This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Phish/Santander.J malware

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello

My Avira antivirus has detected some malware when I go to my Santander bank log in page.
When I request to remove it, it reappears under a different file name. This continues whenever I try to log in.

My Hijack this log is below:

Thanks in advance

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:58:39, on 20/02/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8165 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, neilski

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
Hello there,

Can you provide the file directory of the said malware?

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
===================================================
[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
OTL log
GMER log
Checkup log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
OTL log:

OTL logfile created on: 21/02/2011 15:57:36 - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Neil\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 74.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 169.95 Gb Total Space | 140.86 Gb Free Space | 82.88% Space Free | Partition Type: NTFS
Drive D: | 58.18 Gb Total Space | 17.90 Gb Free Space | 30.76% Space Free | Partition Type: NTFS
Drive H: | 232.88 Gb Total Space | 49.28 Gb Free Space | 21.16% Space Free | Partition Type: NTFS

Computer Name: NEIL-A672D62AD1 | User Name: Neil | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Neil\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Neil\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll (Trusteer Ltd.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (MatSvc) – C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (RapportIaso) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\21923\RapportIaso.sys (Trusteer Ltd.)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (RapportCerberus_19917) – C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys (Trusteer Ltd.)
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (RapportBuka) – C:\WINDOWS\system32\drivers\RapportBuka.sys (Trusteer Ltd.)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (IrBus) – C:\WINDOWS\system32\drivers\irbus.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (gmer) – C:\WINDOWS\system32\drivers\gmer.sys (GMER)
DRV - (PzWDM) – C:\WINDOWS\system32\Drivers\PzWDM.sys (Prassi Technology)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (CamDrL) Logitech QuickCam Pro 3000(CamDrl) – C:\WINDOWS\system32\drivers\Camdrl.sys (Logitech Inc.)
DRV - (se45unic) Sony Ericsson Device 069 USB Ethernet Emulation SEMC45 (WDM) – C:\WINDOWS\system32\drivers\se45unic.sys (MCCI)
DRV - (se45obex) – C:\WINDOWS\system32\drivers\se45obex.sys (MCCI)
DRV - (se45mgmt) Sony Ericsson Device 069 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\se45mgmt.sys (MCCI)
DRV - (se45nd5) Sony Ericsson Device 069 USB Ethernet Emulation SEMC45 (NDIS) – C:\WINDOWS\system32\drivers\se45nd5.sys (MCCI)
DRV - (se45mdm) – C:\WINDOWS\system32\drivers\se45mdm.sys (MCCI)
DRV - (se45mdfl) – C:\WINDOWS\system32\drivers\se45mdfl.sys (MCCI)
DRV - (se45bus) Sony Ericsson Device 069 driver (WDM) – C:\WINDOWS\system32\drivers\se45bus.sys (MCCI)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (avera800) AVerMedia DVB-T BDA Video Capture(A800) – C:\WINDOWS\system32\drivers\avera800.sys (AVerMedia Technologies, Inc.)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (PhilCam8116_XP) Logitech QuickCam Pro 3000(PID_08B1) – C:\WINDOWS\system32\drivers\CamDrL20.sys (Logitech Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3c8e8390-2cf6-11d9-9669-0800200c9a66}:1.3.11
FF - prefs.js..extensions.enabledItems: {a6a33690-2c6a-11d9-9669-0800200c9a66}:1.2.29

FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/20 11:47:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/12/20 11:47:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2011/02/15 11:36:59 | 000,000,000 | —D | M]

[2010/04/14 18:24:59 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Neil\Application Data\Mozilla\Extensions
[2010/04/14 18:24:59 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Neil\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/03/08 22:03:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Neil\Application Data\Mozilla\Extensions\[removed]
[2010/12/06 14:22:53 | 000,000,000 | —D | M] (WebMail) – C:\DOCUMENTS AND SETTINGS\NEIL\APPLICATION DATA\THUNDERBIRD\PROFILES\6S8J91R1.DEFAULT\EXTENSIONS\{3C8E8390-2CF6-11D9-9669-0800200C9A66}
[2010/08/19 08:32:28 | 000,000,000 | —D | M] (WebMail - Hotmail) – C:\DOCUMENTS AND SETTINGS\NEIL\APPLICATION DATA\THUNDERBIRD\PROFILES\6S8J91R1.DEFAULT\EXTENSIONS\{A6A33690-2C6A-11D9-9669-0800200C9A66}

O1 HOSTS File: ([2004/08/10 11:00:00 | 000,000,734 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowRun: 1 = avnotify.exe
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)

========== Files/Folders - Created Within 30 Days ==========

[2011/02/21 10:03:26 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\~1
[2011/02/20 21:56:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\IObit
[2011/02/20 08:55:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Neil\Start Menu\Programs\HiJackThis
[2011/02/19 18:39:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Neil\Start Menu\Programs\Google Chrome
[2011/02/19 18:27:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Neil\Start Menu\Programs\Revo Uninstaller
[2011/02/05 08:55:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/02/05 08:53:57 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/01/28 09:51:06 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2011/01/23 09:29:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Neil\My Documents\ForceField Shared Files

========== Files - Modified Within 30 Days ==========

[2011/02/21 16:03:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/21 16:00:00 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{D7175847-31C0-4205-A548-03632A903D24}.job
[2011/02/21 15:55:36 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/02/21 15:55:00 | 000,000,972 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1003UA.job
[2011/02/21 15:53:23 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/21 15:53:03 | 000,000,310 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2011/02/21 15:52:56 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/21 15:52:55 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1229272821-839522115-1003.job
[2011/02/21 15:52:53 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-823518204-1229272821-839522115-1007.job
[2011/02/21 15:52:27 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/21 15:48:00 | 000,000,980 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1004UA.job
[2011/02/21 15:41:00 | 000,000,980 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1007UA.job
[2011/02/21 12:39:05 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2011/02/21 11:50:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1229272821-839522115-1003.job
[2011/02/21 10:57:03 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/02/21 10:05:22 | 000,098,392 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/02/21 09:55:00 | 000,000,920 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1003Core.job
[2011/02/21 09:41:00 | 000,000,928 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1007Core.job
[2011/02/21 08:51:56 | 000,000,749 | —- | M] () – C:\Documents and Settings\Neil\Desktop\Glary Utilities.lnk
[2011/02/20 22:00:00 | 000,000,382 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag.job
[2011/02/20 08:55:31 | 000,001,982 | —- | M] () – C:\Documents and Settings\Neil\Desktop\HiJackThis.lnk
[2011/02/19 18:39:59 | 000,002,279 | —- | M] () – C:\Documents and Settings\Neil\Desktop\Google Chrome.lnk
[2011/02/19 18:39:59 | 000,002,257 | —- | M] () – C:\Documents and Settings\Neil\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/02/19 18:28:52 | 000,000,815 | —- | M] () – C:\Documents and Settings\Neil\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/19 18:27:59 | 000,000,935 | —- | M] () – C:\Documents and Settings\Neil\Desktop\Revo Uninstaller.lnk
[2011/02/19 17:48:00 | 000,000,928 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1229272821-839522115-1004Core.job
[2011/02/19 10:09:06 | 000,022,926 | —- | M] () – C:\Documents and Settings\Neil\Desktop\Tumour timeline.xlsx
[2011/02/15 09:39:00 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-823518204-1229272821-839522115-1007.job
[2011/02/13 21:46:30 | 000,002,515 | —- | M] () – C:\Documents and Settings\Neil\Desktop\Word 2007.lnk
[2011/02/09 07:52:22 | 000,294,864 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/05 10:13:44 | 000,000,747 | —- | M] () – C:\Documents and Settings\Neil\Application Data\Microsoft\Internet Explorer\Quick Launch\LegalSounds Music Downloader.lnk
[2011/02/05 10:13:44 | 000,000,729 | —- | M] () – C:\Documents and Settings\Neil\Desktop\LegalSounds Music Downloader.lnk
[2011/02/05 08:55:08 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/01/24 16:24:17 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat

========== Files Created - No Company Name ==========

[2011/02/21 10:57:21 | 000,000,103 | —- | C] () – C:\Documents and Settings\Neil\profilingData.log
[2011/02/21 10:10:21 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/02/20 08:55:31 | 000,001,982 | —- | C] () – C:\Documents and Settings\Neil\Desktop\HiJackThis.lnk
[2011/02/19 18:39:59 | 000,002,279 | —- | C] () – C:\Documents and Settings\Neil\Desktop\Google Chrome.lnk
[2011/02/19 18:39:59 | 000,002,257 | —- | C] () – C:\Documents and Settings\Neil\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/02/19 18:27:59 | 000,000,935 | —- | C] () – C:\Documents and Settings\Neil\Desktop\Revo Uninstaller.lnk
[2011/02/05 08:55:08 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/09/24 20:36:03 | 000,002,828 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2009/09/24 20:36:03 | 000,000,008 | RHS- | C] () – C:\Documents and Settings\All Users\Application Data\F39D686D82.sys
[2009/05/18 18:28:25 | 000,000,453 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/01/13 19:07:37 | 000,000,050 | —- | C] () – C:\WINDOWS\bsm.ini
[2008/10/09 10:20:22 | 000,003,072 | —- | C] () – C:\Documents and Settings\Neil\Application Data\dvd.bmk
[2008/04/17 14:30:56 | 000,000,512 | —- | C] () – C:\WINDOWS\_delis32.ini
[2008/01/12 19:19:23 | 000,585,791 | —- | C] () – C:\WINDOWS\gmer.dll
[2007/11/10 13:12:23 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2007/08/25 13:58:45 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2007/06/05 08:25:12 | 000,000,251 | —- | C] () – C:\Program Files\wt3d.ini
[2007/04/28 08:23:39 | 000,130,048 | —- | C] () – C:\Documents and Settings\Neil\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/06 13:18:27 | 000,000,154 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/01/03 10:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 10:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 10:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/13 09:18:43 | 000,000,052 | —- | C] () – C:\WINDOWS\PMXUPL~1.INI
[2006/12/07 21:45:56 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/05 22:38:42 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/11/21 16:03:56 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/11/21 15:52:05 | 000,000,952 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/11/21 13:55:13 | 000,000,306 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/11/20 16:58:46 | 000,000,127 | —- | C] () – C:\Documents and Settings\Neil\Local Settings\Application Data\fusioncache.dat
[2006/11/20 10:51:09 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/11/29 00:11:07 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/05 14:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[1999/01/27 12:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/11/10 14:18:48 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2009/05/15 09:49:29 | 000,000,209 | -HS- | M] () – C:\boot.ini
[2010/12/20 13:01:50 | 000,000,000 | —- | M] () – C:\cookiesnew.txt
[2006/11/20 15:43:52 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/04/17 14:30:23 | 000,000,183 | —- | M] () – C:\LogiSetup.log
[2006/11/20 15:43:52 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 11:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/05/20 09:32:11 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/02/21 15:52:21 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2008/01/07 12:12:04 | 000,000,186 | —- | M] () – C:\picsetup.log
[2010/09/12 21:59:26 | 000,000,106 | —- | M] () – C:\pmt.dat
[2009/08/11 20:28:10 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/08/13 21:39:23 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/08/14 23:43:06 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/08/21 20:11:23 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/08/21 20:11:50 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/08/26 13:56:14 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/09/06 00:35:09 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/09/06 21:41:48 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/05/26 21:13:37 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/05/27 22:01:39 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/06/02 21:10:46 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/06/07 21:31:13 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/06/08 13:45:16 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/06/10 07:10:36 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/06/20 21:54:16 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/06/21 15:19:53 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/07/08 21:16:28 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/07/14 11:59:38 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/08/04 21:30:26 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/08/11 07:41:12 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/08/21 20:11:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/08/21 20:11:50 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/08/26 13:56:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/09/06 00:35:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/09/06 21:41:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/05/26 21:13:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/05/27 22:01:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/06/02 21:10:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/06/07 21:31:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/06/08 13:45:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/06/10 07:10:36 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/06/20 21:54:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/06/21 15:19:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/07/08 21:16:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/07/14 11:59:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/08/04 21:30:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/08/11 07:41:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/08/11 20:28:10 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/08/13 21:39:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/08/14 23:43:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/11/20 15:43:18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2007/06/05 08:25:12 | 000,000,251 | —- | M] () – C:\Program Files\wt3d.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/20 10:49:24 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/11/20 10:49:24 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/11/20 10:49:24 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/05/20 09:40:50 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/11/21 12:10:24 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Neil\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/11/21 12:10:23 | 000,000,079 | —- | M] () – C:\Documents and Settings\Neil\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2010/04/10 15:16:12 | 000,000,786 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-18 07:14:24

< End of report >

Gmer:

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-02-21 17:53:05
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 SAMSUNG_SP2504C rev.VT100-48
Running: gmer.exe; Driver: C:\DOCUME~1\Neil\LOCALS~1\Temp\kwnyifod.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwAssignProcessToJobObject [0xA9174FE4]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwConnectPort [0xA920B534]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwCreateFile [0xA9175996]
SSDT BA7BC2D6 ZwCreateKey
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreatePort [0xA920BCC0]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcess [0xA921EEB4]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0xA921F2A2]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateSection [0xA9228916]
SSDT BA7BC2CC ZwCreateThread
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xA920BDF6]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwDeleteFile [0xA9175AF6]
SSDT BA7BC2DB ZwDeleteKey
SSDT BA7BC2E5 ZwDeleteValueKey
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0xA921DDF0]
SSDT BA7BC2EA ZwLoadKey
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xA9226B44]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwOpenFile [0xA9175A5A]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenProcess [0xA92211CE]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenThread [0xA9220DF8]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwProtectVirtualMemory [0xA917544C]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwQueryValueKey [0xA9179476]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwRenameKey [0xA91793E0]
SSDT BA7BC2F4 ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xA920B0F4]
SSDT BA7BC2EF ZwRestoreKey
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0xA920B7DC]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwSetContextThread [0xA9174F8A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwSetInformationFile [0xA9175B56]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSecurityObject [0xA9227E12]
SSDT BA7BC2E0 ZwSetValueKey
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwSuspendThread [0xA9174F26]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0xA921FF0A]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwTerminateProcess [0xA921FC86]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (RapportPG/Trusteer Ltd.) ZwTerminateThread [0xA9174EC2]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2C9C 80504538 12 Bytes [C0, BC, 20, A9, B4, EE, 21, …]
.text ntkrnlpa.exe!ZwCallbackReturn + 2D6C 80504608 8 Bytes JMP 44BA7BC2
init C:\WINDOWS\system32\drivers\PzWDM.sys entry point in "init" section [0xBA4BC30E]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[380] ntdll.dll!KiUserApcDispatcher 7C90E450 5 Bytes JMP 004397C0 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (RapportService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[380] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 716B0022
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[380] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 71680022
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[380] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 716E0022
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1188] ntdll.dll!KiUserApcDispatcher 7C90E450 5 Bytes JMP 00414C10 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1188] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 716B0022
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1188] USER32.dll!GetGUIThreadInfo + FB 7E428023 6 Bytes JMP 716E001E
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1188] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 71650022
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1188] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 71680022
.text C:\WINDOWS\system32\SearchIndexer.exe[2352] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00F21B19 C:\WINDOWS\system32\mssrch.dll (mssrch.lib/Microsoft Corporation)
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] ntdll.dll!KiUserApcDispatcher 7C90E450 5 Bytes JMP 01537420 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.)
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] ntdll.dll!LdrLoadDll + 1 7C91632E 5 Bytes [22, 00, 68, 71, C3]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] kernel32.dll!ReadFile 7C801812 6 Bytes JMP 7139000A
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 716B0022
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] kernel32.dll!CloseHandle 7C809BE7 6 Bytes JMP 7148000A
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] kernel32.dll!GetQueuedCompletionStatus 7C80A7BD 6 Bytes JMP 714B000A
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] kernel32.dll!WriteFile 7C810E27 6 Bytes JMP 7142000A
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] kernel32.dll!CreateNamedPipeW 7C82F0DD 6 Bytes JMP 713F000A
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] kernel32.dll!CancelIo 7C8300E2 6 Bytes JMP 7145000A
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] kernel32.dll!CreateIoCompletionPort 7C83138D 6 Bytes JMP 713C000A
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 6 Bytes PUSH 71590022; RET
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] USER32.dll!TranslateMessage 7E418BF6 6 Bytes PUSH 71500022; RET
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] USER32.dll!RegisterClassExW 7E41AF7F 6 Bytes PUSH 716E0022; RET
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] USER32.dll!SetWindowLongW 7E42C2BB 6 Bytes PUSH 71530022; RET
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] USER32.dll!GetClipboardData 7E430DBA 6 Bytes PUSH 71560022; RET
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] GDI32.dll!BitBlt 77F16F79 6 Bytes PUSH 715F0022; RET
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] GDI32.dll!StretchDIBits 77F1B0AE 6 Bytes PUSH 715C0022; RET
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 6 Bytes PUSH 71650022; RET
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 714D0022
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2980] CRYPT32.dll!CertVerifyCertificateChainPolicy 77A9B76F 6 Bytes PUSH 71620022; RET
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90ED1A
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90ED8B
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EEB9
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3896] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90ED1A
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90ED8B
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EEB9
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4072] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]

—- Devices - GMER 1.0.15 —-

Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\Udp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\RawIp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
Device \FileSystem\Fastfat \Fat A55A3D20

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-

Checkup:

Results of screen317's Security Check version 0.99.8
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
Avira AntiVir Personal - Free Antivirus
ZoneAlarm
Antivirus out of date! (On Access scanning disabled!)
```````````````````````````````
Anti-malware/Other Utilities Check:

WinPatrol 2007 (Outdated! Latest version is WinPatrol 2009)
Malwarebytes' Anti-Malware
HijackThis 2.0.2
CCleaner
Java™ 6 Update 22
Out of date Java installed!
Adobe Flash Player 10.1.53.64
Adobe Reader 8.2.6
Out of date Adobe Reader installed!
Mozilla Thunderbird (3.1.7)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Windows Defender MSASCui.exe
WinPatrol winpatrol.exe is disabled!
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Windows Defender MsMpEng.exe
Windows Defender MSASCui.exe
Zone Labs ZoneAlarm zlclient.exe
``````````End of Log````````````


Hope this is all you need
Could you provide the report from Avira? I would like to take a look.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • Look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

On your next reply please post :
Avira report
MBAM log
ESET report


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Here's the Avira reports Type: File Source: C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_00010d Status: Infected Quarantine object: 4f04c79f.qua Restored: NO Uploaded to Avira: NO Operating System: Windows 2000/XP/VISTA Workstation Search engine: 8.02.04.170 Virus definition file: 7.11.03.165 Detection: Contains recognition pattern of the PHISH/Santander.J phishing file/email Date/Time: 21/02/2011, 13:20 Type: File Source: C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_00010d Status: Infected Quarantine object: 5793e820.qua Restored: NO Uploaded to Avira: NO Operating System: Windows 2000/XP/VISTA Workstation Search engine: 8.02.04.170 Virus definition file: 7.11.03.165 Detection: Contains recognition pattern of the PHISH/Santander.J phishing file/email Date/Time: 21/02/2011, 13:20 Type: File Source: C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_00021a Status: Infected Quarantine object: 562e052f.qua Restored: NO Uploaded to Avira: NO Operating System: Windows 2000/XP/VISTA Workstation Search engine: 8.02.04.170 Virus definition file: 7.11.03.164 Detection: Contains recognition pattern of the PHISH/Santander.J phishing file/email Date/Time: 20/02/2011, 21:45 Type: File Source: C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_00021a Status: Infected Quarantine object: 4eb92a90.qua Restored: NO Uploaded to Avira: NO Operating System: Windows 2000/XP/VISTA Workstation Search engine: 8.02.04.170 Virus definition file: 7.11.03.164 Detection: Contains recognition pattern of the PHISH/Santander.J phishing file/email Date/Time: 20/02/2011, 21:45 Type: File Source: C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000206 Status: Infected Quarantine object: 4eb92686.qua Restored: NO Uploaded to Avira: NO Operating System: Windows 2000/XP/VISTA Workstation Search engine: 8.02.04.170 Virus definition file: 7.11.03.164 Detection: Contains recognition pattern of the PHISH/Santander.J phishing file/email Date/Time: 20/02/2011, 21:28 Type: File Source: C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_000206 Status: Infected Quarantine object: 562e0939.qua Restored: NO Uploaded to Avira: NO Operating System: Windows 2000/XP/VISTA Workstation Search engine: 8.02.04.170 Virus definition file: 7.11.03.164 Detection: Contains recognition pattern of the PHISH/Santander.J phishing file/email Date/Time: 20/02/2011, 21:28 Here's the Malwarebytes log: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5838 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 22/02/2011 09:05:07 mbam-log-2011-02-22 (09-05-07).txt Scan type: Quick scan Objects scanned: 172904 Time elapsed: 6 minute(s), 2 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Here's the EST scan result: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=ed7a8ddf0d68c84ea51fc0ffd7d589c0 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-02-22 11:05:23 # local_time=2011-02-22 11:05:23 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 103429315 103429315 0 0 # compatibility_mode=1536 16777215 100 0 0 0 0 0 # compatibility_mode=1797 16775141 100 93 268634 34899918 64781 0 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 3812 3812 0 0 # compatibility_mode=9217 16777194 100 70 5523672 14949668 0 0 # scanned=101267 # found=0 # cleaned=0 # scan_time=5795

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI