This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Chrome Not Working

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all, any help will be much appreciated…

I managed to infect my work computer with the "Antimalware Doctor". I removed it using Malwarebytes' Anti-Malware. I also ran TDSSKiller, which said it removed a rootkit, and WinSocketFix in an attempt to resolve this internet connection problem. I've also run scans using Spybot and Ad-aware, and have a corporate Norton Antivirus installed.

Both Firefox and Internet Explorer are fine (but Chrome was the browser I was using when I infected the computer - trying to watch football online!)

I use a proxy when at work.

Attached are the HijackThis and ComboFix logs:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30:16, on 07/04/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Drivers\trcboot.exe
C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\c4ebreg\c4ebreg.exe
c:\sdwork\issimsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AT&T Network Client\NetCfgSv.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\T-Mobile Internet Manager\AssistantServices.exe
C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\WINDOWS\system32\Drivers\ldlcserv.exe
C:\WINDOWS\system32\Drivers\ldlcserv6.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe
C:\Program Files\IBM\Personal Communications\tpam.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.4.19\pmonmh.exe
C:\Program Files\c4ebreg\isamtray.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\T-Mobile Internet Manager\UIExec.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\soffice.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AT&T Network Client\NetClient.exe
C:\notes\nlnotes.exe
C:\notes\ntaskldr.EXE
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\IBM\Lotus\Sametime Connect\rcp\eclipse\plugins\com.ibm.rcp.base_6.1.1.200810091628\win32\x86\eclipse.exe
C:\Program Files\IBM\Lotus\Sametime Connect\rcp\eclipse\plugins\com.ibm.rcp.jcl.desktop.win32.x86_6.2.0.200810071032\jre\bin\sametime80w.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w3.ibm.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://w3.ibm.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.emea.ibm.com:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;127.0.0.1;*.local;
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32maing.exe /cleanup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe"
O4 - HKLM\..\Run: [SODCPreLoad] C:\notes\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20080827-1548\preload.exe C:\notes\data\workspace\.sodc\
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [ipmcmu] c:\Program Files\IBM\IPM Client Migration Utility\ipmcmu.exe "c:\Program Files\IBM\IPM Client Migration Utility"
O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.4.19/pmonmh.exe
O4 - HKLM\..\Run: [ISSI Service] "c:\sdwork\issimsvc.exe"
O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\c4ebreg\c4ebreg.exe" /q
O4 - HKLM\..\Run: [Isamtray] "C:\Program Files\c4ebreg\isamtray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [UIExec] "C:\Program Files\T-Mobile Internet Manager\UIExec.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [NetSP - restore settings on power failure] "C:\Program Files\AT&T Network Client\NetSP.exe" -show
O4 - HKCU\..\Run: [SkinClock] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
O4 - HKCU\..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
O4 - HKCU\..\Run: [SODCPreLoad] C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\preload.exe C:\DOCUME~1\ADMINI~1\IBM\Lotus\Symphony\.sodc\
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Check for TWS Updates.lnk = C:\Jts\WiseUpdt.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O11 - Options group: [JAVA_IBM] Java (IBM)
O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com
O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228972592890
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228972560421
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://
O17 - HKLM\System\CCS\Services\Tcpip\..\{89AE022E-B789-48DF-998A-0E33F3C53F95}: Domain = ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{89AE022E-B789-48DF-998A-0E33F3C53F95}: NameServer = 9.64.162.21,9.64.163.21
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ibm.com
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe (file missing)
O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: csrcmds - IBM Corporation - C:\Program Files\IBM\Personal Communications\csrcmds.exe
O23 - Service: IBM Command Line Trace (cstrcser) - IBM Corporation - C:\WINDOWS\system32\drivers\cstrcser.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing)
O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\c4ebreg\c4ebreg.exe
O23 - Service: ISSI (ISSIMon) - IBM Corp. - c:\sdwork\issimsvc.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: IBM Enterprise Extender (IPv4) (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe
O23 - Service: IBM Enterprise Extender (IPv6) (ldlcserv6) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv6.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\Program Files\AT&T Network Client\NetCfgSv.EXE
O23 - Service: Power Manager DBC Service - Unknown owner - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe
O23 - Service: UI Assistant Service - Unknown owner - C:\Program Files\T-Mobile Internet Manager\AssistantServices.exe

–
End of file - 17804 bytes



********************************************************************************
*******************************************************************


ComboFix 10-04-06.01 - GB090455 07/04/2010 9:50.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1992.1135 [GMT 1:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Client Firewall *disabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
c:\windows\system32\Ijl11.dll

.
((((((((((((((((((((((((( Files Created from 2010-03-07 to 2010-04-07 )))))))))))))))))))))))))))))))
.

2010-04-07 07:20 . 2010-04-07 07:20 ——– d—–w- C:\RegBackup
2010-04-06 21:13 . 2010-04-06 21:13 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-06 19:52 . 2010-04-06 19:52 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-04-06 19:52 . 2010-03-29 23:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-06 19:52 . 2010-04-06 19:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-06 19:52 . 2010-03-29 23:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-06 19:52 . 2010-04-06 19:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-06 19:22 . 2010-04-07 06:30 ——– d—–w- c:\documents and settings\Administrator\Application Data\704BE10D27FAA9B75D694560B86E588B
2010-04-05 18:52 . 2010-04-05 18:52 ——– d—–w- c:\program files\BBC iPlayer Desktop
2010-04-01 22:42 . 2010-04-01 22:43 ——– d—–w- c:\program files\MagicDisc
2010-04-01 22:42 . 2009-02-24 16:42 116736 —-a-w- c:\windows\system32\drivers\mcdbus.sys
2010-04-01 21:56 . 2010-04-01 21:56 ——– d—–w- c:\windows\system32\syncdb
2010-04-01 21:27 . 2010-04-01 21:27 ——– d—–w- c:\program files\Windows Installer Clean Up
2010-03-31 13:31 . 2009-05-18 11:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-03-31 13:31 . 2008-04-17 10:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-03-31 13:30 . 2010-03-31 13:30 ——– d—–w- c:\program files\iPod
2010-03-31 13:30 . 2010-03-31 13:31 ——– d—–w- c:\program files\iTunes
2010-03-31 13:30 . 2010-03-31 13:31 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-03-31 13:29 . 2010-03-31 13:29 ——– d—–w- c:\program files\QuickTime
2010-03-31 13:29 . 2010-03-31 13:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-03-31 13:27 . 2010-03-31 13:27 ——– d—–w- c:\program files\Apple Software Update
2010-03-31 13:27 . 2009-10-16 00:33 41472 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-03-31 13:27 . 2009-10-16 00:33 3003680 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-03-31 13:27 . 2010-03-31 13:27 ——– d—–w- c:\program files\Bonjour

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-07 09:08 . 2005-04-05 17:21 ——– d—–w- c:\program files\C4ebreg
2010-04-07 09:06 . 2007-03-05 22:09 40 —-a-w- c:\windows\system32\profile.dat
2010-04-07 08:41 . 2009-08-14 17:43 ——– d—–w- c:\program files\T-Mobile Internet Manager
2010-04-07 08:31 . 2009-10-31 19:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-07 08:25 . 2006-01-24 00:45 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-04-07 06:42 . 2010-04-06 19:51 319000 —-a-w- c:\windows\system32\drivers\tsk29.tmp
2010-04-07 00:06 . 2009-07-23 21:25 ——– d—–w- c:\documents and settings\Administrator\Application Data\uTorrent
2010-04-06 21:44 . 2010-02-19 00:23 ——– d—–w- c:\documents and settings\Administrator\Application Data\vlc
2010-04-06 21:16 . 2009-10-31 20:35 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-06 21:13 . 2009-10-31 19:49 ——– d—–w- c:\program files\Lavasoft
2010-04-06 20:30 . 2009-07-24 21:16 ——– d—–w- c:\program files\Google
2010-04-06 19:46 . 2009-06-26 00:54 ——– d—–w- c:\program files\AT&T Network Client
2010-04-05 22:32 . 2006-03-27 21:50 ——– d—–w- c:\program files\WST
2010-04-05 18:50 . 2009-06-26 20:01 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-04-04 18:53 . 2006-04-12 02:08 ——– d—–w- c:\program files\Common Files\Adobe
2010-04-02 10:49 . 2005-04-04 18:17 47168 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-01 21:27 . 2007-10-10 15:20 ——– d—–w- c:\program files\MSECache
2010-03-31 13:36 . 2010-01-30 12:28 ——– d—–w- c:\documents and settings\Administrator\Application Data\Apple Computer
2010-03-31 13:30 . 2010-01-17 03:54 ——– d—–w- c:\program files\Common Files\Apple
2010-03-18 19:59 . 2009-07-23 21:26 ——– d—–w- c:\program files\uTorrent
2010-02-26 16:34 . 2009-10-07 10:07 6400 —-a-w- c:\windows\system32\drivers\isamfilter.sys
2010-02-26 13:11 . 2010-02-26 13:11 ——– d—–w- c:\documents and settings\Administrator\Application Data\Facebook
2010-02-25 18:11 . 2005-07-29 18:05 64792 —-a-w- c:\windows\isamunin.exe
2010-02-20 20:24 . 2009-07-20 19:22 ——– d—–w- c:\documents and settings\Administrator\Application Data\Spotify
2010-02-12 09:46 . 2010-02-12 09:46 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 09:46 . 2010-02-12 09:46 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-02-04 15:53 . 2009-10-31 20:35 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-01-27 20:35 . 2009-10-31 20:54 15880 —-a-w- c:\windows\system32\lsdelete.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetSP - restore settings on power failure"="c:\program files\AT&T Network Client\NetSP.exe" [2007-01-13 24576]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-05-21 1134592]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-07-16 307768]
"SODCPreLoad"="c:\program files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\preload.exe" [2009-02-11 40960]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-03 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pmonmh"="c:\program files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.4.19" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"stgclean"="c:\sdwork\w32maing.exe" [2010-03-15 267776]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~2\SYMANT~2\VPTray.exe" [2006-09-27 125168]
"Tpam.exe"="c:\program files\IBM\Personal Communications\tpam.exe" [2007-11-02 28672]
"SODCPreLoad"="c:\notes\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20080827-1548\preload.exe" [2008-11-15 40960]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-06-26 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-06-26 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-06-26 141848]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592]
"TpShocks"="TpShocks.exe" [2008-06-06 181536]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2009-06-26 331776]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2009-06-26 208896]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-26 820520]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2009-06-26 60192]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-03-24 68464]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-08-15 143360]
"ipmcmu"="c:\program files\IBM\IPM Client Migration Utility\ipmcmu.exe" [2009-06-29 204800]
"ISSI Service"="c:\sdwork\issimsvc.exe" [2010-02-11 241392]
"C4EBReg"="c:\program files\c4ebreg\c4ebreg.exe" [2010-02-25 482584]
"Isamtray"="c:\program files\c4ebreg\isamtray.exe" [2010-02-25 285976]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-29 148888]
"UIExec"="c:\program files\T-Mobile Internet Manager\UIExec.exe" [2009-06-12 132608]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-25 142120]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Check for TWS Updates.lnk - c:\jts\WiseUpdt.exe [2010-2-24 194775]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2009-10-02 128360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pcsinst]
2007-11-02 10:45 49152 —-a-w- c:\windows\system32\pcsinst.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 16:37 34344 —-a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2008-03-17 16:02 34080 —-a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 15:57 948672 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 01:57 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\assistant2]
2006-10-20 09:01 2107392 —-a-w- c:\program files\VoiceRite\Client\Viewer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 16:44 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"IBMconfig"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [31/10/2009 21:35 64288]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [16/10/2009 22:12 721904]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [14/05/2008 17:21 19496]
R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [09/10/2009 04:45 169312]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [04/02/2010 16:52 1265264]
R2 ldlcserv6;IBM Enterprise Extender (IPv6);c:\windows\system32\drivers\ldlcserv6.exe [02/11/2007 05:09 40960]
R2 pdlndldl6;IBM Enterprise Extender (HPR/IPv6);c:\windows\system32\drivers\pdlndldl6.sys [02/11/2007 05:09 70656]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\ThinkPad\Utilities\PWMDBSVC.exe [26/06/2009 01:47 94208]
R2 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [27/09/2006 21:33 116464]
R2 UI Assistant Service;UI Assistant Service;c:\program files\T-Mobile Internet Manager\AssistantServices.exe [14/08/2009 18:43 241664]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [26/06/2009 01:22 243856]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [04/09/2009 20:31 102448]
R3 IsamFilter;IsamFilter;c:\windows\system32\drivers\isamfilter.sys [07/10/2009 11:07 6400]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [24/07/2009 22:16 133104]
S3 csrcmds;csrcmds;c:\program files\IBM\Personal Communications\csrcmds.exe [02/11/2007 05:09 49152]
S3 cstrcser;IBM Command Line Trace;c:\windows\system32\drivers\cstrcser.exe [02/11/2007 05:09 36864]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [14/08/2009 18:43 9728]

