|
#1
|
|||
|
|||
|
Can't remove MyWebSearch - moved by Tom
MyWebSearch got inadvertently downloaded onto my laptop. It shows up when I run Spybot- Search & Destroy, but cannot be removed, even on a reboot scan. I tried deleting it from the program files but it says that I don't have permission to do so. Also it does not show up in the "uninstall or change a program" list.
I want to remove it because Spybot brings it up in its scan, however I don't use Explorer, unless I run into a website that isn't supported by Firefox, my preferred browser. So I guess what I'm wondering is, if I don't use MyWebSearch or Explorer is it still worth the hasstle of getting this off my computer. If it is the PLEASE HELP ME! |
|
#2
|
||||
|
||||
|
Howdy CurvyBootcut,
Let's see what all is loaded there first. Please download HijackThis from Here. Then click on the downloaded file to install HijackThis. After it is installed open HijackThis and select Do a system scan and save logfile. Use copy/paste and post that log back here for review. Also go Here and download Silent Runners to your desktop. Run it, and post back here the log it creates. If your AV queries the script, allow it to run. It's not malicious. It will create a file named Startup Programs, and will notify when the scan is complete. Copy the log from the Startup Programs file back here. You can use separate posts here if needed.
__________________
I'm pretty sure my Snark is a Boojum. Back To Nature If we have helped you, please consider supporting Cyber Tech Help with a subscription. |
|
#3
|
|||
|
|||
|
HijackThis logfile
Logfile of HijackThis v1.99.1
Scan saved at 12:03:03 AM, on 9/23/2007 Platform: Unknown Windows (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\TpShocks.exe C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE C:\Windows\System32\rundll32.exe C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe C:\Program Files\Lenovo\AwayTask\AwaySch.EXE C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE C:\Program Files\ThinkVantage\AMSG\Amsg.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Windows\System32\rundll32.exe C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe C:\Windows\system32\taskeng.exe C:\Program Files\Lenovo\Client Security Solution\cssauth.exe C:\Program Files\Lenovo\Zoom\TpScrex.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Symantec AntiVirus\VPTray.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Windows\System32\spool\drivers\w32x86\3\fppdis2 a.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Lenovo\Client Security Solution\tvtpwm_tray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Thunderbird\thunderbird.exe C:\Users\Blake\Desktop\Ugly annoying stuff\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.live.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - c:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: ThinkVantage Password Manager - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - c:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrB kGndMonitor O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBa ttLog O4 - HKLM\..\Run: [TpShocks] TpShocks.exe O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe" O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent O4 - HKLM\..\Run: [LenovoOobeOffers] c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe /filePath="c:\swshare\firstrun.txt" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] C:\Windows\system32\spool\DRIVERS\W32X86\3\fppdis2 a.exe O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Startup: Lenovo Registration.lnk = C:\Program Files\Lenovo Registration\Lenovo.exe O4 - Global Startup: Bluetooth.lnk = ? O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: &Search - ?p=ZJfox000 O8 - Extra context menu item: &Windows Live Search - res://c:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll O9 - Extra 'Tools' menuitem: ThinkVantage Password Manager... - {0045D4BC-5189-4b67-969C-83BB1906C421} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll O11 - Options group: [INTERNATIONAL] International* O13 - Gopher Prefix: O16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} (CInstallLPCtrl Object) - http://u3.sandisk.com/download/apps/LPInstaller.CAB O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DL L O20 - Winlogon Notify: psfus - C:\Windows\system32\psqlpwd.dll O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\Windows\system32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\Windows\system32\IPSSVC.EXE O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: System Update (SUService) - - c:\Program Files\Lenovo\System Update\SUService.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\Windows\System32\TPHDEXLG.exe O23 - Service: On Screen Display (TPHKSVC) - Unknown owner - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe |
|
#4
|
|||
|
|||
|
"Silent Runners.vbs", revision 52, http://www.silentrunners.org/
Operating System: Windows Vista Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run \ {++} "Sidebar" = "C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" [MS] "WMPNSCFG" = "C:\Program Files\Windows Media Player\WMPNSCFG.exe" [MS] HKLM\Software\Microsoft\Windows\CurrentVersion\Run \ {++} "Windows Defender" = "C:\Program Files\Windows Defender\MSASCui.exe -hide" "TPFNF7" = "C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r" ["Lenovo Group Limited"] "SynTPEnh" = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."] "TPHOTKEY" = "C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe" ["Lenovo Group Limited"] "PWMTRV" = "rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrB kGndMonitor" [MS] "BLOG" = "rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBa ttLog" [MS] "(Default)" = "(empty string)" [file not found] "TpShocks" = "TpShocks.exe" ["Lenovo."] "EZEJMNAP" = "C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" ["Lenovo Group Ltd."] "NvSvc" = "RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart" [MS] "NvCplDaemon" = "RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" [MS] "NvMediaCenter" = "RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit" [MS] "TVT Scheduler Proxy" = "C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" ["Lenovo Group Limited"] "DiskeeperSystray" = ""C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"" ["Diskeeper Corporation"] "AwaySch" = "C:\Program Files\Lenovo\AwayTask\AwaySch.EXE" ["Lenovo Group Limited"] "LPManager" = "C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe" ["Lenovo Group Limited"] "AMSG" = "C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup" ["LENOVO"] "SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.6.0\bin\jusched.exe"" ["Sun Microsystems, Inc."] "RoxioDragToDisc" = ""C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe"" ["Roxio"] "ACTray" = "C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" ["Lenovo"] "ACWLIcon" = "C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" ["Lenovo"] "cssauth" = ""C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent" ["Lenovo Group Limited"] "LenovoOobeOffers" = "c:\SWTOOLS\LenovoWelcome\LenovoOobeOffers.exe /filePath="c:\swshare\firstrun.txt"" [null data] "ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"] "vptray" = "C:\PROGRA~1\SYMANT~1\VPTray.exe" ["Symantec Corporation"] "Adobe Reader Speed Launcher" = ""C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"" ["Adobe Systems Incorporated"] "SoundMAXPnP" = "C:\Program Files\Analog Devices\Core\smax4pnp.exe" ["Analog Devices, Inc."] "HP Software Update" = "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."] "pdfFactory Pro Dispatcher v2" = "C:\Windows\system32\spool\DRIVERS\W32X86\3\fppdis 2a.exe" ["FinePrint Software, LLC"] HKLM\Software\Microsoft\Windows\CurrentVersion\Run Once\ {++} "SpybotSnD" = ""C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck" ["Safer Networking Limited"] HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided) -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper" \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided) -> {HKLM...CLSID} = "SSVHelper Class" \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0\bin\ssv.dll" ["Sun Microsystems, Inc."] {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = (no title provided) -> {HKLM...CLSID} = "Windows Live Toolbar Helper" \InProcServer32\(Default) = "c:\Program Files\Windows Live Toolbar\msntb.dll" [MS] {F040E541-A427-4CF7-85D8-75E3E0F476C5}\(Default) = "ThinkVantage Password Manager" -> {HKLM...CLSID} = "CPwmIEBrowserHelper Object" \InProcServer32\(Default) = "C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll" ["Lenovo Group Limited"] HKLM\Software\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved\ "{E7DE9B1A-7533-4556-9484-B26FB486475E}" = (no title provided) -> {HKLM...CLSID} = "Network Map" \InProcServer32\(Default) = "C:\Windows\system32\shdocvw.dll" [MS] "{4A1E5ACD-A108-4100-9E26-D2FAFA1BA486}" = "IGD Property Sheet Handler" -> {HKLM...CLSID} = "IGD Property Page" \InProcServer32\(Default) = "C:\Windows\System32\icsigd.dll" [MS] "{8856f961-340a-11d0-a96b-00c04fd705a2}" = "Microsoft Web Browser" -> {HKLM...CLSID} = "Microsoft Web