. I ran a search to make sure and nothing came up. Could there be something else causing problems?<br><br>2. I'm unable to run Kaspersky's scanner. It requires a newer version of Java which, for whatever reason, I am unable to download. I believe this has something to do with my faulty connection (I'm only able to connect on an old version of IE).<br><br>Otherwise I ran Combofix again.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22475144</guid>
<pubDate>Sun, 31 May 2009 23:54:52 EDT</pubDate>
</item>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22471929</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Spyware Doctor's OnGuard protective functionality may interfere with certain HijackThis fixes we need to make.  Please follow these instructions to disable it:<br><br><b>To deactivate Spyware Doctor's OnGuard Tools</b><br><br>1. From within Spyware Doctor, click the "OnGuard" button on the left side.<br>2. Uncheck "Activate OnGuard".<br><br>You can reenable it once your system is clean.<br><br>I see you have Viewpoint installed...<br><b>Viewpoint Manager</b> is considered to be <b>foistware</b> instead of malware since it is installed without users approval, but doesn't spy or do anything "bad". This will change though, please read this article:<br>&raquo;<A HREF="http://www.clickz.com/news/article.php/3561546" >www.clickz.com/news/article.php/3561546</A><br>I suggest you remove the program now. Go to <b>Start</b> > <b>Settings</b> > <b>Control Panel</b> > <b>Add/Remove Programs</b> and remove the following programs if present:<b><br>- Viewpoint<br>- Viewpoint Manager<br>- Viewpoint Media Player</b><br>Reboot afterwards. -- Important!<br><br>If you chose to uninstall Viewpoint, after rebooting, using Windows Explorer delete the following folder if still there:<br>C:\Program Files\<b>Viewpoint</b><br><br>You are (or were) running LimeWire. Various version of LimeWire have included spyware.  I <b>highly</b> recommend uninstalling it and replacing it with a clean P2P program. As an alternative, there is an exact, open source clone of LimeWire called <A HREF="http://www.frostwire.com/">FrostWire</a>. Except for the name and color scheme, it's the same program. You can find a list of clean P2P programs at  &raquo;<A HREF="http://p2p.malwareremoval.com" >p2p.malwareremoval.com</A>. Remember, however, that just because the P2P client is clean, doesn't mean that the files you download are. Many P2P networks are riddled with malware, and it's often some of the most recent and therefore sometimes the most difficult to remove.<br><br>If you chose to optionally uninstall Limewire, go to Start -> Settings -> Control Panel -> Add or Remove Programs and uninstall the following program:<br><b>LimeWire</b><br><br>Then, using Windows Explorer, delete the folder:<br>C:\Program Files\<b>LimeWire</b><br><br>We need to make sure you have the most recent version of ComboFix.<br><b>Delete</b> your current copy of ComboFix.exe.<br>Download <b>ComboFix&copy; by sUBs</b> from one of these links:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Save the file to your Desktop.<br>Close any open browsers.<br>Close your AntiVirus and any anti-spyware programs you may be running.<br><br>For this next step, please <b>ensure that ComboFix.exe is on your desktop:</b><br><br>Please open <b>Notepad</b>*Do Not Use Wordpad!*(Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:<br>Save this as <b>"CFScript.txt"</b> and change the "Save as type" to "All Files" and place it on your <b>desktop</b>.<br><br> <blockquote><small>quote:</small><hr>Driver::<br>19afffad<br>df90d040<br><br>File::<br>c:\windows\system32\drivers\19afffad.sys<br>c:\windows\system32\drivers\df90d040.sys<br><hr></blockquote><br>Save this as <b>CFScript.txt</b>, in the same location as ComboFix.exe<br><br> <IMG SRC="http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif">  <br><br>Referring to the picture above, drag CFScript into ComboFix.exe<br>When finished, it will produce a log for you at <b>C:\ComboFix.txt</b>. Please post that log in your next reply.<br><br>Please do a scan with <A HREF="http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html">Kaspersky Online Scanner</a><br><br><i>Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.</i><br><br>Click on the <b>Accept</b> button and install any components it needs.<br>- The program will install and then begin downloading the latest definition files.<br>- After the files have been downloaded on the left side of the page in the <b>Scan</b> section select <b>My Computer</b>.<br>- This will start the program and scan your system.<br>- The scan will take a while, so be patient and let it run.<br>- Once the scan is complete, click on <b>View scan report</b><br>- Now, click on the <b>Save Report as</b> button.<br>- In the drop down box labeled <b>Files of type</b> change the type to <b>Text file</b>.<br>- Save the file to your desktop.<br>- Copy and paste that information in your next post.<br><br>Please post a new HijackThis log, The log from Kaspersky's online scanner, the log from ComboFix (combofix.txt), and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22471929</guid>
<pubDate>Sun, 31 May 2009 08:42:35 EDT</pubDate>
</item>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22471193</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Ok, done.<br><br>Problems encountered: FF and Chrome failed to connect (I'm assuming because of the virus). I actually had to delete IE and use an older version to connect.<br><br>And again, once the network got running the spam started running through, so I shut down ccApp to stop the popups.<br><br><b>MBAM LOG:</b><br>Malwarebytes' Anti-Malware 1.37<br>Database version: 2196<br>Windows 5.1.2600 Service Pack 2<br><br>5/30/2009 11:23:59 PM<br>mbam-log-2009-05-30 (23-23-59).txt<br><br>Scan type: Quick Scan<br>Objects scanned: 89043<br>Time elapsed: 4 minute(s), 4 second(s)<br><br>Memory Processes Infected: 0<br>Memory Modules Infected: 0<br>Registry Keys Infected: 1<br>Registry Values Infected: 0<br>Registry Data Items Infected: 1<br>Folders Infected: 0<br>Files Infected: 0<br><br>Memory Processes Infected:<br>(No malicious items detected)<br><br>Memory Modules Infected:<br>(No malicious items detected)<br><br>Registry Keys Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> Quarantined and deleted successfully.<br><br>Registry Values Infected:<br>(No malicious items detected)<br><br>Registry Data Items Infected:<br>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.<br><br>Folders Infected:<br>(No malicious items detected)<br><br>Files Infected:<br>(No malicious items detected)<br><br><b>COMBO FIX LOG:</b><br>ComboFix 09-05-30.03 - ATL 05/30/2009 23:55.1 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1022.528 [GMT -7:00]<br>Running from: c:\documents and settings\ATL\Desktop\pppp.exe<br>AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}<br>FW: Symantec Client Firewall *enabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187}<br><br>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br><br>c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat<br>c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat<br>c:\windows\system32\ledahili.dll<br>c:\windows\system32\rayizanu.exe<br>c:\windows\system32\rezizoto.exe<br>c:\windows\system32\roruhore.exe<br>c:\windows\system32\ukudemeb.ini<br>c:\windows\system32\vakakayu.exe<br>c:\windows\system32\yedobivi.dll<br>c:\windows\system32\zirukeka.dll<br><br>----- BITS: Possible infected sites -----<br><br>hxxp://62.4.83.201<br>.<br>(((((((((((((((((((((((((   Files Created from 2009-04-28 to 2009-05-31  )))))))))))))))))))))))))))))))<br>.<br><br>2009-05-31 06:38 . 2009-05-31 06:46&#9;--------&#9;d-s---w&#9;C:\ComboFix<br>2009-05-30 18:32 . 2009-05-30 18:32&#9;--------&#9;dc----w&#9;c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}<br>2009-05-30 16:51 . 2009-05-30 16:51&#9;--------&#9;d-----w&#9;c:\program files\Trend Micro<br>2009-05-30 16:43 . 2009-05-26 20:20&#9;40160&#9;----a-w&#9;c:\windows\system32\drivers\mbamswissarmy.sys<br>2009-05-30 16:43 . 2009-05-30 16:43&#9;--------&#9;d-----w&#9;c:\program files\Malwarebytes' Anti-Malware<br>2009-05-30 16:43 . 2009-05-26 20:19&#9;19096&#9;----a-w&#9;c:\windows\system32\drivers\mbam.sys<br>2009-05-22 00:47 . 2009-05-22 00:47&#9;--------&#9;d-s---w&#9;c:\windows\system32\config\systemprofile\UserData<br>2009-05-21 10:34 . 2009-05-21 10:36&#9;--------&#9;d-----w&#9;c:\program files\Spybot - Search & Destroy<br>2009-05-21 10:34 . 2009-05-21 10:36&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy<br>2009-05-05 07:13 . 2009-05-05 07:13&#9;--------&#9;d-----w&#9;c:\documents and settings\ATL\Application Data\Malwarebytes<br>2009-05-05 07:13 . 2009-05-05 07:13&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\Malwarebytes<br>2009-05-04 20:34 . 2009-05-22 01:58&#9;0&#9;----a-w&#9;c:\windows\system32\drivers\19afffad.sys<br>2009-05-03 08:05 . 2009-05-03 08:05&#9;45056&#9;----a-r&#9;c:\documents and settings\ATL\Application Data\Microsoft\Installer\{8BF863F9-7739-4DA4-B40A-2AD76D571B82}\MapleStory.exe_DB457427E7B9425292170DC5FADE980F.exe<br>2009-05-03 08:05 . 