Malwarebytes' Anti-Malware 1.34
Database version: 1828
Windows 5.1.2600 Service Pack 3
09/03/2009 11:15:56
mbam-log-2009-03-09 (11-15-56).txt
Scan type: Quick Scan
Objects scanned: 84122
Time elapsed: 13 minute(s), 40 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 1
Registry Keys Infected: 3
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
C:\WINDOWS\sysguard.exe (Trojan.Agent) -> Failed to unload process.
C:\WINDOWS\system32\drivers\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Failed to unload process.
Memory Modules Infected:
C:\WINDOWS\system32\iehelper.dll (Trojan.Vundo.H) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c9c42510-9b21-41c1-9dcd-8382a2d07c61} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c9c42510-9b21-41c1-9dcd-8382a2d07c61} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c9c42510-9b21-41c1-9dcd-8382a2d07c61} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\svcho (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system tool (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\iehelper.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\svcho.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\svchost.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\sysguard.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\Fonts\lydeke_handwrithing_normal.zip (Worm.Archive) -> Quarantined and deleted successfully.
————————————————————————————————————————————-
OTListIt logfile created on: 09/03/2009 11:34:14 - Run 1
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\IBM USER\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1022.92 Mb Total Physical Memory | 597.80 Mb Available Physical Memory | 58.44% Memory free
2.40 Gb Paging File | 2.10 Gb Available in Paging File | 87.55% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.06 Gb Total Space | 5.39 Gb Free Space | 15.81% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: IBM-A65B8BF3646
Current User Name: IBM USER
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\system32\ibmpmsvc.exe ()
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\System32\QCONSVC.EXE (IBM Corp.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\system32\TpKmpSVC.exe ()
PRC - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\tp4serv.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe ()
PRC - C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe ()
PRC - C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE (IBM Corp.)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE (IBM Corp.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\system32\TpScrLk.exe ()
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\USB Disk Win98 Driver\Res.EXE (ali)
PRC - C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
PRC - C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe ()
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\IBM\Messages By IBM\ibmmessages.exe (IBM)
PRC - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
PRC - C:\Program Files\DAEMON Tools\daemon.exe (DT Soft Ltd.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe (Nokia Corporation)
PRC - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe (Nokia.)
PRC - C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe (Nokia Mobile Phones Ltd.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\IBM USER\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (ACS [On_Demand | Stopped]) – C:\WINDOWS\system32\acs.exe ()
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DMService [On_Demand | Stopped]) – C:\WINDOWS\DOWNLO~1\DMService.exe ()
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IBMPMSVC [Auto | Running]) – C:\WINDOWS\system32\ibmpmsvc.exe ()
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Irmon [Auto | Running]) – C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (NetSvc [On_Demand | Stopped]) – C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Unknown | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (QCONSVC [Auto | Running]) – C:\WINDOWS\System32\QCONSVC.EXE (IBM Corp.)
SRV - (ServiceLayer [On_Demand | Running]) – C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe (Nokia.)
SRV - (SoundMAX Agent Service (default) [Auto | Running]) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (SymWSC [Auto | Running]) – c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
SRV - (TpKmpSVC [Auto | Running]) – C:\WINDOWS\system32\TpKmpSVC.exe ()
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ac97intc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (aeaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (AgereSoftModem [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (ANC [System | Running]) – C:\WINDOWS\System32\drivers\ANC.SYS (IBM Corp.)
DRV - (AR5211 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ar5211.sys (Atheros Communications, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (CmdIde [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (E1000 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\e1000325.sys (Intel Corporation)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (IBMPMDRV [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ibmpmdrv.sys (Lenovo.)
DRV - (IBMTPCHK [System | Running]) – C:\WINDOWS\System32\drivers\IBMBLDID.SYS ()
DRV - (ltmodem5 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (Nokia USB Generic [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdc.sys (Nokia)
DRV - (Nokia USB Modem [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdcm.sys (Nokia)
DRV - (Nokia USB Phone Parent [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcd.sys (Nokia)
DRV - (Nokia USB Port [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdcj.sys (Nokia)
DRV - (NSCIRDA [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\nscirda.sys (National Semiconductor Corporation)
DRV - (PMEM [Auto | Running]) – C:\WINDOWS\system32\drivers\PMEMNT.SYS (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (QCNDISIF [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\qcndisif.SYS (IBM Corporation.)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (QV2KUX [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\qv2kux.sys (Microsoft Corporation)
DRV - (S3SSavage [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\s3ssavm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Smapint [System | Running]) – C:\WINDOWS\System32\drivers\Smapint.sys (Microsoft Corporation)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (TDSMAPI [System | Running]) – C:\WINDOWS\System32\drivers\TDSMAPI.SYS ()
DRV - (Tp4Track [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\tp4track.sys (Lenovo Group Limited)
DRV - (TPHKDRV [System | Running]) – C:\WINDOWS\System32\drivers\TPHKDRV.sys (IBM Corporation)
DRV - (TPPWR [System | Running]) – C:\WINDOWS\System32\drivers\Tppwr.sys (IBM Corp.)
DRV - (TSMAPIP [System | Running]) – C:\WINDOWS\System32\drivers\TSMAPIP.SYS ()
DRV - (TwoTrack [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\TwoTrack.sys (IBM Corporation)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/ig?hl=en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {27c60876-b5c9-4335-b4f3-52b26782220c}:0.8.5
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6
FF - HKLM\software\mozilla\Firefox\extensions\\[removed] -> %ProgramFiles%\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2008/12/08 10:30:40 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/02/18 14:55:00 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.6\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/02/18 14:55:00 00,000,000 | —D | M]
FF - C:\Documents and Settings\IBM USER\Application Data\mozilla\Extensions [2008/12/10 13:04:32 00,000,000 | —D | M]
FF - C:\Documents and Settings\IBM USER\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/12/10 13:04:32 00,000,000 | —D | M]
FF - C:\Documents and Settings\IBM USER\Application Data\mozilla\Firefox\Profiles\jpjpwmy2.default\extensions [2009/03/09 10:43:15 00,000,000 | —D | M]
FF - C:\Documents and Settings\IBM USER\Application Data\mozilla\Firefox\Profiles\jpjpwmy2.default\extensions\{27c60876-b5c9-4335-b4f3-52b26782220c} [2009/02/08 19:38:31 00,000,000 | —D | M]
FF - C:\Documents and Settings\IBM USER\Application Data\mozilla\Firefox\Profiles\jpjpwmy2.default\extensions\[removed] [2009/02/23 11:14:45 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions [2008/12/10 13:03:27 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/02/18 14:55:00 00,000,000 | —D | M]
O1 HOSTS File: (73 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google; Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" (ATI Technologies, Inc.)
O4 - HKLM..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog ()
O4 - HKLM..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor (IBM Corp.)
O4 - HKLM..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE ()
O4 - HKLM..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor ()
O4 - HKLM..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe (Lenovo Group Limited)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup ()
O4 - HKLM..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [QCTray] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE (IBM Corp.)
O4 - HKLM..\Run: [QCWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE (IBM Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [S3TRAY2] S3Tray2.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe (Symantec Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TP4EX] tp4ex.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe ()
O4 - HKLM..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe ()
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper (Lenovo)
O4 - HKLM..\Run: [TrackPointSrv] tp4serv.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe ()
O4 - HKLM..\Run: [USB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE (ali)
O4 - HKCU..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 (DT Soft Ltd.)
O4 - HKCU..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKCU..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (Time Information Services Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = -1
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\ThinkPad\PkgMgr\PkgMgr.exe (Lenovo Group Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://www.truprint.co.uk/TruprintActivia.cab (Snapfish Activia)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1161910835210 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A}
https://portal.christianaid.org.uk/Internal…/WhlCompMgr.cab (Whale Client Components)
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/1.4.1/…all-141-win.cab (Java Plug-in 1.4.1 redirector)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003}
http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx (Persits Software XUpload)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{954116AF-8A98-4BF6-96B5-D4F3D5B03FD9}\\NameServer = 192.168.1.254,192.168.1.255
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\tpfnf2: DllName - notifyf2.dll - C:\WINDOWS\system32\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - tphklock.dll - C:\WINDOWS\system32\tphklock.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{821a6891-6531-11db-b26d-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{821a6891-6531-11db-b26d-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{821a6891-6531-11db-b26d-806d6172696f}\Shell\AutoRun\command - "" = D:\setup.exe – File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/03/09 11:31:58 | 00,497,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\IBM USER\Desktop\OTListIt2.exe
[2009/03/09 10:56:06 | 00,033,280 | —- | C] () – C:\WINDOWS\syssvc.exe
[2009/03/06 18:40:45 | 00,848,896 | —- | C] () – C:\Documents and Settings\IBM USER\Desktop\annual report.doc
[2009/03/06 18:24:16 | 00,000,000 | —D | C] – C:\Program Files\pdfsam
[2009/03/06 09:41:26 | 00,940,190 | —- | C] () – C:\Documents and Settings\IBM USER\Desktop\Poster.jpg
[2009/03/04 19:27:40 | 01,593,749 | —- | C] () – C:\Documents and Settings\IBM USER\Desktop\EECore1.6.7.zip
[2009/03/04 18:59:19 | 00,359,811 | —- | C] () – C:\Documents and Settings\IBM USER\Desktop\__THEDOORDB__.sql
[2009/02/28 14:51:14 | 62,558,566 | —- | C] () – C:\Documents and Settings\IBM USER\Desktop\PUSH The Door Appeal launch feat. Martin_0002.wmv
[2009/02/28 08:59:48 | 00,000,000 | —D | C] – C:\Documents and Settings\IBM USER\Application Data\FileZilla
[2009/02/28 08:59:36 | 00,000,000 | —D | C] – C:\Program Files\FileZilla FTP Client
[2009/02/24 14:13:10 | 00,000,000 | —D | C] – C:\Documents and Settings\IBM USER\Application Data\InterVideo
[2009/02/24 12:40:52 | 00,000,000 | —D | C] – C:\Documents and Settings\IBM USER\Desktop\EECore1.6.7
[2009/02/11 12:31:41 | 00,000,000 | —D | C] – C:\Documents and Settings\IBM USER\Desktop\The Door
[2009/02/10 12:09:00 | 00,001,819 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2009/02/10 11:50:24 | 00,000,104 | —- | C] () – C:\WINDOWS\IBMVPD.INI
[2009/02/10 11:50:23 | 00,090,112 | —- | C] () – C:\WINDOWS\System32\vpd.exe
[2009/02/10 11:50:23 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\instdrvw.exe
[2009/02/10 11:50:23 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\pmemw.dll
[2009/02/10 11:50:23 | 00,007,012 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\pmemnt.sys
[2009/02/09 16:05:42 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/02/09 15:55:17 | 00,000,000 | —D | C] – C:\Documents and Settings\IBM USER\Application Data\Malwarebytes
[2009/02/09 15:55:14 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/09 15:55:11 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/09 15:55:10 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/09 15:55:10 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/09 11:14:27 | 00,000,000 | —D | C] – C:\WINDOWS\pss
[2009/02/09 10:54:02 | 00,001,745 | —- | C] () – C:\Documents and Settings\IBM USER\Desktop\HijackThis.lnk
[2009/02/09 10:54:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/09 10:01:41 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/02/09 09:31:26 | 00,000,000 | —D | C] – C:\fixwareout
[2009/02/08 21:22:36 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/02/08 20:37:49 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/02/08 20:34:58 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/02/08 20:34:56 | 00,000,878 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/02/08 20:34:45 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/02/08 20:34:45 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/02/08 19:47:15 | 34,543,112 | —- | C] (Lavasoft ) – C:\Documents and Settings\IBM USER\Desktop\Ad-AwareAE.exe
========== Files - Modified Within 30 Days ==========
[1 C:\*.tmp files]
[4 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/03/09 11:32:01 | 00,497,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\IBM USER\Desktop\OTListIt2.exe
[2009/03/09 11:19:06 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/09 11:18:26 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/09 11:18:23 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/09 11:18:20 | 10,726,80960 | -HS- | M] () – C:\hiberfil.sys
[2009/03/09 10:56:07 | 00,033,280 | —- | M] () – C:\WINDOWS\syssvc.exe
[2009/03/09 10:15:34 | 00,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{DF64C85C-546F-44AE-9B23-F2875941F2D0}.job
[2009/03/06 18:43:52 | 00,848,896 | —- | M] () – C:\Documents and Settings\IBM USER\Desktop\annual report.doc
[2009/03/06 18:29:14 | 00,044,032 | -HS- | M] () – C:\Documents and Settings\IBM USER\Desktop\Thumbs.db
[2009/03/06 09:41:41 | 00,940,190 | —- | M] () – C:\Documents and Settings\IBM USER\Desktop\Poster.jpg
[2009/03/05 18:24:37 | 00,084,992 | —- | M] () – C:\Documents and Settings\IBM USER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/04 19:28:01 | 01,593,749 | —- | M] () – C:\Documents and Settings\IBM USER\Desktop\EECore1.6.7.zip
[2009/03/04 18:59:21 | 00,359,811 | —- | M] () – C:\Documents and Settings\IBM USER\Desktop\__THEDOORDB__.sql
[2009/03/02 20:43:49 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/02/24 08:25:51 | 01,557,664 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/12 03:01:59 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/10 12:08:55 | 00,000,613 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/10 12:08:55 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/02/10 12:08:55 | 00,000,194 | RHS- | M] () – C:\BOOT.INI
[2009/02/10 11:50:29 | 00,000,104 | —- | M] () – C:\WINDOWS\IBMVPD.INI
[2009/02/10 09:32:15 | 00,049,152 | —- | M] () – C:\Documents and Settings\IBM USER\My Documents\Outlookwww.yahoo.co.ukmail-00000002.pst
[2009/02/09 10:54:02 | 00,001,745 | —- | M] () – C:\Documents and Settings\IBM USER\Desktop\HijackThis.lnk
[2009/02/08 20:34:56 | 00,000,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/02/08 20:28:11 | 34,543,112 | —- | M] (Lavasoft ) – C:\Documents and Settings\IBM USER\Desktop\Ad-AwareAE.exe
========== LOP Check ==========
[2009/02/09 15:55:10 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/02/08 20:34:58 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2008/12/13 16:49:08 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{EA6AF74E-BDCD-4FE5-BAB2-F6BF858C5B6A}
[2009/01/27 15:09:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AceBIT
[2008/12/05 09:33:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/04/25 07:55:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/12/13 16:58:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Axure
[2007/05/31 17:17:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2007/06/07 09:54:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2008/07/16 11:18:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/09/02 18:24:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2008/02/03 18:08:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2007/05/17 08:41:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2006/10/26 20:20:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ibm
[2009/02/08 20:37:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/02/09 15:55:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/04/18 07:33:00 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/06/07 09:58:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2003/02/20 16:33:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2006/10/27 17:02:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2006/10/27 01:34:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/02/24 14:13:10 | 00,000,000 | RH-D | M] – C:\Documents and Settings\IBM USER\Application Data
[2009/01/27 15:09:03 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\AceBIT
[2009/03/05 09:42:38 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Adobe
[2007/04/25 07:56:13 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Apple Computer
[2008/12/13 16:58:29 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Axure
[2007/11/16 12:35:23 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Canon
[2007/06/07 23:14:40 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Datalayer
[2007/09/06 13:32:37 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\EditPlus 2
[2009/03/06 19:02:41 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\FileZilla
[2008/09/03 11:26:36 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Google
[2007/04/19 12:17:34 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Help
[2007/05/17 08:45:22 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\HP
[2007/08/31 10:27:16 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\IBM
[2003/02/20 16:20:50 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Identities
[2007/04/14 19:33:50 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\InterTrust
[2009/02/24 14:13:10 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\InterVideo
[2007/04/14 11:49:10 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Macromedia
[2009/02/09 15:55:17 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Malwarebytes
[2008/10/22 11:52:19 | 00,000,000 | –SD | M] – C:\Documents and Settings\IBM USER\Application Data\Microsoft
[2008/12/10 13:04:32 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Mozilla
[2007/06/07 23:14:39 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Nokia
[2007/06/15 09:45:36 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Nokia Multimedia Player
[2007/06/07 23:16:07 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\PC Suite
[2007/06/22 15:22:23 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Snapfish
[2008/06/18 16:45:21 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Sun
[2006/10/26 20:22:26 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\Symantec
[2008/12/02 16:35:02 | 00,000,000 | —D | M] – C:\Documents and Settings\IBM USER\Application Data\WinRAR
[2009/03/02 20:43:49 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2007/08/06 07:34:20 | 00,000,448 | —- | M] () – C:\WINDOWS\Tasks\BMMTask.job
[2001/08/18 09:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/09 11:18:26 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2006/10/26 20:23:14 | 00,000,428 | —- | M] () – C:\WINDOWS\Tasks\Symantec NetDetect.job
[2009/03/09 10:15:34 | 00,000,428 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{DF64C85C-546F-44AE-9B23-F2875941F2D0}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\IBM USER\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\IBM USER\Desktop\Thumbs.db:encryptable
< End of report >
————————————————————————————————————————————————————
OTListIt Extras logfile created on: 09/03/2009 11:34:14 - Run 1
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\IBM USER\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1022.92 Mb Total Physical Memory | 597.80 Mb Available Physical Memory | 58.44% Memory free
2.40 Gb Paging File | 2.10 Gb Available in Paging File | 87.55% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.06 Gb Total Space | 5.39 Gb Free Space | 15.81% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: IBM-A65B8BF3646
Current User Name: IBM USER
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\IBMTOOLS\Updater\ucsmb.exe:*:enabled:IBM Update Connector (IBM Corporation, Inc.)
C:\IBMTOOLS\Updater\jre\bin\java.exe:*:enabled:IBM Update Connector (IBM)
C:\IBMTOOLS\Updater\jre\bin\javaw.exe:*:enabled:IBM Update Connector (IBM)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\IBMTOOLS\Updater\ucsmb.exe:*:enabled:IBM Update Connector (IBM Corporation, Inc.)
C:\IBMTOOLS\Updater\jre\bin\java.exe:*:enabled:IBM Update Connector (IBM)
C:\IBMTOOLS\Updater\jre\bin\javaw.exe:*:enabled:IBM Update Connector (IBM)
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Computer, Inc.)
C:\Program Files\Java\jre6\bin\java.exe:*:Disabled:Java™ Platform SE binary (Sun Microsystems, Inc.)
C:\WINDOWS\system32\drivers\svchost.exe:*:Disabled:Wtypysor Ufuguty File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08094E03-AFE4-4853-9D31-6D0743DF5328}" = QuickTime
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0D80391C-0A72-43BB-9BC2-143F63CC111D}" = Nokia PC Connectivity Solution
"{1297C681-92D7-40EF-93BF-03F66EC5105C}" = ThinkPad EasyEject Utility
"{1526D87C-A955-4FAB-BF18-697BA457E352}" = Norton WMI Update
"{16906D21-0656-4F8B-9A01-C3D24B5401FC}" = Intel® PROSet for Wired Connections
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18A5DFF2-8A95-49F3-873F-743CB5549F3D}" = Canon ScanGear Starter
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{20749F76-4228-43AD-8AB5-E7B20D8040C4}" = hph_readme
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = ThinkPad Keyboard Customizer Utility
"{22B71A00-4DED-11D4-A5E5-0004AC564F43}" = IBM Access Connections
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{31C2FBAC-67CF-4093-8F36-15A146613747}" = IBM Update Connector
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36DC3E2F-CD8C-4953-9E8F-9A1916D10AA1}" = hph_software
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3E2F3C90-0EAF-4CF5-87E8-B1CC1C183020}" = Axure RP Pro 5
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{4E79A62F-7A2D-4058-BCE0-94E6B9E2F162}" = USB Disk Win98 Driver
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{531317A5-586A-4E36-87C1-CA823447B375}" = Nokia PC Suite
"{531BC138-F1F7-496B-879C-F039ECEF438D}" = Adobe Photoshop Lightroom 2
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5CCABD37-479D-4304-B1A5-67952C25F8F2}" = Nokia Software Launcher
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6882DD11-33B8-4DEA-8305-7E765BF74BD3}" = Nokia Connectivity Cable Driver
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6C72E14A-C1F3-45E5-8810-83CE3C19ED63}" = IBM 32-bit SDK for Java 2, v1.4.1
"{6CE96A14-61E2-48CC-837E-22710A953ADE}" = IBM Themes
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{710C0BB2-FE39-484E-BB23-C9B96835A14A}" = Access IBM Message Center
"{75C22B40-6D12-4439-80DC-CAB3313EADA5}" = dj_sf_software_req
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{868F24EB-5CA7-4285-B39B-3617CF37462A}" = D2300_Help
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9FAC9E5C-0D20-4DBF-AFE5-2E09C52A95A2}" = ThinkPad Wireless LAN Adapters Software (11a/b, 11b/g, 11a/b/g)
"{A260B422-70E1-41E2-957D-F76FA21266D5}" = Apple Software Update
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB90749C-7422-4580-8A7A-66CC5E9E5F98}" = iTunes
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{ACCCEE83-B49B-4964-8A4F-378B8FBC9F75}" = hph_ProductContext
"{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B5599ECB-DA72-43EE-8A30-2C80396FF8BB}" = Access IBM
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C45EB9E5-7165-4FB0-8C31-77FC4743362F}" = Manual CanoScan LiDE 25
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}" = Canon CanoScan Toolbox 4.9
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CF44C7A5-5705-41E4-BE84-A9A42977AB05}" = Access IBM Cleanup Utility
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5}" = Software Installer
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D297A783-A680-4FDB-8882-913EBA36ABC5}" = D2300
"{D2A3C9D5-0B56-4656-8277-7EDC65D62B6E}" = HP Photosmart and Deskjet 7.0 Software
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E0C18BB0-32CA-4679-B422-9B9FA825378F}" = HP Deskjet Printer Driver Software 9.0
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{EA664480-3844-11D5-8C25-444553540000}" = TrackPoint Accessibility Features
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F386C340-DF4B-4BBA-9503-420FB7EDB395}" = Wallpapers
"{FC081D4D-DF1B-4CF1-B530-027E4118D846}" = ThinkPad Configuration
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"3271E907F27C989F2C244ACB3D32020E3DD3CA6F" = Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)
"Access IBM Tools" = Access IBM Tools
"Ad-Aware" = Ad-Aware
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"AdobeESD" = Adobe Download Manager 2.2 (Remove Only)
"Agere Systems Soft Modem" = Agere Systems AC'97 Modem
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"Axure RP Pro 5" = Axure RP Pro 5
"BOB Books_is1" = BOB Books Version 1.4.9.3
"Bonusprint Photoservice_is1" = Bonusprint Photoservice
"Budget Yourselves_is1" = Budget Yourselves V2
"Data Access Objects (DAO)" = Data Access Objects (DAO) 3.0
"DVDx_is1" = DVDx
"Easy Cross" = E
"EditPlus 2" = EditPlus 2
"FileZilla Client" = FileZilla Client 3.2.0
"HijackThis" = HijackThis 2.0.2
"Hijackthis_is1" = Hijackthis 1.99.1
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{6C72E14A-C1F3-45E5-8810-83CE3C19ED63}" = IBM 32-bit SDK for Java 2, v1.4.1
"LiveUpdate" = LiveUpdate 1.90 (Symantec Corporation)
"Macromedia Dreamweaver 3" = Macromedia Dreamweaver 3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.6)" = Mozilla Firefox (3.0.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia Map Loader" = Nokia Map Loader
"Power Features" = IBM ThinkPad Battery MaxiMiser and Power Management Features
"Power Management Driver" = ThinkPad Power Management Driver
"Presentation Director" = ThinkPad Presentation Director
"PROSet" = Intel® PRO Network Adapters and Drivers
"Shockwave" = Shockwave
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"TPKBDLED" = Scroll Lock Indicator Utility
"TrackPoint" = ThinkPad TrackPoint Driver
"Whale Communications' Client Components 3.1.0" = Whale Communications' Client Components v3.7.1
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinHTTrack Website Copier_is1" = WinHTTrack Website Copier 3.41-3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Colorworld StudioPartner" = Colorworld StudioPartner
"pdfsam" = pdfsam
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 28/02/2009 04:52:27 | Computer Name = IBM-A65B8BF3646 | Source = Adobe Version Cue CS3 | ID = 3
Description =
Error - 28/02/2009 04:52:27 | Computer Name = IBM-A65B8BF3646 | Source = Adobe Version Cue CS3 | ID = 3
Description =
Error - 28/02/2009 04:52:27 | Computer Name = IBM-A65B8BF3646 | Source = Adobe Version Cue CS3 | ID = 3
Description =
Error - 28/02/2009 04:52:27 | Computer Name = IBM-A65B8BF3646 | Source = Adobe Version Cue CS3 | ID = 3
Description =
Error - 28/02/2009 04:52:27 | Computer Name = IBM-A65B8BF3646 | Source = Adobe Version Cue CS3 | ID = 3
Description =
Error - 28/02/2009 04:52:27 | Computer Name = IBM-A65B8BF3646 | Source = Adobe Version Cue CS3 | ID = 3
Description =
Error - 28/02/2009 04:52:27 | Computer Name = IBM-A65B8BF3646 | Source = Adobe Version Cue CS3 | ID = 3
Description =
Error - 28/02/2009 04:52:27 | Computer Name = IBM-A65B8BF3646 | Source = Adobe Version Cue CS3 | ID = 3
Description =
Error - 28/02/2009 04:52:27 | Computer Name = IBM-A65B8BF3646 | Source = Adobe Version Cue CS3 | ID = 3
Description =
Error - 28/02/2009 04:52:27 | Computer Name = IBM-A65B8BF3646 | Source = Adobe Version Cue CS3 | ID = 3
Description =
[ System Events ]
Error - 05/03/2009 03:44:02 | Computer Name = IBM-A65B8BF3646 | Source = Service Control Manager | ID = 7000
Description = The Start2Driver service failed to start due to the following error:
%%2
Error - 05/03/2009 03:44:02 | Computer Name = IBM-A65B8BF3646 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Start1Driver
Error - 06/03/2009 12:14:35 | Computer Name = IBM-A65B8BF3646 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the WZCSVC service.
Error - 07/03/2009 05:42:04 | Computer Name = IBM-A65B8BF3646 | Source = Service Control Manager | ID = 7000
Description = The Start2Driver service failed to start due to the following error:
%%2
Error - 07/03/2009 05:42:04 | Computer Name = IBM-A65B8BF3646 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Start1Driver
Error - 07/03/2009 12:22:14 | Computer Name = IBM-A65B8BF3646 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the JavaQuickStarterService service.
Error - 09/03/2009 06:11:29 | Computer Name = IBM-A65B8BF3646 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.2 for the Network Card with network
address 00054E4757BE has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).
Error - 09/03/2009 07:18:28 | Computer Name = IBM-A65B8BF3646 | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.
Error - 09/03/2009 07:18:29 | Computer Name = IBM-A65B8BF3646 | Source = Service Control Manager | ID = 7000
Description = The Start2Driver service failed to start due to the following error:
%%2
Error - 09/03/2009 07:18:30 | Computer Name = IBM-A65B8BF3646 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Start1Driver
< End of report >
———————————————————————————————–
I was unable to do the run > cmd thing. when I typed in cmd I got the following error message:
The instruction at "Oc73dd11c7" referenced memory at "0x00000004". The memory could not be "read". Click OK to terminate program.
Also unable to restart router at this time as other people are using it. Could maybe do this later this afternoon.
The MBAM scan through up some files, which, when deleted seems to have solved the new "Spyware Protect 2009" problem. However original problem of search redirects to "couponmountain" and other such sites remains….