Browser" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{3050f3d9-98b5-11cf-bb82-00aa00bdce0b}" = "MSHTML Document" -> {HKLM...CLSID} = "MHTML Document" \InProcServer32\(Default) = "C:\Windows\system32\mshtml.dll" [MS] "{25336920-03f9-11cf-8fd0-00aa00686f13}" = "HTML Document" -> {HKLM...CLSID} = "HTML Document" \InProcServer32\(Default) = "C:\Windows\system32\mshtml.dll" [MS] "{74246bfc-4c96-11d0-abef-0020af6b0b7a}" = "Device Manager" -> {HKLM...CLSID} = "Device Manager" \InProcServer32\(Default) = "C:\Windows\System32\devmgr.dll" [MS] "{44f3dab6-4392-4186-bb7b-6282ccb7a9f6}" = "MyDocuments menu and properties" -> {HKLM...CLSID} = "MyDocuments menu and properties" \InProcServer32\(Default) = "C:\Windows\system32\mydocs.dll" [MS] "{D34A6CA6-62C2-4C34-8A7C-14709C1AD938}" = "Common Places Folder" -> {HKLM...CLSID} = "Common Places FS Folder" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{865e5e76-ad83-4dca-a109-50dc2113ce9a}" = "Programs Folder and Fast Items" -> {HKLM...CLSID} = "Programs Folder and Fast Items" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{21ec2020-3aea-1069-a2dd-08002b30309d}" = "Control Panel" -> {HKLM...CLSID} = "Control Panel" \InProcServer32\(Default) = "shell32.dll" [MS] "{25585dc7-4da0-438d-ad04-e42c8d2d64b9}" = "Client application shell extension" -> {HKLM...CLSID} = "Client application shell extension" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{4d5c8c2a-d075-11d0-b416-00c04fb90376}" = "Microsoft CommBand" -> {HKLM...CLSID} = "Microsoft CommBand" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{92337A8C-E11D-11D0-BE48-00C04FC30DF6}" = "OlePrn.PrinterURL" -> {HKLM...CLSID} = "prturl Class" \InProcServer32\(Default) = "C:\Windows\system32\oleprn.dll" [MS] "{16C2C29D-0E5F-45f3-A445-03E03F587B7D}" = "group_wab_auto_file" -> {HKLM...CLSID} = ".group shell context menu" \InProcServer32\(Default) = "C:\Program Files\Common Files\System\wab32.dll" [MS] "{CF67796C-F57F-45F8-92FB-AD698826C602}" = "contact_wab_auto_file" -> {HKLM...CLSID} = ".contact shell context menu" \InProcServer32\(Default) = "C:\Program Files\Common Files\System\wab32.dll" [MS] "{90b9bce2-b6db-4fd3-8451-35917ea1081b}" = "Search Execute Command" -> {HKLM...CLSID} = "CLSID_SearchExecute" \InProcServer32\(Default) = "ExplorerFrame.dll" [MS] "{1a184871-359e-4f67-aad9-5b9905d62232}" = "Microsoft Windows Font File Context Menu Handler" -> {HKLM...CLSID} = "Microsoft Windows Font Context Menu Handler" \InProcServer32\(Default) = "fontext.dll" [MS] "{8a7cae0e-5951-49cb-bf20-ab3fa1e44b01}" = "Microsoft Windows Font Previewer" -> {HKLM...CLSID} = "Microsoft Windows Font Preview Handler" \InProcServer32\(Default) = "fontext.dll" [MS] "{BC65FB43-1958-4349-971A-210290480130}" = "Network Explorer Property Sheet Handler" -> {HKLM...CLSID} = "Ncd Property Page" \InProcServer32\(Default) = "C:\Windows\System32\NcdProp.dll" [MS] "{0a4286ea-e355-44fb-8086-af3df7645bd9}" = "Windows Media Player" -> {HKLM...CLSID} = "&Windows Media Player" \InProcServer32\(Default) = "C:\PROGRA~1\WI4EB4~1\wmpband.dll" [MS] "{BB6B2374-3D79-41DB-87F4-896C91846510}" = "EMDFileProperties" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "emdmgmt.dll" [MS] "{7A0F6AB7-ED84-46B6-B47E-02AA159A152B}" = "Sync Center Simple Conflict Presenter" -> {HKLM...CLSID} = "Simple Conflict Presenter" \InProcServer32\(Default) = "C:\Windows\System32\SyncCenter.dll" [MS] "{00f20eb5-8fd6-4d9d-b75e-36801766c8f1}" = "PhotoAcqDropTarget" -> {HKLM...CLSID} = "PhotoAcqDropTarget" \InProcServer32\(Default) = "C:\Program Files\Windows Photo Gallery\PhotoAcq.dll" [MS] "{91ADC906-6722-4B05-A12B-471ADDCCE132}" = "Touch Band" -> {HKLM...CLSID} = "Touch Pointer" \InProcServer32\(Default) = "C:\Windows\System32\TouchX.dll" [MS] "{7D4734E6-047E-41e2-AEAA-E763B4739DC4}" = "Windows Media Player Play as Playlist Context Menu Handler" -> {HKLM...CLSID} = "WMP Play Folder As Playlist Launcher" \InProcServer32\(Default) = "C:\Windows\system32\wmpshell.dll" [MS] "{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}" = "GameUX.RichGameMediaThumbnail" -> {HKLM...CLSID} = "RichGameMediaThumbnail Class" \InProcServer32\(Default) = "C:\Windows\System32\gameux.dll" [MS] "{15D633E2-AD00-465b-9EC7-F56B7CDF8E27}" = "Tablet PC Input Panel" -> {HKLM...CLSID} = "Tablet PC Input Panel" \InProcServer32\(Default) = "C:\Program Files\Common Files\microsoft shared\ink\TipBand.dll" [MS] "{6b9228da-9c15-419e-856c-19e768a13bdc}" = "Windows gadget DropTarget" -> {HKLM...CLSID} = "Windows gadget DropTarget" \InProcServer32\(Default) = "C:\Program Files\Windows Sidebar\sbdrop.dll" [MS] "{8A734961-C4AA-4741-AC1E-791ACEBF5B39}" = "Windows Media Player Shop Music Context Menu Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\wmpshell.dll" [MS] "{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Program Files\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."] "{7842554E-6BED-11D2-8CDB-B05550C10000}" = "Monitor" -> {HKLM...CLSID} = "Monitor Class" \InProcServer32\(Default) = "C:\Windows\system32\btncopy.dll" ["Broadcom Corporation."] "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class" -> {HKLM...CLSID} = "DesktopContext Class" \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"] "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper" -> {HKLM...CLSID} = "NVIDIA CPL Extension" \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"] "{23170F69-40C1-278A-1000-000100020000}" = "7-Zip Shell Extension" -> {HKLM...CLSID} = "7-Zip Shell Extension" \InProcServer32\(Default) = "C:\Program Files\ThinkVantage\SMA\7z\7-zip.dll" ["Igor Pavlov"] "{5E44E225-A408-11CF-B581-008029601108}" = "Roxio DragToDisc Shell Extension" -> {HKLM...CLSID} = "Roxio DragToDisc Shell Extension" \InProcServer32\(Default) = "C:\Program Files\Lenovo\Drag-to-Disc\Shellex.dll" ["Roxio"] "{8BEEE74D-455E-4616-A97A-F6E86C317F32}" = "LDVP Shell Extensions" -> {HKLM...CLSID} = "VpshellEx Class" \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"] "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler" -> {HKLM...CLSID} = "Outlook File Icon Extension" \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL" [MS] "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler" -> {HKLM...CLSID} = "Microsoft Office Outlook" \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL" [MS] "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS] "{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler" -> {HKLM...CLSID} = "Microsoft Office Metadata Handler" \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.d ll" [MS] "{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler" -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler" \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.d ll" [MS] "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ <<!>> "GinaDLL" = "vrlogon.dll" ["UPEK Inc."] HKLM\Software\Classes\PROTOCOLS\Filter\ <<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}" -> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter" \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.D LL" [MS] HKLM\Software\Classes\Folder\shellex\ColumnHandler s\ {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info" -> {HKLM...CLSID} = "PDF Shell Extension" \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."] HKLM\Software\Classes\*\shellex\ContextMenuHandler s\ LDVPMenu\(Default) = "{8BEEE74D-455E-4616-A97A-F6E86C317F32}" -> {HKLM...CLSID} = "VpshellEx Class" \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Directory\shellex\ContextMen uHandlers\ WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHa ndlers\ LDVPMenu\(Default) = "{8BEEE74D-455E-4616-A97A-F6E86C317F32}" -> {HKLM...CLSID} = "VpshellEx Class" \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll" ["Symantec Corporation"] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] |
|
#5
|
|||
|
|||
|
Group Policies {GPedit.msc branch and setting}:
----------------------------------------------- Note: detected settings may not have any effect. HKLM\Software\Microsoft\Windows\CurrentVersion\Pol icies\System\ "ConsentPromptBehaviorAdmin" = (REG_DWORD) hex:0x00000002 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Behavior Of The Elevation Prompt For Administrators In Admin Approval Mode} "ConsentPromptBehaviorUser" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Behavior Of The Elevation Prompt For Standard Users} "EnableInstallerDetection" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Detect Application Installations And Prompt For Elevation} "EnableLUA" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Run All Administrators In Admin Approval Mode} "EnableSecureUIAPaths" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Only elevate UIAccess applications that are installed in secure locations} "EnableVirtualization" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Virtualize file and registry write failures to per-user locations} "PromptOnSecureDesktop" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Conrol: Switch to the secure desktop when prompting for elevation} "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} "undockwithoutlogon" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} "FilterAdministratorToken" = (REG_DWORD) hex:0x00000000 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| User Account Control: Admin Approval Mode for the Built-in Administrator Account} "DisableCAD" = (REG_DWORD) hex:0x00000001 {unrecognized setting} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ "Wallpaper" = "C:\Windows\system32\config\systemprofile\Pictures \2007-09-17 Sun&Moon\Sun&Moon 004.JPG" Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ "Wallpaper" = "C:\Users\Blake\Pictures\2007-09-17 Sun&Moon\Sun&Moon 004.JPG" Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ "SCRNSAVE.EXE" = "C:\Windows\system32\Ribbons.scr" [MS] Startup items in "Blake" & "All Users" startup folders: ------------------------------------------------------- C:\Users\Blake\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Startup "Lenovo Registration" -> shortcut to: "C:\Program Files\Lenovo Registration\Lenovo.exe /remind /language=ENU /INIF="C:\SWSHARE\leadertech.ini" /PRNM="Lenovo"" ["Leader Technologies/Lenovo"] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup "Bluetooth" -> shortcut to: "C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe" ["Broadcom Corporation."] "Digital Line Detect" -> shortcut to: "C:\Program Files\Digital Line Detect\DLG.exe" ["Avanquest Software "] "HP Digital Imaging Monitor" -> shortcut to: "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" ["Hewlett-Packard Co."] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Pa rameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS] 000000000002\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000003\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 000000000004\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS] 000000000005\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS] 000000000006\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS] 000000000007\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Pa rameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 23 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" -> {HKLM...CLSID} = "Windows Live Toolbar" \InProcServer32\(Default) = "c:\Program Files\Windows Live Toolbar\msntb.dll" [MS] HKLM\Software\Microsoft\Internet Explorer\Toolbar\ "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = (no title provided) -> {HKLM...CLSID} = "Windows Live Toolbar" \InProcServer32\(Default) = "c:\Program Files\Windows Live Toolbar\msntb.dll" [MS] Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Research" Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL" [MS] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {0045D4BC-5189-4B67-969C-83BB1906C421}\ "MenuText" = "ThinkVantage Password Manager..." "CLSIDExtension" = "{0FE81B52-73FA-425F-8F06-3F32451AC73F}" -> {HKLM...CLSID} = "CPwmIEToolsMenuItem Object" \InProcServer32\(Default) = "C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll" ["Lenovo Group Limited"] {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ "MenuText" = "Sun Java Console" "CLSIDExtension" = "{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}" -> {HKLM...CLSID} = "Java Plug-in 1.6.0" \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0\bin\ssv.dll" ["Sun Microsystems, Inc."] {92780B25-18CC-41C8-B9BE-3C9C571A8263}\ "ButtonText" = "Research" {CCA281CA-C863-46EF-9331-5C8D4460577F}\ "ButtonText" = "@btrez.dll,-4015" "MenuText" = "@btrez.dll,-12650" "Script" = "C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm" [null data] HOSTS file ---------- C:\Windows\System32\drivers\etc\HOSTS maps: 2 domain names to IP addresses, 1 of the IP addresses is *not* localhost! Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Ac Profile Manager Service, AcPrfMgrSvc, "C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe" ["Lenovo"] Access Connections Main Service, AcSvc, "C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe" ["Lenovo"] Andrea ADI Filters Service, AEADIFilters, "C:\Windows\system32\AEADISRV.EXE" ["Andrea Electronics Corporation"] Bluetooth Service, btwdins, "C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe" ["Broadcom Corporation."] Bluetooth Support Service, BthServ, "C:\Windows\system32\svchost.exe -k bthsvcs" {"C:\Windows\System32\bthserv.dll" [MS]} Certificate Propagation, CertPropSvc, "C:\Windows\system32\svchost.exe -k netsvcs" {"C:\Windows\System32\certprop.dll" [MS]} CNG Key Isolation, KeyIso, "C:\Windows\system32\lsass.exe" [MS] Diskeeper, Diskeeper, ""C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe"" ["Diskeeper Corporation"] Extensible Authentication Protocol, EapHost, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\eapsvc.dll" [MS]} Function Discovery Resource Publication, FDResPub, "C:\Windows\system32\svchost.exe -k LocalService" {"C:\Windows\system32\fdrespub.dll" [MS]} HP CUE DeviceDiscovery Service, hpqddsvc, "C:\Windows\system32\svchost.exe -k hpdevmgmt" {"C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll" ["Hewlett-Packard Co."]} hpqcxs08, hpqcxs08, "C:\Windows\system32\svchost.exe -k hpdevmgmt" {"C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll" ["Hewlett-Packard Co."]} Human Interface Device Access, hidserv, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\system32\hidserv.dll" [MS]} IP Helper, iphlpsvc, "C:\Windows\System32\svchost.exe -k NetSvcs" {(missing data)} IPS Core Service, IPSSVC, "C:\Windows\system32\IPSSVC.EXE" ["Lenovo Group Limited"] IviRegMgr, IviRegMgr, "C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe" ["InterVideo"] My Web Search Service, MyWebSearchService, "C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe" ["MyWebSearch.com"] Network Store Interface Service, nsi, "C:\Windows\system32\svchost.exe -k LocalService" {(missing data)} On Screen Display, TPHKSVC, "C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe" [null data] Pml Driver HPZ12, Pml Driver HPZ12, "C:\Windows\System32\svchost.exe -k HPZ12" {"C:\Windows\system32\HPZipm12.dll" ["Hewlett-Packard"]} SAVRoam, SavRoam, ""C:\Program Files\Symantec AntiVirus\SavRoam.exe"" ["symantec"] Smart Card, SCardSvr, "C:\Windows\system32\svchost.exe -k LocalService" {"C:\Windows\System32\SCardSvr.dll" [MS]} Symantec AntiVirus, Symantec AntiVirus, ""C:\Program Files\Symantec AntiVirus\Rtvscan.exe"" ["Symantec Corporation"] Symantec AntiVirus Definition Watcher, DefWatch, ""C:\Program Files\Symantec AntiVirus\DefWatch.exe"" ["Symantec Corporation"] Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon" ["Symantec Corporation"] Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon" ["Symantec Corporation"] System Update, SUService, ""c:\Program Files\Lenovo\System Update\SUService.exe"" [null data] TCP/IP NetBIOS Helper, lmhosts, "C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted" {(missing data)} ThinkPad HDD APS Logging Service, TPHDEXLGSVC, "System32\TPHDEXLG.exe" ["Lenovo."] ThinkPad PM Service, IBMPMSVC, "C:\Windows\system32\ibmpmsvc.exe" ["Lenovo"] ThinkVantage Registry Monitor Service, ThinkVantage Registry Monitor Service, ""C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe"" ["Lenovo Group Limited"] TPM Base Services, TBS, "C:\Windows\System32\svchost.exe -k LocalService" {"C:\Windows\System32\tbssvc.dll" [MS]} TSS Core Service, TSSCoreService, ""C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe"" ["IBM"] TVT Backup Protection Service, TVT Backup Protection Service, ""C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe"" [null data] TVT Backup Service, TVT Backup Service, ""C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe"" ["Lenovo Group Limited"] TVT Scheduler, TVT Scheduler, ""c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe"" ["Lenovo Group Limited"] tvtnetwk, tvtnetwk, "C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe" [null data] UPnP Device Host, upnphost, "C:\Windows\system32\svchost.exe -k LocalService" {"C:\Windows\System32\upnphost.dll" [MS]} Windows Driver Foundation - User-mode Driver Framework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [MS]} Windows Event Log, Eventlog, "C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted" {(missing data)} Windows Image Acquisition (WIA), stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [MS]} Windows Media Player Network Sharing Service, WMPNetworkSvc, ""C:\Program Files\Windows Media Player\wmpnetwk.exe"" [MS] WLAN AutoConfig, Wlansvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\wlansvc.dll" [MS]} XAudioService, XAudioService, "C:\Windows\system32\DRIVERS\xaudio.exe" ["Conexant Systems, Inc."] Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monito rs\ FPP2:\Driver = "fppmon2.dll" ["FinePrint Software, LLC"] LIDIL hpzll4v2\Driver = "hpzll4v2.dll" ["Hewlett-Packard Company"] ---------- (launch time: 2007-09-23 00:05:20) <<!>>: Suspicious data at a malware launch point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points, use the -supp parameter or answer "No" at the first message box and "Yes" at the second message box. ---------- (total run time: 47 seconds, including 10 seconds for message boxes) |
|
#6
|
||||
|
||||
|
I'm not seeing any infection here so far, although I am not sure about one item. Do you recognize this as some Firefox addon you use? It would be a right click option you might see.
O8 - Extra context menu item: &Search - ?p=ZJfox000 MyWebSearch often comes pre-installed by the manufacturer sadly enough - a toned down version but still a search hijacker. Can't recall if IBM went that route as well. Let's see what all is here as installs. Open Hijackthis. Click Config - Misc Tools - Open Uninstall Manager. A list of the entries in Add/Remove programs will appear. Click on Save List... The list will be saved as 'Uninstall_list.txt' Copy & Paste the contents back here for review.
__________________
I'm pretty sure my Snark is a Boojum. Back To Nature If we have helped you, please consider supporting Cyber Tech Help with a subscription. |
|
#7
|
|||
|
|||
|
32 Bit HP CIO Components Installer
Access Help Activation Assistant for the 2007 Microsoft Office suites Adobe Flash Player Plugin Adobe Reader 8.1.0 Client Security Solution CSI-3 Dimensions of Murder 1.0 Diskeeper Home Drag-to-Disc Help Center HP Customer Participation Program 8.0 HP Deskjet All-In-One Software 8.0 HP Imaging Device Functions 8.0 HP Photosmart Essential HP Solution Center 8.0 HP Update HPSSupply Intel(R) PRO Network Connections Drivers InterVideo WinDVD Java(TM) SE Runtime Environment 6 Lenovo Registration Lenovo System Interface Driver LiveUpdate 3.2 (Symantec Corporation) Maintenance Manager Message Center Microsoft .NET Framework 1.1 Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional Plus 2007 Microsoft Office Professional Plus 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (2.0.0.7) Mozilla Thunderbird (2.0.0.6) MSXML 4.0 SP2 (KB936181) Multimedia Center For Think Offerings NVIDIA Drivers On Screen Display PC-Doctor 5 for Windows pdfFactory Pro Picasa 2 Presentation Director Productivity Center Supplement for ThinkPad Registry patch for Windows Vista USB S3 PM Enablement Registry patch of Changing Timing of IDLE IRP by Finger Print Driver for Windows Vista Registry Patch of Enabling Device Initiated Power Management(DIPM) on SATA for Windows Vista Rescue and Recovery RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Excel 2007 (KB936509) Security Update for Office 2007 (KB934062) Security Update for Office 2007 (KB936514) Security Update for Publisher 2007 (KB936646) Security Update for the 2007 Microsoft Office System (KB936960) Sonic Icons for Lenovo SoundMAX Spybot - Search & Destroy 1.4 Symantec AntiVirus System Migration Assistant System Update The Sims 2 The Sims 2 Glamour Life Stuff The Sims 2 Open For Business The Sims 2 Pets The Sims 2 University The Sims™ 2 Seasons ThinkPad Bluetooth with Enhanced Data Rate Software 6.0.1.4900 ThinkPad EasyEject Utility ThinkPad FullScreen Magnifier ThinkPad Mobility Center Customization ThinkPad Modem ThinkPad Power Management Driver ThinkPad Power Manager ThinkPad UltraNav Driver ThinkPad UltraNav Utility ThinkVantage Access Connections ThinkVantage Active Protection System ThinkVantage Productivity Center ThinkVantage Technologies Welcome Message Update for Office 2007 (KB932080) Update for Office 2007 (KB934391) Update for Office 2007 (KB934393) Update for Outlook 2007 (KB937608) Update for Outlook 2007 Junk Email Filter (kb937833) Update for Word 2007 (KB934173) Wallpapers Windows Driver Package - Intel (e1express) Net (02/27/2007 9.7.37.0) Windows Driver Package - Intel (iaStor) hdc (02/12/2007 7.0.0.1020) Windows Driver Package - Intel hdc (11/15/2006 8.2.0.1011) Windows Driver Package - Intel hdc (11/15/2006 8.2.0.1011) Windows Driver Package - Intel hdc (12/06/2006 6.8.0.3002) Windows Driver Package - Intel System (09/15/2006 7.0.0.1011) Windows Driver Package - Intel System (09/15/2006 8.0.0.1008) Windows Driver Package - Intel System (09/15/2006 8.0.0.1010) Windows Driver Package - Intel System (09/15/2006 8.2.0.1000) Windows Driver Package - Intel USB (09/15/2006 8.0.0.1008) Windows Driver Package - Lenovo (IBMPMDRV) System (05/31/2007 1.43) Windows Driver Package - Ricoh Company (rimsptsk) hdc (02/16/2007 6.00.01.10) Windows Driver Package - Ricoh Company MMC Host Controller (02/24/2007 6.00.02.03) Windows Driver Package - Ricoh Company xD Host Controller (03/21/2007 6.00.01.12) Windows Live Toolbar Windows Live Toolbar Windows Media Player Firefox Plugin WinRAR archiver WinSCP 3.8.2 X-Win32 7.1 |
|
#8
|
|||
|
|||
|
I don't recognize that extra content. The only search related things I've used on Firefox is the "Find in this Page" option reached by hitting Ctrl-F.
|
|
#9
|
||||
|
||||
|
I see the MyWebSearch service now when I looked back through the logs. Doesn't show as any installed software so possibly remains from the earlier manufacturer's install or snuck in with another third party software. As for the minor context menu item I don't recognize it either, but as this system has specialty software like WinSCP 3.8.2 and especially X-Win32 7.1 for networking to non-Windows systems it is best to leave that as likely normal use.
Would you believe that IAC Search and Media, the company that cranks out the MyWebSearch adware (and owns Ask.com, Ask Toolbar) actually posts claims that their software is being incorrectly targeted as bad? Go to Start > Run and type cmd and OK. Type (or copy/paste) the below commands and hit "Enter" after each line sc stop My Web Search Service sc delete My Web Search Service Type Exit to close. Then Go here and download the free version of SUPERAntiSpyware and install it. After installation accept any prompts to allow SUPERAntiSpyware to install the latest infection definition files. Next follow the prompts to complete the installation. For now, uncheck the option to have SUPERAntiSpyware "Automatically check for program and definition updates". Providing an email address and allowing the software to send diagnostic reports to it's research center are up to you. Do NOT allow SUPERAntiSpyware to Protect your Home Page settings. Once the installation is complete open SUPERAntiSpyware and press the Preferences button. Under the General and Startup tab, uncheck the following (leaving all other settings as is). Start-up Options: *Start SUPERAntiSpyware when Windows starts Automatic Updates: *Check for program updates when the application starts. Start-up Scanning: *Check for updates before scanning on startup. Then select Close. Don't scan just yet though. Also Go Here and download ATF cleaner. Click on the downloaded file to run it, and select "Select All", then click Empty Selected (and close ATF). If you have them, also click on Firefox/Opera at the top and repeat the steps (and close ATF). Firefox/Opera will need to be closed first for the cleaning to be effective. =============================================== Reboot into Safe Mode (at startup tap the F8 key and select Safe Mode). Open SUPERAntiSpyware and click the Scan your Computer button. Making sure that Fixed Drive (NTFS) is checked (typically the C Drive), check "Perform Complete Scan", then click Next. SUPERAntiSpyware will now complete a system scan. SUPERAntiSpyware will now scan your computer and when its finished it will list all the infections it has found. Make sure that they all have a check next to them and click next. If prompted allow the reboot (or manually reboot at this time), and after the reboot open SUPERAntiSpyware again (double click the bug-shaped Taskbar icon). Click Preferences, then under the Statistics/Logs tab, click to select the most recent Scan Log, then click View Log. Save the log to your desktop, and copy/paste the text from the log back here.
__________________
I'm pretty sure my Snark is a Boojum. Back To Nature If we have helped you, please consider supporting Cyber Tech Help with a subscription. |
|
#10
|
|||
|
|||
|
when I type 'sc delete My Web Service' I get:
[SC] OpenService FAILED 1060: The specified service does not exist as an installed service. |
|
#11
|
|||
|
|||
|
I did type the word 'Search' into the command line, I just missed it in the post above.
|
|
#12
|
||||
|
||||
|
Not real sure what that last post meant. Most important is you do this command line:
sc delete My Web Search Service The first may give you a negative response if the service is not running, but this second removes it either way. But go ahead with the other steps as posted too please.
__________________
I'm pretty sure my Snark is a Boojum. Back To Nature If we have helped you, please consider supporting Cyber Tech Help with a subscription. |
|
#13
|
|||
|
|||
|
That's the thing it was the command with delete in it that came up negative. It told me that My We Search Service does not exist as an installed service. The first one with stop it seemed to work though.
|
|
#14
|
||||
|
||||
|
Go ahead with the other steps then, and we'll check after.
__________________
I'm pretty sure my Snark is a Boojum. Back To Nature If we have helped you, please consider supporting Cyber Tech Help with a subscription. |
|
#15
|
|||
|
|||
|
During the ATF Cleaner is it necessary to delete Firefox Saved Passwords?
|