2009-05-03 08:05&#9;45056&#9;----a-r&#9;c:\documents and settings\ATL\Application Data\Microsoft\Installer\{8BF863F9-7739-4DA4-B40A-2AD76D571B82}\MapleStory.exe1_DB457427E7B9425292170DC5FADE980F.exe<br>2009-05-03 08:05 . 2009-05-03 08:05&#9;10134&#9;----a-r&#9;c:\documents and settings\ATL\Application Data\Microsoft\Installer\{8BF863F9-7739-4DA4-B40A-2AD76D571B82}\ARPPRODUCTICON.exe<br>2009-05-03 06:34 . 2009-05-03 08:31&#9;--------&#9;d-----w&#9;c:\documents and settings\ATL\Local Settings\Application Data\PMB Files<br>2009-05-03 06:34 . 2009-05-03 06:35&#9;--------&#9;d-----w&#9;c:\documents and settings\All Users\Application Data\PMB Files<br>2009-05-03 06:34 . 2009-05-03 06:34&#9;--------&#9;d-----w&#9;c:\program files\Pando Networks<br>2009-05-01 21:04 . 2009-05-01 21:04&#9;212480&#9;----a-w&#9;c:\windows\system32\dllcache\ndis.sys<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2009-05-31 06:25 . 2008-08-07 06:35&#9;40&#9;----a-w&#9;c:\windows\system32\profile.dat<br>2009-05-31 06:14 . 2009-03-30 09:42&#9;--------&#9;d-----w&#9;c:\documents and settings\ATL\Application Data\PC Tools<br>2009-05-30 18:52 . 2008-08-07 06:35&#9;--------&#9;d-----w&#9;c:\program files\Common Files\Symantec Shared<br>2009-05-03 08:34 . 2009-03-30 09:42&#9;--------&#9;d---a-w&#9;c:\documents and settings\All Users\Application Data\TEMP<br>2009-05-03 08:12 . 2009-05-03 08:12&#9;87552&#9;---ha-w&#9;c:\windows\system32\BITA21.tmp<br>2009-05-03 08:12 . 2009-05-03 08:12&#9;79872&#9;---ha-w&#9;c:\windows\system32\BITA22.tmp<br>2009-05-03 08:12 . 2009-05-03 08:12&#9;50688&#9;---ha-w&#9;c:\windows\system32\BITA20.tmp<br>2009-05-02 21:01 . 2008-08-13 01:49&#9;--------&#9;d-----w&#9;c:\program files\Warcraft III<br>2009-05-01 21:04 . 1980-01-01 07:00&#9;212480&#9;----a-w&#9;c:\windows\system32\drivers\ndis.sys<br>2009-04-29 07:28 . 2008-12-31 09:09&#9;--------&#9;d-----w&#9;c:\documents and settings\ATL\Application Data\LimeWire<br>2009-04-14 04:03 . 2009-04-14 04:03&#9;2713&#9;--sh--w&#9;c:\windows\system32\barufutu.exe<br>2009-04-10 22:37 . 2009-04-10 22:37&#9;2713&#9;--sh--w&#9;c:\windows\system32\ratijipe.exe<br>2009-04-09 22:37 . 2009-04-09 22:37&#9;15644&#9;--sha-w&#9;c:\windows\system32\pisabupe.dll<br>2009-04-09 08:36 . 2009-04-09 08:36&#9;2713&#9;--sh--w&#9;c:\windows\system32\nopededo.dll<br>2009-04-09 08:36 . 2009-04-09 08:36&#9;2713&#9;--sh--w&#9;c:\windows\system32\limehabe.exe<br>2009-04-01 05:55 . 2009-04-01 05:55&#9;10866&#9;--sha-w&#9;c:\windows\system32\fujayagi.dll<br>2009-03-23 08:02 . 2009-03-23 08:02&#9;75048&#9;----a-w&#9;c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.0.52\SetupAdmin.exe<br>2009-03-20 05:34 . 2008-08-13 01:53&#9;77691&#9;----a-w&#9;c:\windows\War3Unin.dat<br>2009-03-06 23:45 . 2009-03-30 09:43&#9;130424&#9;----a-w&#9;c:\windows\system32\drivers\PCTCore.sys<br>2009-03-06 06:59 . 2009-03-23 08:05&#9;1900544&#9;----a-w&#9;c:\windows\system32\usbaaplrc.dll<br>2009-03-06 06:59 . 2008-12-26 20:30&#9;36864&#9;----a-w&#9;c:\windows\system32\drivers\usbaapl.sys<br>2009-02-01 08:42 . 2009-02-01 08:42&#9;50688&#9;--sha-w&#9;c:\windows\system32\ligenisa.exe<br>2009-01-12 21:16 . 2009-01-12 21:16&#9;51200&#9;--sha-w&#9;c:\windows\system32\lonazaki.exe<br>2009-02-02 19:53 . 2009-02-02 19:53&#9;51200&#9;--sha-w&#9;c:\windows\system32\ludojila.exe<br>2009-02-04 04:48 . 2009-02-04 04:48&#9;50688&#9;--sha-w&#9;c:\windows\system32\malodoso.exe<br>2009-02-03 08:12 . 2009-02-03 08:12&#9;50688&#9;--sha-w&#9;c:\windows\system32\nokadeno.exe<br>.<br><br>------- Sigcheck -------<br><br>[-] 2008-04-14 00:12&#9;507904&#9;ED0EF0A136DEC83DF69F04118870003E&#9;c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\winlogon.exe<br>[-] 2008-08-26 05:33&#9;502784&#9;B359DE33041BA9ACAB6392745C3F81ED&#9;c:\windows\system32\winlogon.exe<br><br>[-] 2008-04-13 19:20&#9;182656&#9;1DF7F42665C94B825322FAE71721130D&#9;c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ndis.sys<br>[-] 2009-05-01 21:04&#9;212480&#9;791778A1F54D4B3F36773F11783A53FC&#9;c:\windows\system32\dllcache\ndis.sys<br>[-] 2009-05-01 21:04&#9;212480&#9;791778A1F54D4B3F36773F11783A53FC&#9;c:\windows\system32\drivers\ndis.sys<br><br>[-] 2008-04-14 00:12&#9;295424&#9;FF3477C03BE7201C294C35F684B3479F&#9;c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\termsrv.dll<br>[-] 2008-08-26 05:33&#9;295424&#9;40FFC19A8D4875E9E19CECDC76EF9201&#9;c:\windows\system32\termsrv.dll<br>.<br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]<br>"Google Update"="c:\documents and settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-11 133104]<br>"aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-09-15 110592]<br>"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-09-15 512000]<br>"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2005-10-29 864256]<br>"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-11-17 237568]<br>"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-03-09 94208]<br>"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-12-15 925696]<br>"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]<br>"suScheduler"="c:\program files\ThinkVantage\SystemUpdate\UCLauncher.exe" [2005-08-02 40960]<br>"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2006-01-25 106496]<br>"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2005-11-14 487424]<br>"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-08-01 122940]<br>"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]<br>"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]<br>"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752]<br>"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2005-10-28 335872]<br>"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-11-29 196696]<br>"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2006-04-17 409600]<br>"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-04-17 98304]<br>"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-12-07 151552]<br>"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-12-07 208896]<br>"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-31 136600]<br>"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]<br>"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]<br>"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2005-11-07 106496]<br>"TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2005-10-17 65536]<br><br>c:\documents and settings\All Users\Start Menu\Programs\Startup\<br>Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]<br>Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2005-11-1 581693]<br>Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-6 24576]<br><br>[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]<br>"DisallowRun"= 0 (0x0)<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]<br>2006-04-17 20:01&#9;32768&#9;----a-w&#9;c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]<br>2005-12-08 21:59&#9;39936&#9;----a-w&#9;c:\windows\system32\psqlpwd.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]<br>2005-07-06 06:45&#9;28672&#9;----a-w&#9;c:\windows\system32\notifyf2.dll<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]<br>2005-12-01 03:16&#9;24576&#9;----a-w&#9;c:\windows\system32\tphklock.dll<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]<br>Notification Packages&#9;REG_MULTI_SZ   &#9;scecli psqlpwd<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]<br>@=""<br><br>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]<br>@=""<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]<br>"DisableMonitoring"=dword:00000001<br><br>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]<br>"DisableMonitoring"=dword:00000001<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"%windir%\\system32\\sessmgr.exe"=<br>"c:\\Program Files\\ThinkVantage\\SystemUpdate\\jre\\bin\\javaw.exe"=<br>"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=<br>"c:\\Program Files\\AIM6\\aim6.exe"=<br>"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=<br>"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=<br>"c:\\Program Files\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=<br>"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=<br>"c:\\Program Files\\iTunes\\iTunes.exe"=<br>"c:\\Program Files\\LimeWire\\LimeWire.exe"=<br>"c:\\Program Files\\iTunes\\iTunesHelper.exe"=<br>"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]<br>"56823:TCP"= 56823:TCP:Pando Media Booster<br>"56823:UDP"= 56823:UDP:Pando Media Booster<br><br>R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/30/2009 2:43 AM 130424]<br>R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [8/6/2008 11:19 PM 85760]<br>R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [8/6/2008 11:19 PM 4736]<br>R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [8/6/2008 11:42 PM 4442]<br>R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [12/8/2005 2:44 PM 3328]<br>R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/8/2008 7:21 PM 24652]<br>S1 19afffad;19afffad;c:\windows\system32\drivers\19afffad.sys [5/4/2009 1:34 PM 0]<br>S1 df90d040;df90d040;c:\windows\system32\drivers\df90d040.sys --> c:\windows\system32\drivers\df90d040.sys [?]<br>S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [8/18/2005 5:22 PM 124608]<br>S3 sdAuxService;PC Tools Auxiliary Service;c:\nexon\Spyware Doctor\pctsAuxs.exe --> c:\nexon\Spyware Doctor\pctsAuxs.exe [?]<br><br>--- Other Services/Drivers In Memory ---<br><br>*Deregistered* - EraserUtilDrvI7<br>.<br>Contents of the 'Scheduled Tasks' folder<br><br>2009-05-02 c:\windows\Tasks\AppleSoftwareUpdate.job<br>- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]<br><br>2009-05-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-881565578-3357626825-4007795620-1005.job<br>- c:\documents and settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 10:27]<br><br>2009-05-31 c:\windows\Tasks\PMTask.job<br>- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-08-07 08:12]<br><br>2008-08-07 c:\windows\Tasks\Symantec NetDetect.job<br>- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2008-08-07 00:32]<br>.<br>- - - - ORPHANS REMOVED - - - -<br><br>SafeBoot-procexp90.Sys<br><br>.<br>------- Supplementary Scan -------<br>.<br>uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8<br>uInternet Connection Wizard,ShellNext = iexplore<br>uSearchURL,(Default) = hxxp://www.google.com/search?q=%s<br>FF - ProfilePath - c:\documents and settings\ATL\Application Data\Mozilla\Firefox\Profiles\qwywtq3l.default\<br>FF - plugin: c:\documents and settings\ATL\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll<br>FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll<br>FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll<br>FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll<br>FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll<br>FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll<br>.<br><br>**************************************************************************<br><br>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2009-05-30 23:57<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ...  <br><br>scanning hidden autostart entries ... <br><br>scanning hidden files ...  <br><br>scan completed successfully<br>hidden files: 0<br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>- - - - - - - > 'winlogon.exe'(992)<br>c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll<br>c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll<br>c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll<br>c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll<br>c:\windows\system32\Ati2evxx.dll<br>c:\windows\system32\psqlpwd.dll<br>c:\program files\ThinkVantage Fingerprint Software\infra.dll<br>c:\program files\ThinkVantage Fingerprint Software\homefus2.dll<br>c:\windows\system32\biologon.dll<br>c:\program files\ThinkVantage Fingerprint Software\homepass.dll<br>c:\program files\ThinkVantage Fingerprint Software\bio.dll<br>c:\program files\ThinkVantage Fingerprint Software\remote.dll<br>c:\program files\ThinkVantage Fingerprint Software\ps2css.dll<br>c:\windows\system32\tphklock.dll<br><br>- - - - - - - > 'lsass.exe'(1052)<br>c:\windows\system32\psqlpwd.dll<br>c:\program files\ThinkVantage Fingerprint Software\infra.dll<br>c:\program files\ThinkVantage Fingerprint Software\homefus2.dll<br>.<br>Completion time: 2009-05-31 23:58<br>ComboFix-quarantined-files.txt  2009-05-31 06:58<br><br>Pre-Run: 64,699,904,000 bytes free<br>Post-Run: 64,793,206,784 bytes free<br><br>232&#9;--- E O F ---&#9;2009-03-13 10:02<br><br><b>HIJACK THIS LOG:</b><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 12:01:35 AM, on 5/31/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\ibmpmsvc.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe<br>C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\IPSSVC.EXE<br>C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br>C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe<br>C:\WINDOWS\System32\TPHDEXLG.EXE<br>C:\WINDOWS\system32\TpKmpSVC.exe<br>C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe<br>C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br>C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>C:\WINDOWS\system32\TpShocks.exe<br>C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br>C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe<br>C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe<br>C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe<br>C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Documents and Settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe<br>C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\explorer.exe<br>C:\WINDOWS\system32\NOTEPAD.EXE<br>C:\WINDOWS\system32\NOTEPAD.EXE<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>O1 - Hosts: scanner.info<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br>O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br>O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll<br>O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper<br>O4 - HKLM\..\Run: [TpShocks] TpShocks.exe<br>O4 - HKLM\..\Run: [TP4EX] tp4ex.exe<br>O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br>O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe<br>O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay<br>O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER<br>O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe<br>O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe<br>O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br>O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe<br>O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"<br>O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br>O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br>O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor<br>O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c<br>O4 - HKCU\..\Run: [aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Bluetooth.lnk = ?<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O11 - Options group: [JAVA_IBM] Java (IBM)<br>O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)<br>O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br>O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br>O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE<br>O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Nexon\Spyware Doctor\pctsAuxs.exe (file missing)<br>O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - C:\Nexon\Spyware Doctor\pctsSvc.exe (file missing)<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe<br>O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe<br>O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE<br>O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe<br>O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br><br>--<br>End of file - 11469 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22471193</guid>
<pubDate>Sun, 31 May 2009 06:42:59 EDT</pubDate>
</item>

<item>
<title>Re: [Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22470671</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : Hi Superman1234<br><br>I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier. Please follow the directions in the order listed.<br><br>Spyware Doctor's OnGuard protective functionality may interfere with certain HijackThis fixes we need to make.  Please follow these instructions to disable it:<br><br><b>To deactivate Spyware Doctor's OnGuard Tools</b><br><br>1. From within Spyware Doctor, click the "OnGuard" button on the left side.<br>2. Uncheck "Activate OnGuard".<br><br>You can reenable it once your system is clean.<br><br>Clean your Cache and Cookies in IE:<br>-Close all instances of Outlook Express and Internet Explorer <br>-Go to Control Panel > Internet Options > General tab<br>-Click the "Delete Cookies" button<br>-Next to it, Click the "Delete Files" button<br>-When prompted, place a check in: "Delete all offline content", click OK<br>Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):<br>Go to Tools > Options.<br>Click Privacy in the menu on the left side of the Options window.<br>Click the Clear button located to the right of each option (History, Cookies, Private Data).<br>Click OK to close the Options window<br>Alternatively, you can clear all information stored while browsing by clicking Clear All. <br>A confirmation dialog box will be shown before clearing the information.<br>Clean other Temporary files + Recycle bin<br>-Go to start > run and type: <b>cleanmgr</b> and click ok.<br>-Let it scan your system for files to remove.<br>-Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.<br>-Press OK to remove them.<br><br>Download <b>HostsXpert</b> from here: <br><textarea name="code" class="text" cols=50 rows=10>http://www.funkytoad.com/download/HostsXpert.zip&#012;</textarea><!--end code block-->Extract the file HostsXpert.exe to your Desktop and run it.<br>Press 'Restore Original Hosts' and press 'OK'<br>Exit Program.<br>Note: if you were using a custom Hosts file you will need to replace any of those entries yourself.<br><br>Please Run Malwarebytes' Anti-Malware.<br>- Click the Update tab.<br>- Click <b>Check for Updates</b>.<br>- If an update is found, it will download and install.<br>- Click the Scanner tab.<br>- Select "<b>Perform Quick Scan</b>", then click <b>Scan</b>.<br>- The scan may take some time to finish,so please be patient.<br>- When the scan is complete, click OK, then Show Results to view the results.<br>- Make sure that <b>everything is checked</b>, and click <b>Remove Selected</b>.<br>- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)<br>- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.<br>- Copy & Paste the entire report in your next reply along with a fresh HijackThis log.<br><br>Note:<br><i>If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.<br>Click OK to either and let MBAM proceed with the disinfection process.<br>If asked to restart the computer, please do so immediately.</i><br><br>Now you need to run HijackThis and click "<b>Do a system scan only</b>." Place a check next to the following entries (if they are still there):<br><br><b>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<br>O4 - HKLM\..\Run: [lphcc1sj0ec2p] C:\WINDOWS\system32\lphcc1sj0ec2p.exe<br>O20 - AppInit_DLLs: ,C:\WINDOWS\system32\romonata.dll c:\windows\system32\ruhirowa.dll</b><br><br>Now close all browser and other windows except for HijackThis, and click "<b>Fix Checked</b>" to have HijackThis fix the entries you checked.<br><br>Using Windows Explorer, locate the following files, and delete them (if still there):<br>C:\WINDOWS\system32\<b>lphcc1sj0ec2p.exe</b><br>C:\WINDOWS\system32\<b>romonata.dll</b><br>c:\windows\system32\<b>ruhirowa.dll</b><br><br>Download <b>ComboFix&copy; by sUBs</b> from one of these locations:<br><br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br><b>* IMPORTANT !!! Save ComboFix.exe to your Desktop</b><br><br>Familiarize yourself with ComboFix before running it:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" >www.bleepingcomputer.com/combofi&middot;&middot;&middot;combofix</A><br><br>- Disable your AntiVirus and any AntiSpyware programs you may be running (usually via a right click on the System Tray icon) to prevent them from interfering.<br><br>- Double click on ComboFix.exe & follow the prompts.<br><br>- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. <br><br>- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.<br><br>**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif"> <br><br>Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:<br><br> <IMG SRC="http://img.photobucket.com/albums/v706/ried7/whatnext.png"> <br><br>Click on Yes, to continue scanning for malware. When finished, it will save a log. <br>Please include the contents of the log at <b>C:\ComboFix.txt</b> in your next reply.<br><br>Please post a new HijackThis log, the log from MBAM (if the log is clean, please post the previous log and let me know you did so), the log from ComboFix (combofix.txt), and note any errors encountered.<br><br><small>--<br>Proud ASAP member since 2005</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22470671</guid>
<pubDate>Sat, 30 May 2009 21:24:29 EDT</pubDate>
</item>

<item>
<title>[Virus] Sending Spam</title>
<link>http://www.dslreports.com/forum/remark,22469955</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Symantec's been picking up a lot of spam heading out of my computer, and it's made it unusable. I've found that closing the process "ccApp" will actually stop the popups, but will sometimes kill my network.<br><br>Spybot/Malware both got rid of numerous trojans, which have actually delayed the spam (as in, instead of it beginning immediately once network connects there will be a 10 minute delay or so), but it's still coming through.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 5:55:29 PM, on 5/30/2009<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\ibmpmsvc.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe<br>C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\WINDOWS\system32\IPSSVC.EXE<br>C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br>C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>C:\Program Files\Bonjour\mDNSResponder.exe<br>C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br>C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe<br>C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br>C:\Program Files\Java\jre6\bin\jqs.exe<br>C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe<br>C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe<br>C:\WINDOWS\System32\TPHDEXLG.EXE<br>C:\WINDOWS\system32\TpKmpSVC.exe<br>C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe<br>C:\Program Files\Viewpoint\Common\ViewpointService.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe<br>C:\WINDOWS\system32\wscntfy.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br>C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>C:\WINDOWS\system32\TpShocks.exe<br>C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br>C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe<br>C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe<br>C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe<br>C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe<br>C:\Program Files\ThinkVantage\AMSG\Amsg.exe<br>C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\Program Files\Common Files\Symantec Shared\ccApp.exe<br>C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe<br>C:\Program Files\Picasa2\PicasaMediaDetector.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br>C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br>C:\WINDOWS\system32\rundll32.exe<br>C:\Program Files\Java\jre6\bin\jusched.exe<br>C:\Program Files\iTunes\iTunesHelper.exe<br>C:\WINDOWS\system32\ctfmon.exe<br>C:\Documents and Settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe<br>C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\iPod\bin\iPodService.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\wbem\wmiapsrv.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<br>O1 - Hosts: scanner.info<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL<br>O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll<br>O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll<br>O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper<br>O4 - HKLM\..\Run: [TpShocks] TpShocks.exe<br>O4 - HKLM\..\Run: [TP4EX] tp4ex.exe<br>O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe<br>O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe<br>O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe<br>O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay<br>O4 - HKLM\..\Run: [suScheduler] C:\Program Files\ThinkVantage\SystemUpdate\UCLauncher.exe /SCHEDULER<br>O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe<br>O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe<br>O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE<br>O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup<br>O4 - HKLM\..\Run: [ISUSScheduler] "c:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"<br>O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe<br>O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe<br>O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"<br>O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe<br>O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe<br>O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor<br>O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog<br>O4 - HKLM\..\Run: [lphcc1sj0ec2p] C:\WINDOWS\system32\lphcc1sj0ec2p.exe<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\ATL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c<br>O4 - HKCU\..\Run: [aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp<br>O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe<br>O4 - Global Startup: Bluetooth.lnk = ?<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL<br>O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O11 - Options group: [JAVA_IBM] Java (IBM)<br>O20 - AppInit_DLLs:  ,C:\WINDOWS\system32\romonata.dll c:\windows\system32\ruhirowa.dll<br>O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)<br>O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe<br>O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe<br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\<br>O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe<br>O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe<br>O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe<br>O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe<br>O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe<br>O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe<br>O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe<br>O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE<br>O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe<br>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe<br>O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe<br>O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Nexon\Spyware Doctor\pctsAuxs.exe (file missing)<br>O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - C:\Nexon\Spyware Doctor\pctsSvc.exe (file missing)<br>O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe<br>O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe<br>O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe<br>O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe<br>O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE<br>O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe<br>O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe<br>O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe<br><br>--<br>End of file - 12346 bytes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22469955</guid>
<pubDate>Sat, 30 May 2009 18:19:28 EDT</pubDate>
</item>

</channel>
</rss>