— Other Services/Drivers In Memory —

*Deregistered* - BMLoad

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2010-04-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 21:15]

2010-04-07 c:\windows\Tasks\At1.job
- c:\program files\IBM\IPM Client Migration Utility\ipmcmu.exe [2009-06-26 12:43]

2010-04-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-24 21:16]

2010-04-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-24 21:16]

2010-04-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2869554992-1010074173-1580797646-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-03 08:21]

2010-04-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2869554992-1010074173-1580797646-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-03 08:21]

2010-04-07 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2009-06-26 00:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://w3.ibm.com/
uInternet Connection Wizard,ShellNext = hxxp://w3.ibm.com/
uInternet Settings,ProxyServer = proxy.emea.ibm.com:8080
uInternet Settings,ProxyOverride = localhost;127.0.0.1;*.local;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} - hxxp://
DPF: {9519B2A2-6592-4E41-8290-D0298459270C} - hxxp://w3.ibm.com/bluepages/scripts/lnwebassist.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff36\gears.dll
FF - plugin: c:\documents and settings\Administrator\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

Notify-ACNotify - ACNotify.dll
Notify-atmgrtok - atmgrtok.dll
SafeBoot-klmdb.sys
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-07 10:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ipmcmu = c:\program files\IBM\IPM Client Migration Utility\ipmcmu.exe "c:\program files\IBM\IPM Client Migration Utility"?run key ipmcmu was set successfully?run key ipmcmu was not set successfully?Error, Windows run key not found?The service "Task Scheduler" is not ru

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: >>UNKNOWN [0x804D7000]<< >>UNKNOWN [0xF76B7000]<< >>UNKNOWN [0xF76A7000]<< >>UNKNOWN [0xF748F000]<< >>UNKNOWN [0x806FF000]<< >>UNKNOWN [0x89B43AC8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0xf76bbfc3
\Driver\ACPI -> 0xf7495cb8
\Driver\atapi -> 0x8a6131f8
\Driver\iaStor -> 0xf7b4b992
IoDeviceObjectType -> DeleteProcedure -> 0x805e4d69
ParseProcedure -> 0x8057950b
\Device\Harddisk0\DR0 -> DeleteProcedure -> 0x805e4d69
ParseProcedure -> 0x8057950b
NDIS: Intel® WiFi Link 5100 AGN -> SendCompleteHandler -> 0xba62dbb0
PacketIndicateHandler -> 0xba61ca0d
SendHandler -> 0xba630b40
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iastor]
"ImagePath"="system32\drivers\tsk29.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2869554992-1010074173-1580797646-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,fe,38,df,56,87,6c,4c,b5,1c,3e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,fe,38,df,56,87,6c,4c,b5,1c,3e,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1060)
c:\windows\system32\WININET.dll
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll
c:\program files\IBM\Personal Communications\atmgrtok.dll
c:\program files\IBM\Personal Communications\MILLUTIL.DLL
c:\windows\system32\pcsinst.dll

- - - - - - - > 'lsass.exe'(1124)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(752)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\program files\Stardock\Fences\FencesMenu.dll
c:\program files\stardock\fences\DesktopDock.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\windows\system32\Drivers\trcboot.exe
c:\program files\IBM\Personal Communications\PCS_AGNT.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AT&T Network Client\NetCfgSv.EXE
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
c:\program files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
c:\windows\System32\TPHDEXLG.exe
c:\windows\system32\TpKmpSVC.exe
c:\windows\system32\wdfmgr.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\windows\system32\Drivers\ldlcserv.exe
c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\TpShocks.exe
c:\windows\system32\rundll32.exe
c:\program files\IBM\My Help\plugins\com.ibm.myhelp.common_1.4.19\pmonmh.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\Zoom\TpScrex.exe
c:\program files\Synaptics\SynTP\SynTPLpr.exe
c:\program files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\soffice.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-04-07 10:28:13 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-07 09:28

Pre-Run: 3,487,678,464 bytes free
Post-Run: 3,354,902,528 bytes free

- - End Of File - - 14EA25503A6FB9AC9740E9CB7E57C006



As I said, any help would be appreciated, because I've got used to Chrome now!

Thanks,
Mark
Hi,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 24 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


Running Combofix and other advance tools without proper supervision can render your machine inoperable!


Let's start with these:
OTL:
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
–Next–

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


To post in your next reply:
1. OTL logs.
2. GMER log.
Hi Inxanity, thanks for the reply.

Here goes, first to be attached, OTL.txt:

OTL logfile created on: 09/04/2010 12:07:44 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 32.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 4.45 Gb Free Space | 2.98% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: IBM-9E676F572B2
Current User Name: GB090455
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\C4ebreg\isamtray.exe (IBM Corp.)
PRC - C:\Program Files\C4ebreg\c4ebreg.exe (IBM Corp.)
PRC - c:\sdwork\issimsvc.exe (IBM Corp.)
PRC - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Windows Live\Mail\wlmail.exe (Microsoft Corporation)
PRC - C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
PRC - C:\Program Files\T-Mobile Internet Manager\AssistantServices.exe ()
PRC - C:\Program Files\T-Mobile Internet Manager\UIExec.exe ()
PRC - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.4.19\pmonmh.exe ()
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\soffice.exe ()
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\notes\nlnotes.exe (IBM Corp)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
PRC - C:\notes\ntaskldr.exe (IBM Corp)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\WINDOWS\system32\TpShocks.exe (Lenovo.)
PRC - C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe ()
PRC - C:\WINDOWS\system32\TPHDEXLG.exe (Lenovo.)
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\system32\drivers\ldlcserv6.exe (IBM Corporation)
PRC - C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE (IBM Corporation)
PRC - C:\WINDOWS\system32\drivers\trcboot.exe (IBM Corporation)
PRC - C:\WINDOWS\system32\drivers\ldlcserv.exe (IBM Corporation)
PRC - C:\Program Files\IBM\Personal Communications\tpam.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AT&T; Network Client\NetCfgSv.EXE (AT&T;)
PRC - C:\Program Files\AT&T; Network Client\NetClient.exe (AT&T;)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (symantec)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\TpKmpSvc.exe ()
PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (ISAMsmt) – File not found
SRV - (AdobeActiveFileMonitor6.0) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ISAMSvc) – C:\Program Files\c4ebreg\c4ebreg.exe (IBM Corp.)
SRV - (ISSIMon) – c:\sdwork\issimsvc.exe (IBM Corp.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AdobeActiveFileMonitor8.0) – C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (Power Manager DBC Service) – C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
SRV - (IBMPMSVC) – C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
SRV - (UI Assistant Service) – C:\Program Files\T-Mobile Internet Manager\AssistantServices.exe ()
SRV - (btwdins) – C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (AcPrfMgrSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
SRV - (AcSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
SRV - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (S24EventMonitor) – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (TPHDEXLGSVC) – C:\WINDOWS\system32\TPHDEXLG.exe (Lenovo.)
SRV - (csrcmds) – C:\Program Files\IBM\Personal Communications\csrcmds.exe (IBM Corporation)
SRV - (ldlcserv6) IBM Enterprise Extender (IPv6) – C:\WINDOWS\system32\drivers\ldlcserv6.exe (IBM Corporation)
SRV - (cstrcser) – C:\WINDOWS\system32\drivers\cstrcser.exe (IBM Corporation)
SRV - (TrcBoot) – C:\WINDOWS\system32\drivers\trcboot.exe (IBM Corporation)
SRV - (AppnNode) – C:\WINDOWS\system32\drivers\appnnode.exe (IBM Corporation)
SRV - (ldlcserv) IBM Enterprise Extender (IPv4) – C:\WINDOWS\system32\drivers\ldlcserv.exe (IBM Corporation)
SRV - (NetCfgSvr) – C:\Program Files\AT&T; Network Client\NetCfgSv.EXE (AT&T;)
SRV - (SavRoam) – c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (SymSecurePort) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
SRV - (ISSVC) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccProxy) – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (TpKmpSVC) – C:\WINDOWS\system32\TpKmpSvc.exe ()
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (iastor) – C:\WINDOWS\system32\drivers\tsk29.tmp (Intel Corporation)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100408.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100408.002\NAVENG.SYS (Symantec Corporation)
DRV - (IsamFilter) – C:\WINDOWS\system32\drivers\isamfilter.sys (IBM Corp.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (SYMIDSCO) – C:\Program Files\Common Files\Symantec Shared\SymcData\scfidsdefs\20100402.001\SymIDSCo.sys (Symantec Corporation)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SCDEmu) – C:\WINDOWS\system32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (TSMAPIP) – C:\WINDOWS\system32\drivers\TSMAPIP.SYS ()
DRV - (TPPWRIF) – C:\WINDOWS\system32\drivers\TPPWRIF.SYS ()
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (tpm) – C:\WINDOWS\system32\drivers\tpm.sys (Intel Corporation)
DRV - (HECI) Intel® – C:\WINDOWS\system32\drivers\HECI.sys (Intel Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (IBMPMDRV) – C:\WINDOWS\system32\drivers\ibmpmdrv.sys (Lenovo.)
DRV - (e1yexpress) Intel® – C:\WINDOWS\system32\drivers\e1y5132.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (CnxtHdAudService) – C:\WINDOWS\system32\drivers\CHDAU32.sys (Conexant Systems Inc.)
DRV - (tcpipBM) – C:\WINDOWS\system32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (ZTEusbnmea) – C:\WINDOWS\system32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) – C:\WINDOWS\system32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\WINDOWS\system32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (IBMTPCHK) – C:\WINDOWS\system32\drivers\IBMBLDID.sys ()
DRV - (ANC) – C:\WINDOWS\system32\drivers\ANC.sys (IBM Corp.)
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (Shockprf) – C:\WINDOWS\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\WINDOWS\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (TPHKDRV) – C:\WINDOWS\system32\drivers\TPHKDRV.sys (Lenovo Group Limited)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (Appn) – C:\WINDOWS\System32\drivers\appn.sys (IBM Corporation)
DRV - (AppnBase) – C:\WINDOWS\System32\drivers\AppnBase.sys (IBM Corporation)
DRV - (pdlncfwk) – C:\WINDOWS\System32\drivers\pdlncfwk.sys (IBM Corporation)
DRV - (AppnApi) – C:\WINDOWS\System32\drivers\appnapi.sys (IBM Corporation)
DRV - (IBM_LLC2) – C:\WINDOWS\system32\drivers\llc2.sys (IBM Corporation)
DRV - (pdlnacom) – C:\WINDOWS\System32\drivers\pdlnacom.sys (IBM Corporation)
DRV - (pdlndldl6) IBM Enterprise Extender (HPR/IPv6) – C:\WINDOWS\System32\drivers\pdlndldl6.sys (IBM Corporation)
DRV - (pdlndlpb) – C:\WINDOWS\System32\drivers\pdlndlpb.sys (IBM Corporation)
DRV - (pdlnemap) – C:\WINDOWS\System32\drivers\pdlnemap.sys (IBM Corporation)
DRV - (pdlndsdl) – C:\WINDOWS\System32\drivers\pdlndsdl.sys (IBM Corporation)
DRV - (pdlndldl) IBM Enterprise Extender (HPR/IPv4) – C:\WINDOWS\System32\drivers\pdlndldl.sys (IBM Corporation)
DRV - (pdlnshay) – C:\WINDOWS\System32\drivers\pdlnshay.sys (IBM Corporation)
DRV - (pdlnsx25) – C:\WINDOWS\System32\drivers\pdlnsx25.sys (IBM Corporation)
DRV - (pdlnsv25) – C:\WINDOWS\System32\drivers\pdlnsv25.sys (IBM Corporation)
DRV - (pdlndqll) – C:\WINDOWS\System32\drivers\pdlndqll.sys (IBM Corporation)
DRV - (pdlndtdl) – C:\WINDOWS\System32\drivers\pdlndtdl.sys (IBM Corporation)
DRV - (pdlnecfg) – C:\WINDOWS\System32\drivers\pdlnecfg.sys (IBM Corporation)
DRV - (Anydlc) – C:\WINDOWS\System32\drivers\anydlc.sys (IBM Corporation)
DRV - (pdlnafac) – C:\WINDOWS\System32\drivers\pdlnafac.sys (IBM Corporation)
DRV - (KLOGNT) – C:\WINDOWS\System32\drivers\klognt.sys (IBM Corporation)
DRV - (pdlnslea) – C:\WINDOWS\System32\drivers\pdlnslea.sys (IBM Corporation)
DRV - (pdlnatcm) – C:\WINDOWS\System32\drivers\pdlnatcm.sys (IBM Corporation)
DRV - (pdlnepkt) – C:\WINDOWS\System32\drivers\pdlnepkt.sys (IBM Corporation)
DRV - (pdlndoem) – C:\WINDOWS\System32\drivers\pdlndoem.sys (IBM Corporation)
DRV - (pdlnatdl) – C:\WINDOWS\System32\drivers\pdlnatdl.sys (IBM Corporation)
DRV - (pdlndint) – C:\WINDOWS\System32\drivers\pdlndint.sys (IBM Corporation)
DRV - (pdlnemsg) – C:\WINDOWS\System32\drivers\pdlnemsg.sys (IBM Corporation)
DRV - (pdlnctdl) – C:\WINDOWS\System32\drivers\pdlnctdl.sys (IBM Corporation)
DRV - (NsTrcNT) – C:\WINDOWS\System32\drivers\nstrcnt.sys (IBM Corporation)
DRV - (pdlnebas) – C:\WINDOWS\System32\drivers\pdlnebas.sys (IBM Corporation)
DRV - (pdlncbas) – C:\WINDOWS\System32\drivers\pdlncbas.sys (IBM Corporation)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (agnfilt) – C:\WINDOWS\system32\drivers\agnfilt.sys (AT&T;)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (EGATHDRV) – C:\WINDOWS\system32\egathdrv.sys (IBM Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (agnwifi) – C:\WINDOWS\system32\drivers\agnwifi.sys (AT&T;)
DRV - (avpnnic) – C:\WINDOWS\system32\drivers\avpnnic.sys (AT&T;)
DRV - (PMEM) – C:\WINDOWS\system32\drivers\PMEMNT.SYS (Microsoft Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://w3.ibm.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;127.0.0.1;*.local;
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy.emea.ibm.com:8080

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.9
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.36.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {d5ea4520-61a1-11da-8cd6-0800200c9a66}:2009.07.19
FF - prefs.js..extensions.enabledItems: [removed]:3.5.7
FF - prefs.js..network.proxy.backup.ftp: "proxy.emea.ibm.com"
FF - prefs.js..network.proxy.backup.ftp_port: 8080
FF - prefs.js..network.proxy.backup.gopher: "proxy.emea.ibm.com"
FF - prefs.js..network.proxy.backup.gopher_port: 8080
FF - prefs.js..network.proxy.backup.socks: "proxy.emea.ibm.com"
FF - prefs.js..network.proxy.backup.socks_port: 8080
FF - prefs.js..network.proxy.backup.ssl: "proxy.emea.ibm.com"
FF - prefs.js..network.proxy.backup.ssl_port: 8080
FF - prefs.js..network.proxy.ftp: "proxy.emea.ibm.com"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.gopher: "proxy.emea.ibm.com"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "proxy.emea.ibm.com"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "proxy.emea.ibm.com"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "proxy.emea.ibm.com"
FF - prefs.js..network.proxy.ssl_port: 8080

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\T-Mobile Internet Manager\addon [2009/08/14 18:43:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2010/03/06 05:35:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/08 19:09:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/08 19:09:43 | 000,000,000 | —D | M]

[2009/06/29 13:38:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2009/06/29 16:55:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\eclipse\extensions
[2008/12/11 17:46:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\eclipse1\extensions
[2010/04/08 18:27:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\extensions
[2010/01/10 05:56:31 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/08/20 20:06:01 | 000,000,000 | —D | M] (QuickProxy) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\extensions\{d5ea4520-61a1-11da-8cd6-0800200c9a66}
[2010/04/07 16:33:22 | 000,000,000 | —D | M] (DownThemAll!) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/06/29 16:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\extensions\[removed]
[2010/03/05 19:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\extensions\[removed]
[2009/06/29 16:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\extensions\[removed]\plugins
[2009/10/13 15:12:15 | 000,000,939 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\searchplugins\dictionary.xml
[2009/08/27 21:08:26 | 000,001,907 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\searchplugins\flickr-tags.xml
[2009/07/06 17:06:07 | 000,001,504 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\searchplugins\imdb.xml
[2009/10/13 15:12:30 | 000,002,256 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\searchplugins\snappy-words.xml
[2009/07/18 00:19:19 | 000,004,140 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\io5qivq1.default\searchplugins\youtube.xml
[2010/04/08 18:27:22 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/06/30 16:06:45 | 000,072,960 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/04/08 19:09:38 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/08 19:09:39 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/08 19:09:39 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/08 19:09:39 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/04/07 10:16:23 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O4 - HKLM..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [BLOG] C:\Program Files\ThinkPad\Utilities\BATLOGEX.DLL ()
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [C4EBReg] C:\Program Files\c4ebreg\c4ebreg.exe (IBM Corp.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ipmcmu] c:\Program Files\IBM\IPM Client Migration Utility\ipmcmu.exe (IBM)
O4 - HKLM..\Run: [Isamtray] C:\Program Files\c4ebreg\isamtray.exe (IBM Corp.)
O4 - HKLM..\Run: [ISSI Service] c:\sdwork\issimsvc.exe (IBM Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.4.19/pmonmh.exe ()
O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [SODCPreLoad] C:\notes\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20080827-1548\preload.exe ()
O4 - HKLM..\Run: [stgclean] c:\sdwork\w32maing.exe (IBM Global Services)
O4 - HKLM..\Run: [Tpam.exe] C:\Program Files\IBM\Personal Communications\tpam.exe ()
O4 - HKLM..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (Lenovo)
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [UIExec] C:\Program Files\T-Mobile Internet Manager\UIExec.exe ()
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec Client Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [NetSP - restore settings on power failure] C:\Program Files\AT&T; Network Client\NetSP.exe (AT&T;)
O4 - HKCU..\Run: [SkinClock] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe ()
O4 - HKCU..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4 - HKCU..\Run: [SODCPreLoad] C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20081031-1700\preload.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Check for TWS Updates.lnk = C:\Jts\WiseUpdt.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} http:// (Java Plug-in 1.5.0)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1228972592890 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1228972560421 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} http://w3.ibm.com/bluepages/scripts/lnwebassist.cab (LNWebAssist Class)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http:// (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\pcsinst: DllName - pcsinst.dll - C:\WINDOWS\System32\pcsinst.dll (IBM Corporation)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - C:\Program Files\Lenovo\HOTKEY\tphklock.dll - C:\Program Files\Lenovo\HOTKEY\tphklock.dll (Lenovo Group Limited)
O22 - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files\Stardock\Fences\FencesMenu.dll (Stardock)
O24 - Desktop BackupWallPaper: C:\WINDOWS\BlueBack.BMP
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/04/04 18:44:20 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/04/09 10:51:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\smkits
[2010/04/08 05:39:34 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/07 18:46:36 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/04/07 18:45:49 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/04/07 10:31:17 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/07 10:30:16 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/04/07 09:46:25 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/04/07 09:46:25 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/04/07 09:46:24 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/04/07 09:46:24 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/04/07 09:45:32 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/04/07 09:41:40 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/07 09:14:25 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Recent
[2010/04/07 08:20:15 | 000,000,000 | —D | C] – C:\RegBackup
[2010/04/06 22:13:18 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/04/06 20:52:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2010/04/06 20:52:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/06 20:52:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/06 20:52:26 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/06 20:52:25 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/06 20:28:09 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/04/06 20:22:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\704BE10D27FAA9B75D694560B86E588B
[2010/04/05 19:52:30 | 000,000,000 | —D | C] – C:\Program Files\BBC iPlayer Desktop
[2010/04/01 23:42:56 | 000,116,736 | —- | C] (MagicISO, Inc.) – C:\WINDOWS\System32\drivers\mcdbus.sys
[2010/04/01 23:42:56 | 000,000,000 | —D | C] – C:\Program Files\MagicDisc
[2010/04/01 22:56:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\syncdb
[2010/04/01 22:27:43 | 000,000,000 | —D | C] – C:\Program Files\Windows Installer Clean Up
[2010/03/31 14:31:26 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2010/03/31 14:30:13 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/03/31 14:30:05 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/03/31 14:30:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/03/31 14:29:14 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/03/31 14:29:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/03/31 14:27:56 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/03/31 14:27:40 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/03/31 14:27:34 | 003,003,680 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2010/03/31 14:27:17 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/03/22 22:48:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\Travel Insurance
[2010/03/17 20:53:42 | 000,094,208 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/03/17 20:53:42 | 000,069,632 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2010/02/06 01:16:01 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/07/24 22:21:00 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/06/29 12:58:36 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Avaya
[2009/06/26 01:53:21 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2009/06/26 01:53:21 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Intel
[2008/08/22 16:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\IBM
[2005/04/04 18:47:12 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2005/04/04 18:44:12 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2005/04/04 18:44:12 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/09 11:38:00 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/09 11:33:01 | 000,000,998 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2869554992-1010074173-1580797646-500UA.job
[2010/04/09 10:51:00 | 000,002,271 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AT&T; Network Client.lnk
[2010/04/09 09:38:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/09 09:33:00 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2869554992-1010074173-1580797646-500Core.job
[2010/04/09 07:57:28 | 000,000,818 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\AtomicAlarmClock.ini
[2010/04/09 07:14:48 | 000,023,552 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/09 05:22:27 | 000,000,000 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\LOWEPRO PASSPORT SLING + SAMSONITE CARRY-ON
[2010/04/09 01:12:00 | 000,000,510 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2010/04/08 19:27:25 | 000,000,316 | —- | M] () – C:\WINDOWS\tasks\PMTask.job
[2010/04/08 18:16:58 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/04/08 18:14:21 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/08 18:13:44 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/08 18:13:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/08 18:12:55 | 2088,787,968 | -HS- | M] () – C:\hiberfil.sys
[2010/04/07 11:16:44 | 000,002,344 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Google Chrome.lnk
[2010/04/07 11:16:03 | 000,000,513 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to MBA Finance.lnk
[2010/04/07 10:35:59 | 000,512,914 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/07 10:35:59 | 000,436,048 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/04/07 10:35:59 | 000,069,680 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/04/07 10:30:50 | 010,223,616 | —- | M] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/04/07 10:17:49 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/07 10:16:23 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/04/07 10:06:15 | 000,000,040 | —- | M] () – C:\WINDOWS\System32\profile.dat
[2010/04/07 10:06:10 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2010/04/07 09:33:02 | 003,908,515 | R— | M] () – C:\Program Files\ComboFix.exe
[2010/04/06 22:16:56 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/04/06 11:32:37 | 000,000,000 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\ACCEPT LBS + SEND STUFF (plus pay £1500!) by 15th April
[2010/04/06 11:20:47 | 000,000,701 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Mark Utilisation 2010.xls.lnk
[2010/04/06 11:13:51 | 000,223,712 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/04/02 11:49:17 | 000,047,168 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/02 11:45:51 | 000,349,331 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2010/03/31 14:44:58 | 007,105,444 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\AcingTheMBAInterview.mp3
[2010/03/31 14:44:58 | 007,003,452 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\MBAvMSF.mp3
[2010/03/31 14:28:50 | 000,000,498 | —- | M] () – C:\WINDOWS\win.ini
[2010/03/31 14:28:50 | 000,000,294 | RHS- | M] () – C:\boot.ini
[2010/03/31 13:08:53 | 000,001,643 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\alarms.ini
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/24 01:13:16 | 000,014,336 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Camera Insurance.xls
[2010/03/23 23:28:13 | 000,006,160 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\PrimoPDFSet.xml
[2010/03/19 11:53:34 | 000,065,024 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\corporate games entry form 2010.xls
[2010/03/19 11:48:20 | 000,080,080 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\DragonPayment.JPG
[2010/03/19 01:05:30 | 000,018,944 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Family Videos.xls
[2010/03/17 20:53:42 | 000,094,208 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/03/17 20:53:42 | 000,069,632 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2010/03/16 20:06:06 | 001,135,734 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\MarkCliftDriverLicence.bmp
[2010/03/12 18:02:38 | 000,261,632 | —- | M] () – C:\WINDOWS\PEV.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/09 05:22:27 | 000,000,000 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\LOWEPRO PASSPORT SLING + SAMSONITE CARRY-ON
[2010/04/07 11:16:44 | 000,002,344 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Google Chrome.lnk
[2010/04/07 11:16:02 | 000,000,513 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Shortcut to MBA Finance.lnk
[2010/04/07 09:46:26 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/07 09:46:25 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/07 09:46:25 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/07 09:46:24 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/07 09:46:24 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/07 09:32:33 | 003,908,515 | R— | C] () – C:\Program Files\ComboFix.exe
[2010/04/06 11:32:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\ACCEPT LBS + SEND STUFF (plus pay £1500!) by 15th April
[2010/04/06 11:20:47 | 000,000,701 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Mark Utilisation 2010.xls.lnk
[2010/03/24 01:03:14 | 000,014,336 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Camera Insurance.xls
[2010/03/19 11:48:19 | 000,080,080 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\DragonPayment.JPG
[2010/03/18 23:57:41 | 000,018,944 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Family Videos.xls
[2010/03/16 20:06:04 | 001,135,734 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\MarkCliftDriverLicence.bmp
[2010/03/15 10:14:09 | 000,065,024 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\corporate games entry form 2010.xls
[2010/03/14 17:52:51 | 007,105,444 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\AcingTheMBAInterview.mp3
[2010/03/14 17:51:31 | 007,003,452 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\MBAvMSF.mp3
[2010/03/07 21:43:54 | 000,000,280 | —- | C] () – C:\Documents and Settings\Administrator\VideoTrace_1.txt
[2010/03/07 21:43:54 | 000,000,183 | —- | C] () – C:\Documents and Settings\Administrator\VideoTrace_0.txt
[2010/03/07 21:43:26 | 000,001,294 | —- | C] () – C:\Documents and Settings\Administrator\FFDC.1267994606168.txt
[2010/03/07 21:43:21 | 000,001,294 | —- | C] () – C:\Documents and Settings\Administrator\FFDC.1267994601246.txt
[2010/03/07 21:43:16 | 000,001,294 | —- | C] () – C:\Documents and Settings\Administrator\FFDC.1267994596449.txt
[2010/02/24 18:27:28 | 000,000,043 | —- | C] () – C:\WINDOWS\ib.ini
[2010/02/24 18:27:27 | 000,026,624 | —- | C] () – C:\WINDOWS\GetIe.dll
[2010/02/03 22:38:29 | 000,000,008 | RH– | C] () – C:\Documents and Settings\Administrator\hwid
[2010/01/11 22:19:50 | 000,000,881 | —- | C] () – C:\Documents and Settings\Administrator\.recently-used.xbel
[2009/11/18 22:03:38 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\TunnelThruDll.dll
[2009/11/18 22:03:38 | 000,030,720 | —- | C] () – C:\WINDOWS\System32\tdsExSvr.dll
[2009/11/01 21:30:31 | 010,223,616 | —- | C] () – C:\Documents and Settings\Administrator\ntuser.dat
[2009/10/16 22:12:07 | 000,721,904 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/09/27 23:51:48 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2009/08/27 00:10:17 | 000,001,643 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\alarms.ini
[2009/08/27 00:10:17 | 000,000,818 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\AtomicAlarmClock.ini
[2009/08/19 18:01:06 | 000,000,102 | —- | C] () – C:\WINDOWS\SW_Win2000X9.DLL
[2009/08/19 17:51:29 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\XLSCX.INI
[2009/08/19 17:51:29 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\WordCX.INI
[2009/08/19 17:51:28 | 000,000,050 | —- | C] () – C:\WINDOWS\SW_Win2000X16.DLL
[2009/08/12 00:17:46 | 000,000,605 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\AutoGK.ini
[2009/08/11 23:50:29 | 000,000,038 | —- | C] () – C:\WINDOWS\AviSplitter.INI
[2009/07/21 14:31:13 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2009/07/01 21:13:50 | 000,006,160 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\PrimoPDFSet.xml
[2009/07/01 21:13:48 | 000,000,324 | —- | C] () – C:\Documents and Settings\LocalService\Application Data\PrimoPDFSet.xml
[2009/07/01 21:09:50 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2009/07/01 14:59:16 | 000,023,552 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/30 12:04:35 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Administrator\nation.hiv.LOG
[2009/06/30 12:04:35 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Administrator\ctf.hiv.LOG
[2009/06/30 12:04:34 | 000,008,192 | —- | C] () – C:\Documents and Settings\Administrator\nation.hiv
[2009/06/30 12:04:34 | 000,008,192 | —- | C] () – C:\Documents and Settings\Administrator\layout.hiv
[2009/06/30 12:04:34 | 000,008,192 | —- | C] () – C:\Documents and Settings\Administrator\ctf.hiv
[2009/06/30 12:04:34 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Administrator\layout.hiv.LOG
[2009/06/29 16:18:17 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/06/26 01:53:40 | 000,004,224 | —- | C] () – C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2009/06/26 01:49:23 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2009/06/26 01:48:11 | 001,060,424 | —- | C] () – C:\WINDOWS\System32\WdfCoInstaller01000.dll
[2009/06/26 01:47:57 | 000,004,442 | —- | C] () – C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2009/06/26 01:42:41 | 000,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2009/06/26 01:42:41 | 000,001,024 | -H– | C] () – C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2009/06/26 01:22:49 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4957.dll
[2009/04/27 05:13:36 | 000,000,314 | —- | C] () – C:\WINDOWS\primopdf.ini
[2009/02/11 22:21:22 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/11/14 22:24:06 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\pdresrc.dll
[2008/11/14 22:24:04 | 000,552,960 | —- | C] () – C:\WINDOWS\System32\pdclntif.dll
[2008/11/14 22:24:04 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\pdprDlg.dll
[2008/11/14 22:24:04 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\selnt.dll
[2008/11/14 22:24:04 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\IBMMenu.dll
[2008/08/18 19:44:34 | 002,854,912 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2007/01/13 15:03:04 | 000,049,230 | —- | C] () – C:\Documents and Settings\All Users\Application Data\devicemanager.xml.rc4
[2006/07/17 21:30:20 | 000,012,288 | —- | C] () – C:\WINDOWS\impborl.dll
[2006/01/24 01:55:44 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2005/04/27 10:53:10 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\pwdmon.dll
[2005/04/05 20:59:19 | 000,000,000 | —- | C] () – C:\WINDOWS\pcsmig.INI
[2005/04/04 20:42:47 | 000,000,299 | RH– | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/04/04 18:48:45 | 000,024,576 | -H– | C] () – C:\Documents and Settings\Administrator\ntuser.dat.LOG
[2005/04/04 18:48:45 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Administrator\ntuser.ini
[2005/02/17 13:41:32 | 000,000,603 | —- | C] () – C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 13:41:30 | 000,000,593 | —- | C] () – C:\WINDOWS\System32\btcss.dll.manifest
[2003/04/08 01:00:00 | 000,222,928 | —- | C] () – C:\WINDOWS\System32\lobas09.dll
[2003/04/08 01:00:00 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\lotrn13.dll
[2003/04/08 01:00:00 | 000,031,008 | —- | C] () – C:\WINDOWS\System32\ivtrn09.dll
[2003/04/08 01:00:00 | 000,014,928 | —- | C] () – C:\WINDOWS\System32\wingen.drv
[2002/10/15 23:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2002/04/01 18:45:50 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\ODBCMON.DLL
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[1998/10/01 01:00:00 | 001,708,032 | —- | C] () – C:\WINDOWS\System32\MSO97V.DLL
[1997/06/18 01:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/06/18 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL

========== LOP Check ==========

[2010/04/07 07:30:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\704BE10D27FAA9B75D694560B86E588B
[2009/06/30 10:22:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Avaya
[2009/10/19 06:19:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2009/07/13 14:01:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Centra
[2008/11/15 02:48:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/10/16 23:20:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\DAEMON Tools Lite
[2009/09/10 14:29:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ETRADEUK
[2010/02/26 14:11:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Facebook
[2009/10/16 21:40:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\foobar2000
[2009/06/30 16:07:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Foxit
[2009/11/11 10:59:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\gtk-2.0
[2009/07/27 00:28:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Helios
[2008/11/14 22:14:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\IBM
[2009/07/15 02:02:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\iPodder
[2009/06/29 16:47:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Lotus
[2009/08/14 18:43:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Program Files
[2009/06/30 10:22:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\QcWizard
[2009/07/13 14:01:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Saba
[2009/07/21 14:30:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Saba Software
[2009/08/28 00:55:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SharePod
[2010/04/09 10:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\smkits
[2010/02/20 21:24:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Spotify
[2009/12/23 23:54:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Stardock
[2010/04/09 04:30:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\uTorrent
[2009/06/26 01:54:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AGNS
[2009/10/16 23:19:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/11/09 18:46:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2005/04/05 20:53:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IBM
[2009/08/11 16:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IBMERS
[2007/02/20 22:46:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IGS
[2009/06/29 16:52:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lotus
[2009/08/22 17:40:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rosetta Stone
[2009/08/14 19:34:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdBackup
[2010/03/31 14:31:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/06 22:13:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2009/12/23 23:54:42 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{A87EB928-0C6C-4071-AEF1-59E32BAEDF1B}
[2008/07/10 22:57:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{ABCF2613-B074-49B8-8A4C-5EA193A250F6}
[2010/04/08 18:16:58 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/04/09 01:12:00 | 000,000,510 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2010/04/08 19:27:25 | 000,000,316 | —- | M] () – C:\WINDOWS\Tasks\PMTask.job

========== Purity Check ==========


< End of report >
Next up, Extras.Txt:

OTL Extras logfile created on: 09/04/2010 12:07:44 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 32.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 4.45 Gb Free Space | 2.98% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: IBM-9E676F572B2
Current User Name: GB090455
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"IBMconfig" = 1
"FirewallDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Ltd Services – (Rosetta Stone Ltd. )
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone Version 3 Application – (Rosetta Stone Ltd. )

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify AB)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Ltd Services – (Rosetta Stone Ltd. )
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone Version 3 Application – (Rosetta Stone Ltd. )
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0698CECB-9072-47B1-AEA1-94CA350989B8}" = Symantec Client Security
"{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{148E08FF-D7C4-46ED-8D4D-601C67FE0AFD}" = Rosetta Stone Version 3
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav Utility
"{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
"{1CB76495-23DE-4642-B392-C78687804E47}" = IBM Tivoli Storage Manager Client
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = ThinkPad Keyboard Customizer Utility
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2E21CBDA-1EDF-4C18-A561-DB53D683229F}" = AT&T Network Client
"{2EAF7E61-068E-11DF-953C-005056806466}" = Google Earth
"{2FA41EBB-3F5A-35C3-85D6-51EC72A11FBD}" = Google Gears
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D2AF369-6FDD-4243-881C-D8D3DB5B4042}" = Saba Offline Player
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{47ECCB1F-2811-49C0-B6A7-26778639ABA0}" = 32 Bit HP CIO Components Installer
"{4E3B953D-56AB-44DC-BA33-6D0471ADF486}" = VoiceRite Client EMEA 2.4.3
"{4F3AFB85-B972-4621-AEB6-6C22317E145B}" = IBM 32-bit Runtime Environment for Java 2, v5.0
"{53A93780-6073-4207-A729-A99A30AFDE40}" = AFP Workbench for Windows
"{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}" = Adobe Audition 3.0
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65706020-7B6F-41F2-8047-FC69579E386A}" = Presentation Director
"{6855CCDD-BDF9-48E4-B80A-80DFB96FE36C}" = CmdHere Powertoy For Windows XP
"{6928A265-9EED-4F8A-8016-483A4668016A}" = IBM Infoprint Select
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6dde8b21-0510-4cfd-92db-cac94e4e4d0a}" = IBM Lotus Symphony
"{76BC2442-0002-47FA-9617-43BAD82BEF4C}" = Bonjour
"{78225D0F-D12C-09E4-5D6D-A64D763E8982}" = BBC iPlayer Desktop
"{7830CB0F-3AD2-428E-9341-25DE7EAF4E6B}" = E*TRADE Professional V2
"{7D968F83-A23F-40F7-937C-A3B5A0C44048}" = My Help - Workstation Setup Wizard
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{903B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Project Professional 2002
"{90540409-6D54-11D4-BEE3-00C04F990354}" = Microsoft Visio Standard 2002 SR-1 [English]
"{90840409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel Viewer 2003
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{90D451F1-1F43-4AEC-8F24-D11972551D0E}" = GMATPrep™
"{95120000-0052-0409-0000-0000000FF1CE}" = Microsoft Office Visio Viewer 2007
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{996A2FAA-7514-4628-9D12-A8FC34A0016E}" = iTunes
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Power Manager
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2EF91BA-068C-4F6D-B6ED-52D1D272ED8F}" = IBM Lotus Sametime Connect 8.0.2
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}" = T-Mobile Internet Manager
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AEB909AF-6850-4838-B83E-1EB4403B11A9}" = Adobe Photoshop Lightroom 3 Beta 2
"{AED53CDF-1046-4C6B-B5E2-C195125ECDA0}" = Intel® PROSet/Wireless WiFi Software
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5C3B892-0849-476C-9F46-B12F84819D57}" = Apple Mobile Device Support
"{B6EC7388-E277-4A5B-8C8F-71067A41BA64}" = TextPad 5
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CA96F3A1-F350-11D3-B354-002035C150E4}" = ILC
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D178299E-39AE-416E-9E53-B0A3C2586CBA}" = Lotus Notes 8.0.2
"{D564B5E2-CCB5-4A5C-B35E-2FC30BBC9336}" = Adobe Premiere Elements 7.0
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DFF415AC-3883-4338-9365-DDCB74A0CFBA}" = IBM My Help
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F7ED29C4-8FC6-48CF-BEF4-6ADE3E0165CF}" = IBM Personal Communications
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Audition 3.0" = Adobe Audition 3.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
"Atomic Alarm Clock_is1" = Atomic Alarm Clock 5.61
"Autopano Giga" = Autopano Giga
"AviSynth" = AviSynth 2.5
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"Belarc Advisor" = Belarc Advisor 8.1
"CCleaner" = CCleaner (remove only)
"CDCheck" = CDCheck
"CNXT_AUDIO_HDA" = Conexant 20561 SmartAudio HD
"CNXT_MODEM_HDA_HSF" = ThinkPad Modem Adapter
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"Exact Audio Copy" = Exact Audio Copy 0.99pb5
"Fences" = Fences
"Flickr Uploadr" = Flickr Uploadr 3.2.1
"foobar2000" = foobar2000 v0.9.6.9
"Foxit Reader" = Foxit Reader
"HandBrake" = HandBrake 0.9.3
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"IBM Ayudame" = IBM Ayudame
"ie8" = Windows Internet Explorer 8
"InstallShield_{4E3B953D-56AB-44DC-BA33-6D0471ADF486}" = VoiceRite Client EMEA 2.4.3
"InstallShield_{4F3AFB85-B972-4621-AEB6-6C22317E145B}" = IBM 32-bit Runtime Environment for Java 2, v5.0
"IPM Client Migration Utility" = IPM Client Migration Utility
"Juice" = Juice 2.2
"KeyView for Lotus" = KeyView for Lotus 97
"Lexmark_HostCD" = Lexmark Software Uninstall
"LiveUpdate" = LiveUpdate 3.1 (Symantec Corporation)
"Magic ISO Maker v5.5 (build 0276)" = Magic ISO Maker v5.5 (build 0276)
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Marketmaker CFD-FX" = Marketmaker CFD-FX
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MKVtoolnix" = MKVtoolnix 2.9.8
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"myTrack" = myTrack
"NPIF Network Print Information Frontend" = NPIF Network Print Information Frontend
"OnScreenDisplay" = On Screen Display
"P2P GUI" = IBM ISMA Peer-To-Peer
"PM28 Practical Estimating_is1" = PM28 Practical Estimating v1.0
"PM54 Project Management Orientation_is1" = PM54 Project Management Orientation v1.2
"PM55 Risk Management_is1" = PM55 Risk Management v1.0
"Power Management Driver" = ThinkPad Power Management Driver
"PowerISO" = PowerISO
"PremElem70" = Adobe Premiere Elements 7.0
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"ProInst" = Intel PROSet Wireless
"RealPlayer 6.0" = RealPlayer
"Snapshot Viewer" = Snapshot Viewer
"Spotify" = Spotify
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"Trader Workstation 4.0" = Trader Workstation 4.0
"uTorrent" = µTorrent
"Videora iPod Converter" = Videora iPod Converter 5.03
"VLC media player" = VLC media player 1.0.5
"VobSub" = VobSub v2.23 (Remove Only)
"Wdf01000" = Microsoft Kernel-Mode Driver Framework 1.0
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinGimp-2.0_is1" = GIMP 2.6.7
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Workstation Security Tool_is1" = Workstation Security Tool 2.4
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"Trader Workstation" = Trader Workstation

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 08/04/2010 04:40:29 | Computer Name = IBM-9E676F572B2 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 13230453

Error - 08/04/2010 04:40:34 | Computer Name = IBM-9E676F572B2 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 08/04/2010 04:40:34 | Computer Name = IBM-9E676F572B2 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 13236000

Error - 08/04/2010 04:40:34 | Computer Name = IBM-9E676F572B2 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 13236000

Error - 08/04/2010 04:40:36 | Computer Name = IBM-9E676F572B2 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 08/04/2010 04:40:36 | Computer Name = IBM-9E676F572B2 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 13237953

Error - 08/04/2010 04:40:36 | Computer Name = IBM-9E676F572B2 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 13237953

Error - 08/04/2010 04:40:38 | Computer Name = IBM-9E676F572B2 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 08/04/2010 04:40:38 | Computer Name = IBM-9E676F572B2 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 13239968

Error - 08/04/2010 04:40:38 | Computer Name = IBM-9E676F572B2 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 13239968

[ System Events ]
Error - 07/04/2010 04:50:58 | Computer Name = IBM-9E676F572B2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the ldlcserv service.

Error - 07/04/2010 04:51:08 | Computer Name = IBM-9E676F572B2 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460

Error - 07/04/2010 04:51:28 | Computer Name = IBM-9E676F572B2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the ldlcserv6 service.

Error - 07/04/2010 05:08:41 | Computer Name = IBM-9E676F572B2 | Source = Service Control Manager | ID = 7000
Description = The Adobe Active File Monitor V6 service failed to start due to the
following error: %%2

Error - 08/04/2010 13:03:18 | Computer Name = IBM-9E676F572B2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the PolicyAgent service.

Error - 08/04/2010 13:03:18 | Computer Name = IBM-9E676F572B2 | Source = Service Control Manager | ID = 7000
Description = The IPSEC Services service failed to start due to the following error:
%%1053

Error - 08/04/2010 13:06:43 | Computer Name = IBM-9E676F572B2 | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%10048

Error - 08/04/2010 13:07:35 | Computer Name = IBM-9E676F572B2 | Source = DCOM | ID = 10010
Description = The server {7160A13D-73DA-4CEA-95B9-37356478588A} did not register
with DCOM within the required timeout.

Error - 08/04/2010 13:09:11 | Computer Name = IBM-9E676F572B2 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the WZCSVC service.

Error - 08/04/2010 13:14:13 | Computer Name = IBM-9E676F572B2 | Source = Service Control Manager | ID = 7000
Description = The Adobe Active File Monitor V6 service failed to start due to the
following error: %%2


< End of report >
Hi Inzanity, GMER keeps crashing my system so can't post its logs (tried 4 times with varying degrees of success - the first and last gave me the blue screen of death, while the 2nd and 3rd attempts just crashed the program itself). I didn't have anything else running, and had disabled everything apart from my corporate antivirus (Norton). Is there anything I need to do in its place? Many thanks, Mark
Hi,

Can you tell me what exactly is the problem with Chrome?

You have µTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/d/security-centra…-p-id-theft-103

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall µTorrent, via Control Panel -> Add or Remove Programs.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

References for the risk of these programs can be found in these links:
http://www.esecurityguy.com/p2p_file_sharing
http://www.microsoft.com/protect/data/down…ilesharing.aspx

–Next–

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent our tools from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click Advanced mode if not already selected.
  • Choose Yes at the Warning prompt.
  • Expand the Tools menu.
  • Click Resident.
  • Uncheck the Resident TeaTimer (Protection of overall system settings) active. box.
  • In the File menu click Exit to exit Spybot Search & Destroy.
  • Reboot your computer.
    (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.)

–Next–

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

–Next–

Try running GMER again. If it fails try running it in safe mode and check on "Files" on the right hand side to uncheck it before having it run.

–Next–

Please go to VirSCAN
  • Click on Browse.
  • On the File Upload window, copy/paste the text below into the File name box:
    C:\WINDOWS\SW_Win2000X9.DLL
  • Click Submit. Allow the file to be scanned. If it says already scanned – click Reanalyze Now
Repeat the procedure with the following files:
C:\WINDOWS\SW_Win2000X16.DLL
C:\WINDOWS\System32\Primomonnt.dll


Please post the results in your next reply.

–Next–

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :dir
    C:\Documents and Settings\Administrator\Application Data\704BE10D27FAA9B75D694560B86E588B
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

To post in your next reply:
1. The problem with Chrome.
2. Defogger log.
3. GMER log.
4. VirSCAN log.
5. Systemlook log.
Hi, many thanks for your help.

To answer your question about Chrome, it opens the screen but stays blank (see attached screenshot), despite trying to load my home page of google.co.uk. Normally it just stays like that forever, with the loading animation still going, but occasionally it brings up a “this page has become unresponsive” dialogue.

I uninstalled uTorrent, ran Defogger (no errors so no log to include), and followed the instructions you gave.

The only way I could get Gmer to run was if I unticked the “files” box. It continued to crash in every other situation. The output is below:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-11 00:55:44
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pfgyipow.sys


—- System - GMER 1.0.15 —-

SSDT 8593B6B0 ZwConnectPort
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF76C787E]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA8E5F350]
SSDT 858CFD78 ZwQueryValueKey
SSDT 858C1BC8 ZwResumeThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA8E5F580]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device -> \Driver\iastor \Device\Harddisk0\DR0 89C05AC8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00234df246c0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x2A 0xE5 0xF7 0x1F …
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\00234df246c0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x2A 0xE5 0xF7 0x1F …

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\iastor.sys suspicious modification

—- EOF - GMER 1.0.15 —-


As it said “suspicious modification” for the last file, I also uploaded that to VirSCAN, but it didn’t find anything.

I then uploaded the 3 files you mentioned, but they all gave the same “Scanners did not find malware!” result.

Finally, I ran the SystemLook tool, and got the following output:

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 01:23 on 11/04/2010 by GB090455 (Administrator - Elevation successful)

========== dir ==========

C:\Documents and Settings\Administrator\Application Data\704BE10D27FAA9B75D694560B86E588B - Parameters: "(none)"

—Files—
enemies-names.txt –a— 28842 bytes [19:22 06/04/2010] [19:22 06/04/2010]

—Folders—
None found.

-=End Of File=-


Is any of that helpful?!

Thanks again,
Mark
Hi,

Yes, that is very helpful. :)

Did you create this file? If not can you post or tell me what it contains? Thanks.

—Files—
enemies-names.txt –a— 28842 bytes [19:22 06/04/2010] [19:22 06/04/2010]


Let's do another run of SystemLook.
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *iastor*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hi, no, I didn't create it. It contains the following:

[Advertising.com]
Threat="Tracking cookie or cookie of tracking site"
Description="I won't call a saved IP in combination with a log of visited web pages anonymous!"
[Avenue A, Inc.]
Threat="Tracking cookie or cookie of tracking site"
Description="They say they no longer do tracking."
[ClickFinders]
Threat=Tracking cookie or cookie of tracking site
Description=Their cookie itself is a tracking cookie.
[CoreMetrics]
[Enliven]
Threat=Tracking cookie or cookie of tracking site
Description=A unique number and the IP would be enough for me to call it tracking; but to also save search terms is even worse.
[HitBox]
[Bluemountain]
Threat=Tracking cookie or cookie of tracking site
Description=
[Adbureau]
Threat=Tracking cookie or cookie of tracking site
[AllInOneTelcom.HotA]
Threat=Dialer
Description=Above URLs are an example for a company that is using that dialer.
[VLoading]
Threat=Security threat
[InterFun]
Threat=Dialer
Description=Upon clicking 'enter', a window is opened saying 'opening website', while in the background the connection is made.
[TTW]
Threat=Dialer
Description=To activate by phone 25 € per call and 2,50 € per minute. ActiveX install.
[RatedXXX]
Threat=Dialer
Description=Dialer for New Zealand (also international calls to NZ), also hijacker of IE start page.
[Huysuzseks]
Threat=Dialer
Description=Dialer for Australia, Austria, Belgium, Germany, Greece, Italy, Netherlands, Spain, Switzerland, Turkey, UK, US
[MoneyTree]
Description=Page installs multiple dialers. Adds itself to the list of trusted publishers. Could be a Central24 dialer because its certificate contains reference to Central24.
Threat=Dialer
[IBS]
Threat=Dialer
Description=The targeted dialer product is advertised in spam mail. Mail tells reader that 'Claudia' would commit suicide if the user doesn't dial in.
[UnderageHost]
Threat=Browser hijacker
Description=Silently sets itself as IE start- and search pages (furthermore done by a file on every system start), and adds some favourites. Anyone visiting the site that installs it is sick!
[SuperSexPass]
Threat=(Unverified) Browser hijacker
Description=Redirects MSN search for URLs that could not be resolved.
[Amircivil]
Threat=Malware
Description=
[DeskMate.Tahni]
Threat=Trojan
Description=This trojan horse adds itself to systemstart and connects without user consent to the internet.It also downloads other trojan horses and malware like Zlob , SurfSideKick, Smitfraud-C.
[CastGen]
Threat=Trojan
Description=This trojan horse downloads other malware and trojans like ClimaxBucks.InternetOptimizer, Avenue Media and Media-Motor without user consent.
[Win32.Downloader.Wzip32]
Threat=Trojan
Description=This trojan horse poses as Winzip and adds itself as such in the systemstart. It also downloads other malware like ClientMn and Win32.Downloader
[Autodialer]
Threat=Dialer
Description=The dialer builds up an expensive connection to a german provider without informing the user about the fees.
[Axis]
Threat=Dialer
Description=The dialer builds up an expensive connection to a german provider without informing the user about the fees.
[BD Internet Billing]
Threat=Dialer
Description=This dialer tries to establish a connection (foreign call) to a server in australia. The connection gets started in a hidden mode in the background of the system without user permission.
[BTV Industries]
Threat=Dialer
Description=BTV Industries is a company which developes dialer that try to build up an expensive dial up connection without informing the user about possibe fees.
[Cbit-Solutions]
Threat=Dialer
Description=Cbit-solutions is an illegal dialer that tries to establish expensive connections. The user cannot see how expansive these dial-up connection is and so he will not recognize in what danger he could be.
[ConnectMePlus]
Threat=Dialer
Description=This Italian dialer tries to establish an expansive connection without informing the user about the special fees. So the user cannot see how expansive a connection is.
[Consul-Info B.V]
Threat=Dialer
Description=The Consul-Info B.V dialer connects to expensive toll numbers without user awareness.
[Dataline]
Threat=Dialer
Description=Dataline dialer establishes an expensive connection to the USA without informing the user about the special fees.
[DerBiz]
Threat=Dialer
Description=This program installs a data communication connection with which the user connects to its own provider. This causes high tolls. At the same time the program redirects IE to the provider's web site and the user is unable to change the homepage
[Netvision]
Threat=Dialer
Description=The dialer connects to expensive toll numbers without user awareness.
[New Media]
Threat=Dialer
Description=New Media establishes an expensive connection to a 0190 number (EUR 1,98/min) without clearly informing the user.
[One2Bill]
Threat=Dialer
Description=One2Bill establishes an expensive connection to a 0900 number (0900/90001530) without informing the user about the special fees.
[Phonerdial]
Threat=Dialer
Description=The dialer connects to expensive toll numbers without users awareness.
[RST Datentechnik GmbH]
Threat=Dialer
Description=Establishes an expensive connection to 0190 numer (EUR 1,86/min) without users awareness.
[TripleSexoes]
Threat=Dialer
Description=The connects to expensive toll numbers without users awareness.
[VacPro]
Threat=Trojan
Description=This program is a trojan that tracks the user's surfing habits. There are several variants that create a registry entry under the specific name and copy files to the System32 folder.
[WWPack32Dialer]
Threat=Dialer
Description=The dialer connects to expensive toll numbers without users awareness.
[Xgenius]
Threat=Dialer
Description=The Xgenius dialer connects to expensive toll numbers without users awareness.
[Allwebsearcher]
Threat=Hijacker
Description=AllWebSearcher redirects the IE start page to a dangerous website and always reconnects to this particular site.
[Copiloto]
Threat=Hijacker
Description=The Toolbar installs without user consent into the Internet Explorer and there is no way to uninstall it.
[IwantSearch]
Threat=Hijacker
Description=Iwantsearch changes the IE start page to a dangerous website and redirects the user this site all the time.
[Media Access]
Threat=Hijacker
Description=This hijacker installs a toolbar in IE, creates popups with dubious contents and redirects the start page to a dubious search enginge.
[Process Guard Killer 2]
Threat=Hijacker
Description=This program disables known security tools (e.g. ZoneAlarm) thus making the computer more vulnerable and enabling an attack. It can also be used to start and terminate services and to directly access the TaskManager.
[SmileyWorld]
Threat=Hijacker
Description=This hijacker installs an IE toolbar and redirects everything to a very dangerous website
[TargetSearch]
Threat=Hijacker
Description=Targetsearch sets the start page to a dangerous website and and redirects several popular sites to this page (e.g. www.msn.de, www.microsoft.com, www.heise.de)
[TNS-Search]
Threat=Hijacker
Description=This hijacker creates a false security warning when opening IE asking the user to download the latest virus definitions. In consequence, it will install an IE toolbar, redirect the IE start page and creates a lot of icons on the desktop.
[Windowssearch]
Threat=Hijacker
Description=Hijacks the startpage of the Internet Explorer
[Wow Access]
Threat=Hijacker
Description=Wow Access changes the IE start page a dangerous website which cannot be undone.
[Macrosoft]
Threat=Malware
Description=Macrosoft installs itself into the window directory and runs on each system startup using a lot of resources without user consent and without any usefull effect.
[Phynix]
Threat=Malware
Description=Phynix installes itself on the computer and is running in the background using a lot of resources without user consent.
[QDown]
Threat=Malware
Description=Installs itself on the computer and tries to spy on the users surf behaviour. When the computer is connected to the internet the program waits for new orders to harm the computer
[R-Bot]
Threat=Trojan
Description=This trojan copies itself to the System32 folder and removes its download file. Then it tries to connect to the internet and waits for new orders to harm the computer
[NetzAny]
Threat=Browser Hijacker
Description=
[System1060]
Threat=Browser hijacker
Description=Set of files that do everything to appear as system files. Named taskmgr.exe and twunk_64.exe, both even have the original Microsoft description in their properties, but they don't have the original functionality. Instead, they begin phoning home on system start.
[Xupiter]
Threat=Browser hijacker/BHO
Description=A hijacker that comes with it's own IE toolbar.
[RapidBlaster]
Threat=BHO
Description=Runs in background and connects in short intervals to the internet.
[SearchAndBrowse]
Threat=BHO/Hijacker
Description=Installs a new toolbar upon leaving page. %0D%0ASee more information here: http://and.doxdesk.com/parasite/SearchAndBrowse.html
[WebEntrance]
Threat=Hijacker
[FakeWGA]
Threat=Trojan
Description=Disables the Windows firewall, adds itself and a services.exe in Windows\etc\ as services. Both run in background and are registered as autostarting services. They connect to various IPs and wait for incoming TCP and UDP connections.
[Zlob.DVBX11_Bat]
Threat=Trojan
Description=Disguises as the Bat! email client and DVB services.%0D%0ADisables the Windowssecuritycenter and enables the Windows Explorer to pass the Windows Firewall.%0D%0ARuns in backbground and hooks up to winlogon to get started at any Windows boot. As long the file bmtdhh.dll in system32 directory is active, the other files of this trojan are hidden from the WindowAPI (i.e. invisible for most applications including Explorer).%0D%0A%0D%0AIf the file bmtdhh.dll remains active in winlogon, it can recreate some of the other files and settings, to disable the file it is required to reboot windows in minimal alternate shell and rename the file manually.%0D%0AThe filename is static and it is located in the system32 directory.%0D%0A%0D%0AThe Windowssecuritycenter may need to be reinstalled to function properly.
[eUniverse.PowerSearch]
Threat=Trojan
Description=This trojan horse installs in background, connects to the internet in background, does not show up any useful function to the user and downloads other software without user consent.
[CoolWWWSearch.WinRes]
Threat=Hijacker
Description=Part of the CoolWWWSearch hijackers. It installs itself without any permission in background. It hooks itself to the Internet Explorer and redirects its searches and/or homepage to CoolWWWSearch websites, which habor other malware or fraudware.
[CoolWWWSearch.IE-Extension]
Threat=Trojan
Description=An Internet Explorer Browser Helper Object. Changes Zonemaps. The IE-Extension connects to certain Web sites and tries to download malware, every time Internet Explorer is started. Code contains traces of the spyware Vipsearcher, related to the multitudinous and reproductive CWS clan.
[Sallity.Badcro]
Threat=Malware
Description=Sallity.Badcro is a bad MS-Word macro. It copies DLLs to the Windows system folder, and creates an .exe file in the root folder.
[Win32.Small.v]
Threat=Trojan
Description=It creates an Autorun entry ("msbb") in the registry in order to be launched on each Windows startup. It also downloads other objects without giving the user a possibility to stop this process.
[NCast]
Threat=Adware
Description=It installs an Browser Helper Object which is executed every time you run the Internet Explorer. Then it connects to www.ncast.cn, www.ishowbao.com and urlad.cn and displays ads in the Internet Explorer. All that happens without user consent.%0D%0A
[Fake.xpRecovery]
Threat=Malware
Description=It deletes the complete content of the hostfile. Additionally it installs a BHO which is loaded on every Internet Explorer start. Then it connects to many bad pages in the internet and tries to download files
[AdMoke]
Threat=Adware
Description=It installs an BHO wich is executed every time you start the Internet Explorer. It connects to many webpages and tries to download files. It also tries to install a chinese language package. A service is installed to be loaded on every windows startup. All that happens without user consent.
[Ad-Protect]
Threat=Malware
Description=Ad-Protect pretends to be an antispyware solution but actually does not detect any kind of malware. The program's website contains horrifying stories about computers, espionnage etc. urging the user to install Ad-Protect.
[AdSponsor]
Threat=Adware
Description=AdSponsor gets installed on the computer without user consent and advertising popups come up when certain key words are typed.
[HappyToFind.Toolbar]
Threat=Hijacker
Description=This hijacker makes use of security holes and trojans to get installed. When it is installed it displays a toolbar that redirects to malicious websites.
[Kolweb.B]
Threat=Trojan
Description=Kolweb.B copies itself into the system directory of the operating system and tries to connect to the internet. When it is connected it waits for new orders to harm the computer.
[SearchBy]
Threat=Hijacker
Description=The browser start page gets reset to this page if you install Ultimate Popup Killer from their homepage for free. To get rid of it, you have to uninstall Ultimate Popup Killer.
[FreeHQMovies]
Description=Pages installs dialer and hijacks IE to itself.
[Jethomepage]
Threat=Hijacker
[Desktop Detective 2000]
Threat=Keylogger
Description=Stealth, encrypted log file, remote capability.
[Desktop Spy]
Threat=Keylogger
Description=Password protected, stealth mode.
[MDSA Sentinel]
Threat=Keylogger
Description=Stealth, password protected.
[Probot]
Threat=Keylogger
Description=Stealth, password protected, remote functionality, sends log by email..
[SpyCapture]
Threat=Keylogger
Description=Can't be found on website any more.
[SpyPC]
Threat=Keylogger
Description=Warning! Website links to other site.
[WinRecon]
Threat=Keylogger
Description=Stealth, password protected, encrypted logs, sends log as email, network capability.
[Informer]
Threat=Keylogger
Description=Stealth, sends log as mail. Uses the AFP File Monitor & Protector to protect itself against removal. Please boot into safe mode before removing.
[DSO Exploit]
Threat=Security hole
Description=There's a security hole in IE allowing websites to execute code without asking you first. You can find more information at http://security.greymagic.com/adv/gm001-ie/
[BDE Projector]
Threat=Stealth network
Description=According to News.com (http://news.com.com/2100-1023-873181.html), the BDE Software contains technologie that would allow Brilliant Digital to turn every computer with BDE installed into a node of a Brilliant controlled network. Thus Brilliant could use your computer for distributed computing without your knowledge.
[ClickTheButton]
Threat=Spyware
Description=ClickTheButton monitors your visits to shopping sites.
[ClickTillUWin]
Threat=Adware/Spyware/Trojan
Description=Hides itself using the name Explorer.exe. F-Secure lists it as a trojan (http://www.europe.f-secure.com/v-descs/dlder.shtml).
[Cydoor]
Threat=Adware
Description=Cydoor has been using unique user IDs in the past, but is stating to do that no longer.%0D%0AFOR YOUR INFORMATION: It may be illegal and surely is illegitimate to use Cydoor-infected software after you have replaced Cydoor with the dummy. The dummy is only provided so that you may save all your data from the infected software after it has been cleaned; it is strongly suggested that you look for a spyware-free alternative.
[Expedioware]
Threat=Adware
Description=Only possible threat is the continued use of a personal ID (registration number).
[Flyswat]
Threat=Adware/Spyware
Description=Flyswat creates a User ID to every user.
[IE Plugin]
Threat=Spyware/BHO
Description=See Terms Of Use. IMI may change the software at any time and upload it to your computer without your knowledge. It also breaches your security by sending the whole URL to their server whenever it contains one of their keywords.
[Message Mates]
Threat=Adware/Possibly Spyware
Description=This product saves an identifier and keeps track of you like stated in the Privavy statement quoted above. A named feature on AdTools' website is: 'Comprehensive tracking'.
[WMF Exploit.NewYear2006]
Threat=Trojan
Description=connects to the internet and tries to download luckly.exe%0D%0Aalso opens the IE in background and connects it to the internet.%0D%0Aalso installs Fake.Wget Trojan%0D%0Acopies nerodll.exe into systemdirectory and enters the system through exploits like WMF
[Win32.Small.Act]
Threat=Trojan
Description=This trojan copies its dll files to the system folder and runs without user consent
[Yazzle]
Threat=PUPS
Description=This package is frequently installed in background by trojan horses. In most cases it does not run automatically and just lies dormant on the computer.
[Win32.Autoit.E]
Threat=Trojan
Description=Win32.Autoit.E copies a malicious executable file into the system directory, starts itself in autorun as "Task Manager" and "SVCHOST" without giving the user a possibility to cancel that process.
[Pigeon]
Threat=Trojan
Description=Pigeon copies a malicious library file into the system directory without giving the user a possibility to cancel that process.
[AntiLamerBackDoor]
Threat=Trojan
Description=AntiLamerBackDoor enables remote access to the infected computer. It can be remotely controlled to delete data, steal data, send emails and messages, edit the registry, show PC and ICQ passwords and change other OS settings.
[SearchPixieBar]
Threat=Hijacker
Description=SearchPixieBar installs a toolbar into the Internet Explorer without user consent. The SearchPixieBar seems to provide the possibillity to search the web like the Google Toolbar does. But in reality the search option does not work and only advertisement will be displayed.
[FM.Toolbar]
Threat=Hijacker
Description=FM.Toolbar installs a toolbar into the Internet Explorer without user consent. The FM.Toolbar seems to provide the possibillity to search the web like the Google Toolbar does. But in reality the search option does not work and only advertisement will be displayed.
[Fraud.PCHealth]
Threat=Malware
Description=Fraud.PCHealth claims to be an antispyware solution. When it is installed on the computer it shows a lot of harmless cookies, browser helper objects and autorun entries as high risk spyware problems installed by itself. When the user wants to fix these false positives he has to purchase a license.
[Win32.BHO.kv]
Threat=Trojan
Description=Win32.BHO.kv runs in background, installs itself as a browser helper object (BHO) to get started with the Internet Explorer. It also installs a service which starts this trojan horse at system start. It runs in background and connects to its malicious websites.
[AdwarePro]
Threat=Malware
Description=When it is installed AdwarePro detects a lot of entries which are false positives. When the user wants to fix these problems he has to buy a license.
[VisualBreeze]
Threat=Trojan
Description=The trojan downloads several files and installs them into the system directory. It runs in background and tries to get the user's passwords. It also disables the Windows Secuity Center.
[RightMedia]
Threat=Trojan
Description=The web site contains adult content images, movies and messages. Automatically connects to a webserver hosting pornographical content.
[Redtube]
Threat=Malware
Description=The web site contains pornographical images, movies and live cams.
[Win32.Delf.rtk]
Threat=Trojan
Description=This trojan horse installs itself in background. It uses rootkit functions and multiple services to start itself and stay persistent on the users computer.
[IRCBot.svchost]
Threat=Trojan
Description=This trojan horse installs itself in background and pretends to be a system file. It runs in background and connects to malicious IRC channels to receive commands to harm the users computer or use the users computer for a botnet.
[Agent.Clicker]
Threat=Trojan
Description=This trojan horse installs itself in background, it also registers itself to the system start. It runs in background without user notice and connects to its malicious websites.
[Win32.Joleee.K]
Threat=Trojan
Description=Win32.Joleee.K copies a malicious executable file ("services.exe") into the system directory, starts itself in autorun as "services" without giving the user a possibility to cancel that process. Also disables Windows firewall
[Win32.Delf.jl]
Threat=Trojan
Description=Win32.Delf.jl substitutes an original file (c:\Program Files\Internet Explorer\msvcrt.dll) to a malicious faked one. Also copies a malicious relive.dll into the CommonProgrammfiles directory without giving the user a possibility to cancel that process.
[Win32.Delf.gkw]
Threat=Trojan
Description=Win32.Delf.gkw copies an executable file into the system and Windows directories, starts itself in autorun as "Printer", "DriveSystem" and "Spoolsrv" without giving the user a possibility to cancel that process. Also loads and installs BraveSentry, Win32.Agent.gvu, Win32.Qhost.abh, Smitfraud-C., CoolWWWSearch, Virtumonde, Win32.Agent.bfj, Win32.Agent.gvu, Win32.Agent.pz.
[PCCleaner]
Threat=Malware
Description=PCCleaner claims to be an antispyware solution and if it is installed on the computer it flags some entries as malware, which are totally harmless. When the user tries to fix these problems he has to buy a license and so the program tries to frighten users by showing false positives.
[Vegas.Red.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[USA.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[Swiss.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[Slots.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[Sky.Kings.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[Sierra.Star.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[SIA.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[Royal.Dice.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[Prestige.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[Playgate.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[New.York.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[Mega.Sport.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[Mansion.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.
[Magic.Box.Casino.PT]
Threat=PUPS
Description=This online casino uses the PlayTech software which only allows gaming after registration of personal information like surname, name, email address, phone number, birthday, country and currency. Like all PlayTech installers, the installation does not finish with "installation finished" , the software still downloads and installs parts of the online casino in background for several minutes. Boni offers usually mislead users to play for money.

================================================================================
===================

The SystemLook log file reads as follows:

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 13:14 on 11/04/2010 by GB090455 (Administrator - Elevation successful)

========== filefind ==========

Searching for "*iastor*"
C:\cmdcons\iastor.sys –a— 319000 bytes [00:55 26/06/2009] [00:22 26/06/2009] ABFEBC5F846C71AFEBD7F8F6BA740C03
C:\pnp\001\iastor.cat –a— 11215 bytes [00:22 26/06/2009] [00:22 26/06/2009] 3B84F7FECF4AF068C69969FE69DC7534
C:\pnp\001\iastor.inf –a— 8114 bytes [00:22 26/06/2009] [00:22 26/06/2009] AF29B83CF68C2128D89CFAC8720E143F
C:\pnp\001\iastor.PNF –a— 13516 bytes [00:41 26/06/2009] [13:31 10/10/2009] 1D0D4C821113A35913ADA9EACD9B83EB
C:\pnp\001\iastor.sys –a— 319000 bytes [00:22 26/06/2009] [00:22 26/06/2009] ABFEBC5F846C71AFEBD7F8F6BA740C03
C:\WINDOWS\system32\drivers\iaStor.sys –a— 319000 bytes [10:24 13/02/2006] [00:22 26/06/2009] ABFEBC5F846C71AFEBD7F8F6BA740C03

-=End Of File=-


Thanks,
Mark
Hi,

enemies-names.txt is a file by the infection Antimalware Doctor. We'll deal with that later.

Please do the following:
Open a new Notepad session
  • Click the Start button, click Run.
  • In the run box type notepad.
  • click OK.
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all of the text in the code box below into Notepad, Do not copy the word code.

    @ECHO OFF
    copy /y C:\cmdcons\iastor.sys c:\
    
    del %0
  • Click File, Save as…, and set the Save in to your Desktop
  • In the File name box, type fix.bat
  • In the Save as type: box, choose All Files
  • Choose a location to save. Preferably on your desktop.
  • Click Save
It should look like this: [external image: Posted Image]

Double click on fix.bat & allow it to run. A small black box should open and close - this is normal.

–Next–

Run Systemlook again. Let's make sure the batch file run successfully.
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *iastor*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hi, yes it worked. Interesting, so the cmdcons directory is hidden from me (my settings are set to view hidden files). Log attached: SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 12:37 on 12/04/2010 by GB090455 (Administrator - Elevation successful) ========== filefind ========== Searching for "*iastor*" C:\cmdcons\iastor.sys –a— 319000 bytes [00:55 26/06/2009] [00:22 26/06/2009] ABFEBC5F846C71AFEBD7F8F6BA740C03 C:\iastor.sys –a— 319000 bytes [11:35 12/04/2010] [00:22 26/06/2009] ABFEBC5F846C71AFEBD7F8F6BA740C03 C:\pnp\001\iastor.cat –a— 11215 bytes [00:22 26/06/2009] [00:22 26/06/2009] 3B84F7FECF4AF068C69969FE69DC7534 C:\pnp\001\iastor.inf –a— 8114 bytes [00:22 26/06/2009] [00:22 26/06/2009] AF29B83CF68C2128D89CFAC8720E143F C:\pnp\001\iastor.PNF –a— 13516 bytes [00:41 26/06/2009] [13:31 10/10/2009] 1D0D4C821113A35913ADA9EACD9B83EB C:\pnp\001\iastor.sys –a— 319000 bytes [00:22 26/06/2009] [00:22 26/06/2009] ABFEBC5F846C71AFEBD7F8F6BA740C03 C:\WINDOWS\system32\drivers\iaStor.sys –a— 319000 bytes [10:24 13/02/2006] [00:22 26/06/2009] ABFEBC5F846C71AFEBD7F8F6BA740C03 -=End Of File=- Thanks, Mark
Hi,

Print out these instructions to use while in the Recovery Console:
  • Restart your computer.
  • Before Windows loads, you will be prompted to choose which Operating System to start.
  • Use the up and down arrow key to select Microsoft Windows Recovery Console
  • You must enter which Windows installation to log onto. Type 1 and press 'Enter'.
  • At the C:\Windows prompt, type the following bolded entries, and press 'Enter' (note the spaces):

    cd c:\windows\system32\drivers
    ren iastor.sys iastor.old
    copy c:\iastor.sys c:\windows\system32\drivers
    exit


    You should see a message '1 file copied'. If you did not see that message, try again and ensure there is a space after the word copy and another space between the file paths.
    (if you do not see 1 file copied on the screen, even after ensuring the commands are correct, rename the file back to it's original name by typing the following command then hitting Enter.
    ren iastor.old iastor.sys
    you should NOT be prompted to overwrite an existing file, but if you are, select No then type exit to restart and notify me of your results)

  • Type exit and press 'Enter'. Your computer should reboot.

Notify me on how it goes. Thanks.
Hi, it worked. Could you explain what you're doing please? I know my way around a computer, so I understand that you've just copied the iastor.sys from the cmdcons folder to drivers. So do you think the previous one in drivers was infected? What is this cmdcons folder that I can't see? On another note, when I restarted (I hadn't restarted in a while) Symantec gave me a "Cleaning Threats From This Computer" message, and looking in the logs I saw it had attempted to remove "Trojan.Zbot". It prompted me to restart again, asking to complete "remediation tasks", but didn't work ("Symantec Antivirus could not complete remediation tasks"). I don't know if this is the same infection or whether I've somehow picked up another one in the interim? Thanks for this - all much appreciated, Mark
Hi,

We just replaced iastor.sys as it seems it was infected. The cmdcons folder is created when you installed or have Recovery Console in your pc.

Can you post the Symantec log?

–Next–

Let's run another GMER scan with these settings:
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Double click GMER.exe.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.

To post in your next reply:
1. Symantec log.
2. GMER log.
Hi, ok, I can't get GMER to run - I've tried 5 times, disabling as much as I can and never touching the computer, and every time it's blue screened at one point or another. I think, though, that the reason could be that my Symantec Antivirus (10.1.5.5000) keeps enabling itself after I've disabled it. It's a corporate version so I don't know if there's any way round this - I couldn't find anything by googling. I ran another scan last night and it seemed to successfully get rid of whatever it found - the Symantec history shows the following: Trojan.Zbot Reboot Required - Reboot Processing 35 Unavailable File Unavailable IBM-9E676F572B2 IBM-9E676F572B2\GB090455 Infected Unavailable Reboot Required - Delete Reboot Required - Leave alone (log only) Trojan.Zbot Reboot Required - Reboot Processing 35 Unavailable File Unavailable IBM-9E676F572B2 IBM-9E676F572B2\GB090455 Infected Unavailable Reboot Required - Delete Reboot Required - Leave alone (log only) When I right click and "Clean" on either of those, they are no longer present. Do you know of any way to more effectively disable Symantec, if that is the cause of the problems, or an alternative to GMER? Thanks, Mark

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI