This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google redirect, cannot run in safe mode

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Experts,

I've getting the very annoying redirections when I click on a result in a Google (or Bing) search. I've also noticed that when I attempt to startup in Safe Mode, the computer won't boot. As well as this, running GMER eventually ends in a blue screen, after about 4 hours - I've tried it twice, with McAfee disabled. Any help would be very appreciated!!

Here is my MBAM log:

Malwarebytes' Anti-Malware 1.42
Database version: 3413
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

7/01/2010 11:27:16 AM
mbam-log-2010-01-07 (11-27-16).txt

Scan type: Quick Scan
Objects scanned: 186583
Time elapsed: 24 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


================================================================================
=================

And the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:07:53 AM, on 8/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ngvpnmgr.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\VMware\VMware Player\hqtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Apps\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
D:\Apps\Easy Accounting\Reminder.exe
C:\Program Files\HyperSnap 6\HprSnap6.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Apps\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\Apps\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\SLM\bin\SlmServer.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Kodak\printer\center\KodakSvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Apps\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe
C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\StacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\TEXTPA~1\TextPad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row-rel&channel=au&ibd=1080123
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.co.uk/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.co.uk/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row-rel&channel=au&ibd=1080123
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.co.uk/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=y9…yPC1HjmV4RKTXTo
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = epaulette:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: ChromeFrame BHO - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome Frame\Application\4.0.266.0\npchrome_tab.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\VMware Player\hqtray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O4 - Startup: Easy Accounting Reminder Utility.LNK = D:\Apps\Easy Accounting\Reminder.exe
O4 - Startup: HyperSnap 6.lnk = C:\Program Files\HyperSnap 6\HprSnap6.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Apps\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware player\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware player\vsocklib.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {205E7068-6D03-4566-AD06-A146B592FBA5} (Loader Class v2) - http://spottail.bbs.bunnings.com.au/qcbin/Spider80.ocx
O16 - DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} (STCWeb Control) - https://vpn-emea1.infor.com/CACHE/webvpn/st…ries/stcweb.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1202778825280
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1238539192156
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://infor.webex.com/client/T26L10NSP49E…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = infor.com
O17 - HKLM\Software\..\Telephony: DomainName = infor.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = infor.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = infor.com
O18 - Protocol hijack: cf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E}
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
O23 - Service: Apache2 - Apache Software Foundation - C:\Apps\Apache Group\Apache2\bin\Apache.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: Infor Solution License Server (BCLMD) - Infor Global Solutions Technology GmbH - C:\Program Files\SLM\bin\SlmServer.exe
O23 - Service: BEA WebLogic Platform 8.1 NodeManager - BEA Systems, Inc. - C:\Apps\bea\WEBLOG~1\server\bin\beasvc.exe
O23 - Service: beasvc wbdomain_wbserver - BEA Systems, Inc. - C:\Apps\bea\WEBLOG~1\server\bin\beasvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Cognos ReportNet - Cognos Incorporated - C:\Apps\cognos\crn\bin\cogbootstrapservice.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files\Kodak\printer\center\KodakSvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - McAfee, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: MotoConnect Service - Unknown owner - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
O23 - Service: Aventail VPN Client (NgVpnMgr) - Aventail Corporation - C:\WINDOWS\system32\ngvpnmgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OracleOraDb10g_home1iSQL*Plus - Oracle - C:\Apps\oracle\product\10.2.0\db_1\bin\isqlplussvc.exe
O23 - Service: OracleOraDb10g_home1TNSListener - Unknown owner - C:\Apps\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe
O23 - Service: OracleServiceWB50 - Oracle Corporation - c:\apps\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
O23 - Service: OracleServiceWBCRN - Oracle Corporation - c:\apps\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
O23 - Service: WebSphere Embedded Messaging Publish And SubscribeWAS_AuMEngmrbt1s_server1 (WebSphereEmbeddedMessagingPublishAndSubscribeWAS_AuMEngmrbt1s_server1) - Unknown owner - C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe (file missing)
O23 - Service: WebSphere Embedded Messaging Publish And SubscribeWAS_AuMEngmrbt1s_WB50 (WebSphereEmbeddedMessagingPublishAndSubscribeWAS_AuMEngmrbt1s_WB50) - Unknown owner - C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe (file missing)
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 21187 bytes


================================================================================
==============

And here's the DDS log (Attach.zip is attached):


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 10:52:41.48 on Thu 07/01/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.1500 [GMT 11:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\ngvpnmgr.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Apps\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\Program Files\SLM\bin\SlmServer.exe
C:\Apps\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Kodak\printer\center\KodakSvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Apps\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe
C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\VMware\VMware Player\hqtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Apps\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
D:\Apps\Easy Accounting\Reminder.exe
C:\Program Files\HyperSnap 6\HprSnap6.exe
C:\WINDOWS\system32\StacSV.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
c:\progra~1\common~1\instal~1\update~1\isuspm.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\WINDOWS\system32\mdm.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Network Associates\VirusScan\SCAN32.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\WINDOWS\explorer.exe
C:\Documents and Settings\dfoster3\My Documents\Utilities\SpyWare Removal\dds.pif
C:\WINDOWS\system32\SearchProtocolHost.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com.au/
uSearch Page = hxxp://www.google.co.uk
uDefault_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row-rel&channel=au&ibd=1080123
uSearch Bar = hxxp://www.google.co.uk/ie
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=y9-u2tVYuezSyPC1HjmV4RKTXTo
uInternet Settings,ProxyServer = epaulette:8080
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.co.uk/keyword/%s
mSearchAssistant = hxxp://www.google.co.uk/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome frame\application\4.0.266.0\npchrome_tab.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
EB: &Research: {ff059e31-cc5a-4e2e-bf3b-96e929d65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [WavXMgr] c:\program files\wave systems corp\services manager\docmgr\bin\WavXDocMgr.exe
mRun: [SecureUpgrade] c:\program files\wave systems corp\SecureUpgrade.exe
mRun: [KADxMain] c:\windows\system32\KADxMain.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ShStatEXE] "c:\program files\network associates\virusscan\SHSTAT.EXE" /STANDALONE
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [FinePrint Dispatcher v5] "c:\windows\system32\spool\drivers\w32x86\3\fpdisp5a.exe" /source=HKLM
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [CoolSwitch] c:\windows\system32\taskswitch.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey
mRun: [VMware hqtray] "c:\program files\vmware\vmware player\hqtray.exe"
dRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 6\PcSync2.exe" /NoDialog
StartupFolder: c:\docume~1\dfoster3\startm~1\programs\startup\easyac~1.lnk - d:\apps\easy accounting\Reminder.exe
StartupFolder: c:\docume~1\dfoster3\startm~1\programs\startup\hypers~2.lnk - c:\program files\hypersnap 6\HprSnap6.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\toshiba\bluetooth toshiba stack\TosBtMng.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\monito~1.lnk - c:\apps\apache group\apache2\bin\ApacheMonitor.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\windows\system32\msjava.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\program files\vmware\vmware player\vsocklib.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab
DPF: {205E7068-6D03-4566-AD06-A146B592FBA5} - hxxp://spottail.bbs.bunnings.com.au/qcbin/Spider80.ocx
DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} - hxxps://vpn-emea1.infor.com/CACHE/webvpn/stc/1/binaries/stcweb.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1202778825280
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238539192156
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-1_3_1_09-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://infor.webex.com/client/T26L10NSP49EP5/webex/ieatgpc.cab
Handler: cf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome frame\application\4.0.266.0\npchrome_tab.dll
Handler: qrev - {9DE24BAC-FC3C-42c4-9FC4-76B3FAFDBD90} - c:\apps\toad\RNetPin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: ckpNotify - ckpNotify.dll
Notify: gemsafe - c:\program files\gemplus\gemsafe libraries\bin\WLEventNotify.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Authentication Packages = msv1_0 wvauth
Hosts: 10.10.10.10 localhost

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\dfoster3\applic~1\mozilla\firefox\profiles\zmyuxxcz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/
FF - component: c:\apps\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\apps\mozilla firefox\plugins\NPJava11.dll
FF - plugin: c:\apps\mozilla firefox\plugins\NPJava12.dll
FF - plugin: c:\apps\mozilla firefox\plugins\NPJava131_09.dll
FF - plugin: c:\apps\mozilla firefox\plugins\NPJava32.dll
FF - plugin: c:\apps\mozilla firefox\plugins\npoji600.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\j2re1.4.2_07\bin\NPJava11.dll
FF - plugin: c:\program files\java\j2re1.4.2_07\bin\NPJava12.dll
FF - plugin: c:\program files\java\j2re1.4.2_07\bin\NPJava13.dll
FF - plugin: c:\program files\java\j2re1.4.2_07\bin\NPJava14.dll
FF - plugin: c:\program files\java\j2re1.4.2_07\bin\NPJava32.dll
FF - plugin: c:\program files\java\j2re1.4.2_07\bin\NPJPI142_07.dll
FF - plugin: c:\program files\java\j2re1.4.2_07\bin\NPOJI610.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
c:\apps\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-12-18 207792]
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2008-2-12 59904]
R2 afpa;afpa;c:\windows\system32\drivers\afpa.sys [2008-3-31 106224]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2006-12-19 79432]
R2 BCLMD;Infor Solution License Server;c:\program files\slm\bin\SlmServer.exe [2009-7-7 475136]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2009-12-18 112592]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-11-9 54752]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\printer\center\KodakSvc.exe [2007-12-13 18944]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2009-9-25 120128]
R2 McShield;Network Associates McShield;c:\program files\network associates\virusscan\mcshield.exe [2007-11-26 221191]
R2 McTaskManager;Network Associates Task Manager;c:\program files\network associates\virusscan\vstskmgr.exe [2007-11-26 29184]
R2 MotoConnect Service;MotoConnect Service;c:\program files\motorola\motoconnectservice\MotoConnectService.exe [2009-8-20 91392]
R2 NgVpnMgr;Aventail VPN Client;c:\windows\system32\ngvpnmgr.exe [2009-1-19 223333]
R2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener;c:\apps\oracle\product\10.2.0\db_1\bin\tnslsnr –> c:\apps\oracle\product\10.2.0\db_1\bin\TNSLSNR [?]
R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2009-3-26 54960]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [2004-8-4 5120]
R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [2006-11-2 97536]
R3 NaiAvFilter1;NaiAvFilter1;c:\windows\system32\drivers\naiavf5x.sys [2008-2-12 117024]
R3 NgLog;Aventail VPN Logging;c:\windows\system32\drivers\nglog.sys [2009-1-19 25240]
R3 NgVpn;Aventail VPN Adapter;c:\windows\system32\drivers\ngvpn.sys [2009-1-19 77976]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-27 135664]
S3 BEA WebLogic Platform 8.1 NodeManager;BEA WebLogic Platform 8.1 NodeManager;c:\apps\bea\weblog~1\server\bin\beasvc.exe [2008-2-25 90112]
S3 beasvc wbdomain_wbserver;beasvc wbdomain_wbserver;c:\apps\bea\weblog~1\server\bin\beasvc.exe [2008-2-25 90112]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\drivers\CSVirtA.sys [2008-3-27 22136]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-1-23 29744]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2009-8-20 19712]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2009-8-20 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2009-8-20 42752]
S3 NgFilter;Aventail VPN Filter;c:\windows\system32\drivers\ngfilter.sys [2009-1-19 20632]
S3 NgWfp;Aventail VPN Callout;c:\windows\system32\drivers\ngwfp.sys [2009-1-19 23192]
S3 OracleServiceWB50;OracleServiceWB50;c:\apps\oracle\product\10.2.0\db_1\bin\oracle.exe wb50 –> c:\apps\oracle\product\10.2.0\db_1\bin\ORACLE.EXE WB50 [?]
S3 OracleServiceWBCRN;OracleServiceWBCRN;c:\apps\oracle\product\10.2.0\db_1\bin\oracle.exe wbcrn –> c:\apps\oracle\product\10.2.0\db_1\bin\ORACLE.EXE WBCRN [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-12-18 359624]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-12-18 1141712]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2008-2-13 280344]
S3 WebSphereEmbeddedMessagingPublishAndSubscribeWAS_AuMEngmrbt1s_server1;WebSphere Embedded Messaging Publish And SubscribeWAS_AuMEngmrbt1s_server1;C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe –> C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe [?]
S3 WebSphereEmbeddedMessagingPublishAndSubscribeWAS_AuMEngmrbt1s_WB50;WebSphere Embedded Messaging Publish And SubscribeWAS_AuMEngmrbt1s_WB50;C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe –> C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe [?]
S4 OracleJobSchedulerWB50;OracleJobSchedulerWB50;c:\apps\oracle\product\10.2.0\db_1\bin\extjob.exe wb50 –> c:\apps\oracle\product\10.2.0\db_1\bin\extjob.exe WB50 [?]
S4 OracleJobSchedulerWBCRN;OracleJobSchedulerWBCRN;c:\apps\oracle\product\10.2.0\db_1\bin\extjob.exe wbcrn –> c:\apps\oracle\product\10.2.0\db_1\bin\extjob.exe WBCRN [?]

=============== Created Last 30 ================

2028-09-05 07:10:07 204800 —-a-w- c:\windows\system32\EATools.dll
2022-02-05 01:15:29 249856 —-a-w- c:\windows\system32\EACtlLib.ocx
2009-12-23 22:26:48 75776 -c—-w- c:\windows\system32\dllcache\strmfilt.dll
2009-12-23 22:26:46 25088 -c—-w- c:\windows\system32\dllcache\httpapi.dll
2009-12-23 22:26:45 265728 -c—-w- c:\windows\system32\dllcache\http.sys
2009-12-23 22:26:16 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-23 22:25:33 79872 -c—-w- c:\windows\system32\dllcache\raschap.dll
2009-12-23 22:25:31 149504 -c—-w- c:\windows\system32\dllcache\rastls.dll
2009-12-23 22:22:31 270336 -c—-w- c:\windows\system32\dllcache\oakley.dll
2009-12-23 03:34:52 0 d—–w- c:\program files\Trend Micro
2009-12-23 02:09:07 0 d—–w- c:\docume~1\dfoster3\applic~1\PC Tools
2009-12-23 02:09:07 0 d—–w- c:\docume~1\alluse~1\applic~1\PC Tools
2009-12-22 23:33:14 55856 —-a-r- c:\windows\system32\vnetinst.dll
2009-12-22 23:33:14 16560 —-a-r- c:\windows\system32\drivers\vmnetadapter.sys
2009-12-22 23:32:59 26288 —-a-w- c:\windows\system32\drivers\vmnetuserif.sys
2009-12-22 23:32:54 50736 —-a-r- c:\windows\system32\vmnetbridge.dll
2009-12-22 23:32:54 31280 —-a-r- c:\windows\system32\drivers\vmnetbridge.sys
2009-12-22 23:32:54 18736 —-a-r- c:\windows\system32\drivers\vmnet.sys
2009-12-22 23:32:35 723504 —-a-w- c:\windows\system32\vnetlib.dll
2009-12-22 23:32:27 23216 —-a-w- c:\windows\system32\drivers\VMkbd.sys
2009-12-22 23:30:26 0 d—–w- c:\program files\VMware
2009-12-18 02:34:19 882 —-a-w- c:\windows\RegSDImport.xml
2009-12-18 02:34:19 880 —-a-w- c:\windows\RegISSImport.xml
2009-12-18 02:34:19 767952 —-a-w- c:\windows\BDTSupport.dll
2009-12-18 02:34:19 165840 —-a-w- c:\windows\PCTBDRes.dll
2009-12-18 02:34:19 1640400 —-a-w- c:\windows\PCTBDCore.dll
2009-12-18 02:34:19 149456 —-a-w- c:\windows\SGDetectionTool.dll
2009-12-18 02:34:19 131 —-a-w- c:\windows\IDB.zip
2009-12-18 02:34:19 1152444 —-a-w- c:\windows\UDB.zip
2009-12-18 02:30:50 7387 —-a-w- c:\windows\system32\drivers\pctgntdi.cat
2009-12-18 02:30:50 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-18 02:30:46 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-18 02:30:46 7412 —-a-w- c:\windows\system32\drivers\PCTAppEvent.cat
2009-12-18 02:30:46 7383 —-a-w- c:\windows\system32\drivers\pctcore.cat
2009-12-18 02:30:46 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-18 02:30:37 7383 —-a-w- c:\windows\system32\drivers\pctplsg.cat
2009-12-18 02:30:36 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-18 02:30:24 0 d—–w- c:\program files\common files\PC Tools
2009-12-18 02:30:23 0 d—–w- c:\program files\Spyware Doctor
2009-12-18 01:05:09 0 d-sh–w- c:\documents and settings\dfoster3\IECompatCache
2009-12-16 04:14:59 0 d—–w- c:\docume~1\dfoster3\applic~1\Malwarebytes
2009-12-16 04:14:42 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-16 04:14:36 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-16 04:14:29 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-16 04:14:28 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-15 03:23:14 0 d—–w- c:\program files\Preview Handler Pack
2009-12-15 02:09:03 0 d—–w- c:\program files\Microsoft Corporation
2009-12-15 01:14:48 140824 —-a-w- c:\windows\system32\SecMan.dll
2009-12-15 01:14:47 0 d—–w- c:\program files\GetData
2009-12-14 05:19:11 0 d—–w- c:\docume~1\dfoster3\applic~1\Windows Search
2009-12-09 01:23:56 326192 —-a-w- c:\windows\system32\vmnetdhcp.exe
2009-12-09 01:23:54 399920 —-a-w- c:\windows\system32\vmnat.exe
2009-12-08 04:51:19 0 d—–w- c:\program files\Enterprise Library 3.1 Configuration

==================== Find3M ====================

2009-12-02 00:14:05 123508 —-a-w- c:\windows\system32\nvModes.dat
2009-11-27 00:15:07 51172 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-04 21:39:40 87552 —-a-w- c:\windows\system32\cpwmon2k.dll
2009-10-29 07:45:38 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-13 10:30:16 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 —-a-w- c:\windows\system32\raschap.dll
2008-02-12 23:32:46 32768 –sha-w- c:\windows\system32\config\systemprofile\application data\microsoft\internet explorer\userdata\index.dat
2008-02-12 23:32:46 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat

============= FINISH: 10:58:02.41 ===============

Attachments:

  • [attachment removed: Attach.zip]
Hi,

Please try this as an alternative to GMER, we need to check for Rootkits before proceeding.
  • Download RootRepeal from one of the following locations and save it to your desktop.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • In the Select Scan dialog, check
    [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Please post this log in your next reply.
OK, that ran a lot better. Here's the log. Thanks so much helping me out. This is infuriating. ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2010/01/11 10:06 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xB7094000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xBA5D6000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xAF14B000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: c:\documents and settings\dfoster3\application data\skype\dfoster5\etilqs_iqomlabdannfn0pqjbjp Status: Allocation size mismatch (API: 32768, Raw: 0) Path: c:\documents and settings\dfoster3\application data\skype\dfoster5\etilqs_vwumjjocacque7bptoj9 Status: Allocation size mismatch (API: 16384, Raw: 0) Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS042DB.log Status: Invisible to the Windows API! Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS042DC.log Status: Invisible to the Windows API! Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS042DD.log Status: Invisible to the Windows API! Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS042DE.log Status: Invisible to the Windows API! Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS0432D.log Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS0432E.log Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS0432F.log Status: Visible to the Windows API, but not on disk. Path: c:\documents and settings\all users\application data\microsoft\search\data\applications\windows\gatherlogs\systemindex\systemindex.5.crwl Status: Allocation size mismatch (API: 280, Raw: 8) Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.ci Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.dir Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.wid Status: Visible to the Windows API, but not on disk. SSDT ——————- #: 041 Function Name: NtCreateKey Status: Hooked by "PCTCore.sys" at address 0xb9ed2e52 #: 047 Function Name: NtCreateProcess Status: Hooked by "PCTCore.sys" at address 0xb9eb3cde #: 048 Function Name: NtCreateProcessEx Status: Hooked by "PCTCore.sys" at address 0xb9eb3ed0 #: 053 Function Name: NtCreateThread Status: Hooked by "" at address 0x8770c109 #: 063 Function Name: NtDeleteKey Status: Hooked by "PCTCore.sys" at address 0xb9ed3640 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "PCTCore.sys" at address 0xb9ed38f4 #: 119 Function Name: NtOpenKey Status: Hooked by "PCTCore.sys" at address 0xb9ed1b44 #: 192 Function Name: NtRenameKey Status: Hooked by "PCTCore.sys" at address 0xb9ed3d60 #: 247 Function Name: NtSetValueKey Status: Hooked by "PCTCore.sys" at address 0xb9ed3112 #: 257 Function Name: NtTerminateProcess Status: Hooked by "PCTCore.sys" at address 0xb9eb3984 ==EOF==
OK, let's proceed.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here's the ComboFix log:

ComboFix 10-01-11.01 - dfoster3 12/01/2010 10:56:54.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2852 [GMT 11:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-110663390-1942244339-696691482-500
c:\recycler\S-1-5-21-1563938574-1566498033-2365784913-500
c:\recycler\S-1-5-21-2593470740-3531416835-2459339422-500
c:\windows\AegisP.inf
c:\windows\system32\bin
c:\windows\system32\bin\appletviewer.exe
c:\windows\system32\bin\beanreg.dll
c:\windows\system32\bin\extcheck.exe
c:\windows\system32\bin\HtmlConverter.exe
c:\windows\system32\bin\idlj.exe
c:\windows\system32\bin\jar.exe
c:\windows\system32\bin\jarsigner.exe
c:\windows\system32\bin\java.exe
c:\windows\system32\bin\javac.exe
c:\windows\system32\bin\javadoc.exe
c:\windows\system32\bin\javah.exe
c:\windows\system32\bin\javap.exe
c:\windows\system32\bin\javaw.exe
c:\windows\system32\bin\jdb.exe
c:\windows\system32\bin\keytool.exe
c:\windows\system32\bin\kinit.exe
c:\windows\system32\bin\klist.exe
c:\windows\system32\bin\ktab.exe
c:\windows\system32\bin\native2ascii.exe
c:\windows\system32\bin\orbd.exe
c:\windows\system32\bin\packager.exe
c:\windows\system32\bin\policytool.exe
c:\windows\system32\bin\rmic.exe
c:\windows\system32\bin\rmid.exe
c:\windows\system32\bin\rmiregistry.exe
c:\windows\system32\bin\serialver.exe
c:\windows\system32\bin\servertool.exe
c:\windows\system32\bin\tnameserv.exe
c:\windows\system32\Cache
c:\windows\unins000.dat
c:\windows\unins000.exe

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\atapi.sys
.
((((((((((((((((((((((((( Files Created from 2009-12-12 to 2010-01-12 )))))))))))))))))))))))))))))))
.

2028-09-05 07:10 . 2028-09-05 07:10 204800 —-a-w- c:\windows\system32\EATools.dll
2009-12-23 22:26 . 2009-10-21 05:38 75776 -c—-w- c:\windows\system32\dllcache\strmfilt.dll
2009-12-23 22:26 . 2009-10-21 05:38 25088 -c—-w- c:\windows\system32\dllcache\httpapi.dll
2009-12-23 22:26 . 2009-10-20 16:20 265728 -c—-w- c:\windows\system32\dllcache\http.sys
2009-12-23 22:26 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2009-12-23 22:25 . 2009-10-12 13:38 79872 -c—-w- c:\windows\system32\dllcache\raschap.dll
2009-12-23 22:25 . 2009-10-12 13:38 149504 -c—-w- c:\windows\system32\dllcache\rastls.dll
2009-12-23 22:22 . 2009-10-13 10:30 270336 -c—-w- c:\windows\system32\dllcache\oakley.dll
2009-12-23 03:51 . 2009-12-23 03:51 ——– d—–w- c:\program files\ERUNT
2009-12-23 03:34 . 2009-12-23 03:34 ——– d—–w- c:\program files\Trend Micro
2009-12-18 02:34 . 2009-11-09 23:28 149456 —-a-w- c:\windows\SGDetectionTool.dll
2009-12-18 02:34 . 2009-11-09 23:28 165840 —-a-w- c:\windows\PCTBDRes.dll
2009-12-18 02:34 . 2009-11-09 23:28 1640400 —-a-w- c:\windows\PCTBDCore.dll
2009-12-18 02:34 . 2009-11-09 23:26 767952 —-a-w- c:\windows\BDTSupport.dll
2009-12-18 02:34 . 2009-10-27 14:36 1152444 —-a-w- c:\windows\UDB.zip
2009-12-18 02:34 . 2008-11-26 01:08 131 —-a-w- c:\windows\IDB.zip
2009-12-18 02:30 . 2009-10-30 00:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-18 02:30 . 2009-11-09 00:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-18 02:30 . 2009-10-06 05:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-18 02:30 . 2009-09-02 22:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-18 02:30 . 2009-12-23 02:09 ——– d—–w- c:\program files\Common Files\PC Tools
2009-12-18 02:30 . 2009-12-23 02:09 ——– d—–w- c:\program files\Spyware Doctor
2009-12-18 01:05 . 2009-12-18 01:05 ——– d-sh–w- c:\documents and settings\dfoster3\IECompatCache
2009-12-16 04:14 . 2009-12-16 04:14 ——– d—–w- c:\documents and settings\dfoster3\Application Data\Malwarebytes
2009-12-16 04:14 . 2009-12-03 05:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-16 04:14 . 2009-12-16 04:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-16 04:14 . 2009-12-03 05:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-16 04:14 . 2009-12-23 02:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-15 03:23 . 2009-12-23 02:09 ——– d—–w- c:\program files\Preview Handler Pack
2009-12-15 02:09 . 2009-12-15 02:09 ——– d—–w- c:\program files\Microsoft Corporation
2009-12-15 01:36 . 2009-12-15 01:53 ——– d—–w- c:\documents and settings\All Users\Application Data\WinZip
2009-12-15 01:14 . 2007-03-29 03:57 140824 —-a-w- c:\windows\system32\SecMan.dll
2009-12-15 01:14 . 2009-12-15 01:14 ——– d—–w- c:\program files\GetData
2009-12-15 01:13 . 2010-01-12 00:18 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-14 05:19 . 2009-12-14 05:19 ——– d—–w- c:\documents and settings\dfoster3\Application Data\Windows Search

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-12 00:19 . 2008-02-13 12:49 ——– d—–w- c:\documents and settings\All Users\Application Data\VMware
2010-01-12 00:19 . 2008-02-13 12:51 ——– d—–w- c:\documents and settings\NetworkService\Application Data\VMware
2010-01-12 00:18 . 2008-03-26 22:35 0 —-a-w- c:\documents and settings\dfoster3\Local Settings\Application Data\WavXMapDrive.bat
2010-01-11 04:02 . 2008-03-27 04:15 ——– d—–w- c:\documents and settings\dfoster3\Application Data\VMware
2010-01-08 05:42 . 2008-03-27 04:29 ——– d—–w- c:\documents and settings\dfoster3\Application Data\Skype
2010-01-08 05:04 . 2008-03-27 04:30 ——– d—–w- c:\documents and settings\dfoster3\Application Data\skypePM
2010-01-08 04:15 . 2008-03-27 02:39 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-08 00:27 . 2009-10-06 00:02 63964 —ha-w- c:\windows\system32\mlfcache.dat
2009-12-23 22:36 . 2008-02-13 13:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-23 02:10 . 2009-08-17 00:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Aventail
2009-12-23 02:09 . 2009-12-22 23:30 ——– d—–w- c:\program files\VMware
2009-12-23 02:09 . 2009-12-23 02:09 ——– d—–w- c:\documents and settings\dfoster3\Application Data\PC Tools
2009-12-23 02:09 . 2009-12-23 02:09 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-15 03:57 . 2008-03-28 23:39 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-08 04:51 . 2009-12-08 04:51 ——– d—–w- c:\program files\Enterprise Library 3.1 Configuration
2009-12-02 22:51 . 2008-01-23 03:46 77664 —-a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-02 22:51 . 2008-01-23 03:54 77664 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-02 00:14 . 2008-01-23 03:15 123508 —-a-w- c:\windows\system32\nvModes.dat
2009-12-01 22:07 . 2009-11-30 22:30 ——– d—–w- c:\program files\Windows Desktop Search
2009-11-30 22:31 . 2009-11-30 22:31 ——– d—–w- c:\documents and settings\dfoster3\Application Data\Windows Desktop Search
2009-11-30 05:07 . 2009-11-30 05:07 ——– d—–w- c:\program files\Microsoft Works
2009-11-30 05:07 . 2008-02-12 04:25 ——– d—–w- c:\program files\MSBuild
2009-11-30 04:59 . 2009-11-30 04:59 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2009-11-30 00:50 . 2009-11-30 00:50 ——– d—–w- c:\program files\VisualSVN
2009-11-27 00:31 . 2008-01-23 03:52 ——– d—–w- c:\program files\Google
2009-11-22 23:03 . 2009-11-22 23:03 ——– d—–w- c:\documents and settings\dfoster3\Application Data\McAfee
2009-11-21 15:51 . 2004-08-04 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-18 00:35 . 2009-11-18 00:33 0 —-a-w- c:\documents and settings\kwong\Local Settings\Application Data\WavXMapDrive.bat
2009-11-17 05:04 . 2009-11-17 05:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Infor Global Solutions
2009-11-09 05:56 . 2009-11-09 05:56 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-11-04 21:39 . 2008-04-11 06:16 87552 —-a-w- c:\windows\system32\cpwmon2k.dll
2009-10-29 07:45 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 07:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 07:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 07:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 07:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 07:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 07:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 07:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 07:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 07:55 85768 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-19 159744]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-31 8429568]
"nwiz"="nwiz.exe" [2007-05-31 1626112]
"NVHotkey"="nvHotkey.dll" [2007-05-31 67584]
"NvMediaCenter"="NvMCTray.dll" [2007-05-31 81920]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 823296]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 974848]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2007-09-10 92160]
"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2007-09-14 218424]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-14 29744]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-21 98304]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-18 303104]
"FinePrint Dispatcher v5"="c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" [2008-03-04 516096]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2007-11-13 1052672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-09-24 136512]
"VMware hqtray"="c:\program files\VMware\VMware Player\hqtray.exe" [2009-03-26 64048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ScreenHunter 5.0 Free.lnk - c:\program files\Wisdom-soft ScreenHunter 5 Free\ScreenHunter.exe [2008-3-17 4874240]

c:\documents and settings\dfoster3\Start Menu\Programs\Startup\
Easy Accounting Reminder Utility.LNK - d:\apps\Easy Accounting\Reminder.exe [2028-9-5 28672]
HyperSnap 6.lnk - c:\program files\HyperSnap 6\HprSnap6.exe [2009-5-14 2266712]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-11 2150400]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-1-23 50688]
Monitor Apache Servers.lnk - c:\apps\Apache Group\Apache2\bin\ApacheMonitor.exe [2008-1-17 41042]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
2005-06-19 03:11 24669 —-a-w- c:\windows\system32\ckpNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gemsafe]
2006-11-16 07:20 73728 —-a-w- c:\program files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-333310\Scripts\Logon\0\0]
"Script"=\\infor.com\NETLOGON\maxcinstall.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-333310\Scripts\Logon\1\0]
"Script"=TrackIt.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-335423\Scripts\Logon\0\0]
"Script"=\\infor.com\NETLOGON\maxcinstall.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-335423\Scripts\Logon\1\0]
"Script"=TrackIt.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-382399\Scripts\Logon\0\0]
"Script"=\\infor.com\NETLOGON\maxcinstall.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-382399\Scripts\Logon\1\0]
"Script"=TrackIt.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-382399\Scripts\Logon\2\0]
"Script"=IESecurity_LocalIntranet_AddCompanyDomains.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-382399\Scripts\Logon\3\0]
"Script"=\\infor.com\sysvol\infor.com\scripts\Enterprise Vault\EVCinstall.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-382553\Scripts\Logon\0\0]
"Script"=\\infor.com\NETLOGON\maxcinstall.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-382553\Scripts\Logon\1\0]
"Script"=TrackIt.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-391569\Scripts\Logon\0\0]
"Script"=\\infor.com\NETLOGON\maxcinstall.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-391569\Scripts\Logon\1\0]
"Script"=TrackIt.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-467414\Scripts\Logon\0\0]
"Script"=\\infor.com\NETLOGON\maxcinstall.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-467414\Scripts\Logon\1\0]
"Script"=TrackIt.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-467414\Scripts\Logon\2\0]
"Script"=IESecurity_LocalIntranet_AddCompanyDomains.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-938813117-458837582-310601177-467414\Scripts\Logon\3\0]
"Script"=\\infor.com\sysvol\infor.com\scripts\Enterprise Vault\EVCinstall.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Apps\\oracle\\product\\10.2.0\\db_1\\jdk\\jre\\bin\\java.exe"=
"c:\\Apps\\java\\j2sdk1.4.2_15\\bin\\java.exe"=
"c:\\Apps\\java\\jdk1.5.0_12\\jre\\bin\\javaw.exe"=
"c:\\Apps\\java\\j2sdk1.4.2_15\\bin\\javaw.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Apps\\WebSphere\\AppServer\\java\\bin\\java.exe"=
"c:\\Apps\\IBM\\WebSphere MQ\\bin\\runmqlsr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Apps\\java\\jdk1.5.0_12\\bin\\java.exe"=
"c:\\Apps\\java\\jdk1.5.0_12\\bin\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Motorola\\UID Extraction Tool\\UIDExtraction.exe"=
"c:\\Program Files\\Motorola\\RSD Lite\\SDL.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [18/12/2009 1:30 PM 207792]
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [12/02/2008 2:34 PM 59904]
R2 afpa;afpa;c:\windows\system32\drivers\afpa.sys [31/03/2008 2:24 PM 106224]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [19/12/2006 5:21 PM 79432]
R2 BCLMD;Infor Solution License Server;c:\program files\SLM\bin\SlmServer.exe [7/07/2009 11:53 AM 475136]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [18/12/2009 1:34 PM 112592]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [9/11/2009 10:06 AM 54752]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [13/12/2007 12:07 PM 18944]
R2 MotoConnect Service;MotoConnect Service;c:\program files\Motorola\MotoConnectService\MotoConnectService.exe [20/08/2009 10:04 PM 91392]
R2 NgVpnMgr;Aventail VPN Client;c:\windows\system32\ngvpnmgr.exe [19/01/2009 10:49 AM 223333]
R2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener;c:\apps\oracle\product\10.2.0\db_1\BIN\TNSLSNR –> c:\apps\oracle\product\10.2.0\db_1\BIN\TNSLSNR [?]
R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [26/03/2009 10:58 PM 54960]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [4/08/2004 11:00 PM 5120]
R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [2/11/2006 3:32 PM 97536]
R3 NgLog;Aventail VPN Logging;c:\windows\system32\drivers\nglog.sys [19/01/2009 10:46 AM 25240]
R3 NgVpn;Aventail VPN Adapter;c:\windows\system32\drivers\ngvpn.sys [19/01/2009 10:48 AM 77976]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27/11/2009 11:30 AM 135664]
S3 BEA WebLogic Platform 8.1 NodeManager;BEA WebLogic Platform 8.1 NodeManager;c:\apps\bea\WEBLOG~1\server\bin\beasvc.exe [25/02/2008 2:04 PM 90112]
S3 beasvc wbdomain_wbserver;beasvc wbdomain_wbserver;c:\apps\bea\WEBLOG~1\server\bin\beasvc.exe [25/02/2008 2:04 PM 90112]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\drivers\CSVirtA.sys [27/03/2008 10:09 PM 22136]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [5/08/2009 10:48 PM 704864]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [23/01/2008 2:52 PM 29744]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [20/08/2009 10:05 PM 19712]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [20/08/2009 10:05 PM 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [20/08/2009 10:05 PM 42752]
S3 NgFilter;Aventail VPN Filter;c:\windows\system32\drivers\ngfilter.sys [19/01/2009 10:48 AM 20632]
S3 NgWfp;Aventail VPN Callout;c:\windows\system32\drivers\ngwfp.sys [19/01/2009 10:48 AM 23192]
S3 OracleServiceWB50;OracleServiceWB50;c:\apps\oracle\product\10.2.0\db_1\bin\ORACLE.EXE WB50 –> c:\apps\oracle\product\10.2.0\db_1\bin\ORACLE.EXE WB50 [?]
S3 OracleServiceWBCRN;OracleServiceWBCRN;c:\apps\oracle\product\10.2.0\db_1\bin\ORACLE.EXE WBCRN –> c:\apps\oracle\product\10.2.0\db_1\bin\ORACLE.EXE WBCRN [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [18/12/2009 1:30 PM 359624]
S3 WebSphereEmbeddedMessagingPublishAndSubscribeWAS_AuMEngmrbt1s_server1;WebSphere Embedded Messaging Publish And SubscribeWAS_AuMEngmrbt1s_server1;C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe –> C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe [?]
S3 WebSphereEmbeddedMessagingPublishAndSubscribeWAS_AuMEngmrbt1s_WB50;WebSphere Embedded Messaging Publish And SubscribeWAS_AuMEngmrbt1s_WB50;C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe –> C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe [?]
S4 OracleJobSchedulerWB50;OracleJobSchedulerWB50;c:\apps\oracle\product\10.2.0\db_1\Bin\extjob.exe WB50 –> c:\apps\oracle\product\10.2.0\db_1\Bin\extjob.exe WB50 [?]
S4 OracleJobSchedulerWBCRN;OracleJobSchedulerWBCRN;c:\apps\oracle\product\10.2.0\db_1\Bin\extjob.exe WBCRN –> c:\apps\oracle\product\10.2.0\db_1\Bin\extjob.exe WBCRN [?]
.
Contents of the 'Scheduled Tasks' folder

2008-10-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 01:34]

2010-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-27 00:29]

2010-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-27 00:29]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=y9-u2tVYuezSyPC1HjmV4RKTXTo
uInternet Settings,ProxyServer = epaulette:8080
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.co.uk/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\VMware\VMware Player\vsocklib.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {205E7068-6D03-4566-AD06-A146B592FBA5} - hxxp://spottail.bbs.bunnings.com.au/qcbin/Spider80.ocx
DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} - hxxps://vpn-emea1.infor.com/CACHE/webvpn/stc/1/binaries/stcweb.cab
FF - ProfilePath - c:\documents and settings\dfoster3\Application Data\Mozilla\Firefox\Profiles\zmyuxxcz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/
FF - component: c:\apps\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\apps\Mozilla Firefox\plugins\NPJava11.dll
FF - plugin: c:\apps\Mozilla Firefox\plugins\NPJava12.dll
FF - plugin: c:\apps\Mozilla Firefox\plugins\NPJava131_09.dll
FF - plugin: c:\apps\Mozilla Firefox\plugins\NPJava32.dll
FF - plugin: c:\apps\Mozilla Firefox\plugins\npoji600.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\j2re1.4.2_07\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_07\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_07\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_07\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_07\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_07\bin\NPJPI142_07.dll
FF - plugin: c:\program files\Java\j2re1.4.2_07\bin\NPOJI610.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-MSPY2002 - c:\windows\system32\IME\PINTLGNT\ImScInst.exe
HKLM-Run-PHIME2002ASync - c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
HKLM-Run-PHIME2002A - c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
AddRemove-Enterprise Library 3.1 Configuration - c:\program files\Enterprise Library 3.1 Configuration\uninst.exe
AddRemove-Spybot - Search & Destroy_is1 - c:\windows\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-12 11:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\msftesql]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:MSSQLSERVER"
–

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WebSphereEmbeddedMessagingPublishAndSubscribeWAS_AuMEngmrbt1s_server1]
"ImagePath"="C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WebSphereEmbeddedMessagingPublishAndSubscribeWAS_AuMEngmrbt1s_WB50]
"ImagePath"="C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OracleOraDb10g_home1TNSListener]
"ImagePath"="c:\apps\oracle\product\10.2.0\db_1\BIN\TNSLSNR "

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WebSphereEmbeddedMessagingPublishAndSubscribeWAS_AuMEngmrbt1s_server1]
"ImagePath"="C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WebSphereEmbeddedMessagingPublishAndSubscribeWAS_AuMEngmrbt1s_WB50]
"ImagePath"="C:/Apps/IBM/WebSphere MQ/WEMPS/bin/bipservice.exe"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Driver Signing]
@Denied: (2) (Administrators)
"Policy"=hex:00,00,00,00
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(1080)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll
c:\program files\Bonjour\mdnsNSP.dll

- - - - - - - > 'explorer.exe'(4688)
c:\windows\system32\WININET.dll
c:\program files\HyperSnap 6\HSTxtCap.dll
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\program files\McAfee\Common Framework\McTrayLegacySupportPlugin.dll
c:\program files\McAfee\Common Framework\McTrayInterfaceLib.dll
c:\program files\McAfee\Common Framework\McAfeeWin32GUISupportDLL.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\apps\WinSCP3\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Cisco Systems\SSL VPN Client\agent.exe
c:\windows\System32\SCardSvr.exe
c:\apps\Apache Group\Apache2\bin\Apache.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\apps\Apache Group\Apache2\bin\Apache.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\Network Associates\VirusScan\mcshield.exe
c:\program files\Network Associates\VirusScan\vstskmgr.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\windows\system32\nvsvc32.exe
c:\apps\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\StacSV.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\program files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RunDLL32.exe
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\windows\system32\vmnat.exe
c:\program files\DellTPad\HidFind.exe
c:\windows\stsystra.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\Intel\Wireless\Bin\WLKeeper.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\VMware\VMware Player\vmware-authd.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\windows\system32\vmnetdhcp.exe
c:\program files\Motorola\MotoConnectService\MotoConnect.exe
c:\windows\system32\mdm.exe
c:\windows\system32\SearchProtocolHost.exe
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Completion time: 2010-01-12 11:32:39 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-12 00:32

Pre-Run: 20,196,323,328 bytes free
Post-Run: 20,447,514,624 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 5BD536873473639CD3B78EEE96DBA48A
Looking better, how's it running now?

Eset online scannner

You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
It's running much better now… no re-directs, and IE is much faster. The ESET log is below, but just a note: IE kept blocking it, so eventually I had to follow the Firefox instructions. I don't know whether that's relevant… C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip Win32/Bagle.gen.zip worm C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentieu.zip Win32/Bagle.gen.zip worm C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinFraudLoadedt.zip Win32/Bagle.gen.zip worm C:\Documents and Settings\dfoster3\My Documents\Utilities\WinZip_Pro_14.0.8652.rar NSIS/TrojanDownloader.Agent.NBE trojan
Hi,

C:\Documents and Settings\dfoster3\My Documents\Utilities\WinZip_Pro_14.0.8652.rar NSIS/TrojanDownloader.Agent.NBE trojan
This could well be the source of your problems, I recommend you remove this file.

Click Start >> Run, and then type ComboFix /Uninstall and hit enter.
You can now delete any other tools I had you download and use, unless you wish to keep them.

Now that your system appears to be clean, there's just a few steps I'd like you to take to prevent any future infections.
  • Update Java - you can do this either by using Java's entry on the Control Panel, or by uninstalling these two items:
    Java 2 Runtime Environment Standard Edition v1.3.1_09
    Java 2 Runtime Environment, SE v1.4.2_07

    … and then installing the latest from Sun's website.

  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI