Lenovo G400 Bluetooth Driver infected with Virus

i am using a lenovo G400 notebook since last 4 months and wasn't able to install the bluetooth driver.
recently i formatted my laptop and downloaded the driver for fresh installation.
The driver got installed but the bluetooth wasn't working and it was reporting "device not found"
then i updated my Antivirus from net, NOD32 antivirus and it reported that the bluetooth driver contains a trojan.
i checked the downloaded installation file and it too had trojan.
here is the repost of threat generated
"Time    Module    Object    Name    Threat    Action    User    Information
2/9/2008 21:32:28 PM    AMON    file    C:\WINDOWS\system32\BtWizard.dll    probably a variant of Win32/Genetik trojan    quarantined - deleted    NT AUTHORITY\SYSTEM    Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe. The file was moved to quarantine. You may close this window.
Time    Module    Object    Name    Threat    Action    User    Information
2/9/2008 21:27:52 PM    AMON    file    C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe    probably a variant of Win32/Genetik trojan    quarantined - deleted    NT AUTHORITY\SYSTEM    Event occurred on a file modified by the application: C:\WINDOWS\system32\msiexec.exe. The file was moved to quarantine. You may close this window.
please help me with this problem
and if anyone is having similar problem please report.
Regards
Tarun
[email protected]

i find other AV to be ineffective..
and NOD32 is a famous av..
also few more logs
Time    Module    Object    Name    Threat    Action    User    Information
2/3/2008 14:33:10 PM    Kernel    file    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe    probably a variant of Win32/Genetik trojan           
2/3/2008 14:33:01 PM    Kernel    file    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe    probably a variant of Win32/Genetik trojan           
2/3/2008 14:32:27 PM    Kernel    file    c:\program files\intel\wireless\bin\s24evmon.exe    probably a variant of Win32/Genetik trojan           
2/3/2008 14:32:16 PM    Kernel    file    c:\program files\intel\wireless\bin\evteng.exe    probably a variant of Win32/Genetik trojan           
its of wireless drivers..

Similar Messages

  • Bios protection from infection with virus or bios recovery of Lenovo Thinkpad Edge e545

    I have Lenovo Thinkpad Edge e545 laptop. Among downloads there are no bios images but only backup cd iso file. Does laptop bios somehow protected from beeing infected with virus when OS installed on laptop is infected? If not, is there a way to recover bios from usb flash? Or is there some other way to recover already infected bios without help of technical support center?  

    Dear Wyacheslav1
    Welcome in lenovo community
    Actually there is no relationship between the Virus and the BIOS also the BIOS cannot be infected such as the windows . So if you have any debut that your machine has been attacked by a Virus, you can install any antivirus application to scan for this virus and to protect the machine from such attack 
    Thanks
    Alaa

  • My Mac Book Pro says it has been infected with viruses. How do I clean them up?

    My Macbook Pro says it has been infected with viruses. How do I clean it up?

    There are different variants of names for this malware but the steps of removal should be the same unless it has advanced.
    http://www.securemac.com/MAC-Defender-Rouge-Anti-Virus-Analysis-Removal.php
    https://discussions.apple.com/thread/3032201?start=0&tstart=0
    https://discussions.apple.com/thread/3042885?start=0&tstart=0
    http://www.reedcorner.net/news.php/news.php?s=macdefender

  • Can a PC infected with virus make breaches if Time Capsule firewall?

    Hello!
    Recently had my PC (not mac) infected with virus. Is there a possibility that viruses can make changes to Time Capsuel settings andmake breaches in Time Capsuel firewall?
    For example set port mapping via UPnP  for viral activity on TC or something like that? I'm not very fond of network technologies - but know that some programs can set routing ports on their own. Or am I mistaken?
    Maybe it is worth to make a full reset for TC? I dont know.

    Alejandro_64 wrote:
    But any bother needs open ports to be able to use planted virus behind the firewall, right?
    This will not happen very often.. NAT is a not strictly a firewall. It can be broken under pretty intensive attack but still seldom happens. The virus gets into the computer via YOU.. you browse to a compromised website or download an infected application or email etc. The vast majority of infected computers cannot actually be prevented by firewalls.. unless as John pointed out, you cut yourself off from the internet. The internet is out there and for you to gain access to it, to some degree it has to have some access to you. But YOU are the one who infects the computer in 99% of cases.
    Once infected the computer on a LAN can infect other computers on the LAN.. because people do not password their shares. There is little protection. And from inside the LAN the virus can then call home. It does not do anything to the router. Because you have to have the ability to open ports from the LAN side the virus can take advantage of that.
    Note in a business with a strong firewall, only a very limited number of ports are available. And there is a lot more effort put into virus checking. For home system.. just NAT and NOT downloading suspect apps and emails will keep you pretty clear of problems with the need for a decent AV for the occasional mistake.
    Do not torrent, do not use USENET, do not go to Warez and suspect places. Download Prawn and you will have your computer loaded with viruses in no time. It is free and available but has a big sting in the tail.
    If you want to do all those things.. well plan on getting infected pretty often and use the computer in proper DMZ and wipe it pretty often.

  • My mac is infected with viruses, Safari can not normally search for constantly appear commercials and some unknown site. What to do? antivirus free program that you recommend?

    my mac is infected with viruses, Safari can not normally search for constantly appear commercials and some unknown site. What to do? antivirus free program that you recommend?

    You may have installed the "VSearch" trojan, perhaps under a different name. Remove it as follows.
    Malware is constantly changing to get around the defenses against it. The instructions in this comment are valid as of now, as far as I know. They won't necessarily be valid in the future. Anyone finding this comment a few days or more after it was posted should look for more recent discussions or start a new one.
    Back up all data before proceeding.
    Step 1
    From the Safari menu bar, select
              Safari ▹ Preferences... ▹ Extensions
    Uninstall any extensions you don't know you need, including any that have the word "Spigot," "Trovi," or "Conduit" in the description. If in doubt, uninstall all extensions. Do the equivalent for the Firefox and Chrome browsers, if you use either of those.
    Reset the home page and default search engine in all the browsers, if it was changed.
    Step 2
    Triple-click anywhere in the line below on this page to select it:
    /Library/LaunchAgents/com.vsearch.agent.plist
    Right-click or control-click the line and select
              Services ▹ Reveal in Finder (or just Reveal)
    from the contextual menu.* A folder should open with an item named "com.vsearch.agent.plist" selected. Drag the selected item to the Trash. You may be prompted for your administrator login password.
    Repeat with each of these lines:
    /Library/LaunchDaemons/com.vsearch.daemon.plist
    /Library/LaunchDaemons/com.vsearch.helper.plist
    /Library/LaunchDaemons/Jack.plist
    Restart the computer and empty the Trash. Then delete the following items in the same way:
    /Library/Application Support/VSearch
    /Library/PrivilegedHelperTools/Jack
    /System/Library/Frameworks/VSearch.framework
    ~/Library/Internet Plug-Ins/ConduitNPAPIPlugin.plugin
    Some of these items may be absent, in which case you'll get a message that the file can't be found. Skip that item and go on to the next one.
    This trojan is distributed on illegal websites that traffic in pirated content. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect much worse to happen in the future.
    You may be wondering why you didn't get a warning from Gatekeeper about installing software from an unknown developer, as you should have. The reason is that this Internet criminal has a codesigning certificate issued by Apple, which causes Gatekeeper to give the installer a pass. Apple could revoke the certificate, but as of this writing, has not done so, even though it's aware of the problem. This failure of oversight has compromised both Gatekeeper and the Developer ID program. You can't rely on Gatekeeper alone to protect you from harmful software.
    *If you don't see the contextual menu item, copy the selected text to the Clipboard by pressing the key combination  command-C. In the Finder, select
              Go ▹ Go to Folder...
    from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.

  • Firefox infected with virus (searchq)

    My browser (firefox) has been infected with a virus searchq through jzip and I seem to have successfully removed it from my files etc but it has attached itself to my homepage and into mozilla files but not allowing me to remove it and can not default back to google - my IE browser and chrome have no problems but I prefer firefox so I uninstalled all firefox files from my program files and control panel and tried to reinstall but searchq is still there. Can I remove firefox completely to start again? Ive tried to google this but there seems to be a consensus on forums that you can not remove it permanently. There seems no other way of getting searchq off my pc if this is the case.

    Thanks - I finally found a thread that sorted it out (been at it for over a week) it was under TOOLS>OPTIONS>GENERAL show my homepage and I can restore to default. I had tried to change it under control panel and remove all files, remove all addons under extensions....Cant find the thread link now on here but it was on this forum. Many thanks

  • Main Computer infected with virus

    My Son has a Dell running Windows XP2 Home Edition. Fortunately he has not connected his ipod since the virus appeared. The dell is in the shop but is an old unit and the virus cannot be cleaned without a system complete restore to original. I have purchased a new Vista for his school work. If we assume his old computer is dead or may possibly infect the ipod if he plugs it into the old computer.Is there a way to transfer all his music on the ipod 30G to the new computer without any change requiring connecting back to the old computer. (example Apple says to change auto to manual on old computer then transfer)
    Thanks for any suggestions.

    If you are using iTunes version 7 or later, then you can transfer purchased iTunes store music from the iPod to an authorized computer by using the "file/transfer purchases from iPod" menu. Note that the maximum of 5 authorized computers applies here.
    For all other non purchased music (your own CDs etc) try this method which works on some Windows PCs.
    Enable your iPod for disk use.
    See: iPod Disk Use.
    Open iTunes and select edit/preferences/advanced/general. Put a check mark in the box marked "copy files to iTunes music folder when adding to library" and also "keep iTunes music folder organized", then click 'ok'.
    Connect the iPod whilst holding down the shift/ctrl keys to prevent any auto sync, and if you see the dialogue window asking if you want to sync to this itunes library, click 'no'.
    Then go to file/add folder, open 'my computer', select your iPod and click 'ok'.
    The music files should transfer to your iTunes.
    If this doesn't work (and it may not because officially it's not supposed to), check out the instructions/suggestions here.
    Music from iPod to computer (using option 2). This a manual method using "hidden folders" and although it works, it can be messy.
    Much easier ways are to use one of the many 3rd party programs that copy music from the iPod to the computer.
    One of the most recommended is Yamipod. This is a free program that transfers music from iPod back to the computer. However, it does not transfer playcounts/ratings etc.
    Another free program is Pod Player.
    If you want to recover just the structure of playlists from the iPod (and not the actual song files themselves), there's iRepo for Windows. which I understand has this feature along with all the standard features for these programs.
    There is also CopyTrans. This does preserve ratings/playcounts etc if those are important to you but this program is not free. It also supports video transfer.
    All Vista compatible.

  • My laptop downloading Firefox 4 automatically and then it got infected with viruses when I went to net so what should I do???

    Laptop doesnt allow access to net now. I am running Windows 7 starter on a Dell netbook. I get popup message for Windows virus remover and request to enter credit card info. All attempts to access websites using Firefox fail as this pop up message is repeated.
    I have never had a problem with Mozilla open source products until this time when my netbook automatically upgraded to Firefox version 4. I was in Europe at the time.

    Hey allan. I dont know. Nothing seems to change. I still dont have net connection. Im at a net shop right now. (Not using mac.)  What will happen to the OSX Lion that I payed for? The icon was gone. Im still in the middle of downloading it.

  • 6600 infected with virus?

    My 6600 keeps on showing me a warning: "message sending failed" or something like that, altough I'm not sending any messages. Any sugestions? Thanks

    Tonight I think I found out what was hapenning. My phone is trying to send a "happy birthday" MultimediaMeSsage to a couple of numbers that are not in my contacts. This type of behaviour is supposed to be the behaviour of a infected Nokia 6600(at least that is what I've read on the internet).
    Anyway, I've found an antivirus software provided by the Symantec corporation: "Symantec Mobile Threats Removal Tool 1.0.3" that is supossed to get me rid of this virus.
    Hopefully it will work.
    Thanks

  • Safari and pop-up window saying computer is infected with virus

    Hello,
    I'm ... "hoping"...this was just scareware stuff - but I was on safari and clicked on a link off of google when I got a pop-up that said my computer has been infected. I think another window popped up and I clicked cancel - and kept on clicking cancel...it kept popping up and I'd click cancel - finally about after say 5 times closing the popup - the original popup was there. I don't think it gave me a choice to cancel...it was like continue or some other choice.
    At any rate what appeared next was what looked like file folders and perhaps a scan bar or progress bar and a bunch of stuff about viruses detected. I panicked and quickly just closed the window as quick as possible and now can't even really recall what I saw.
    I honestly didn't do anything other than click on a link. So I can't imagine I really did anything. Can you get into trouble just from clicking on a link?? Is there a way to tell if I really did anything? Has anyone else had this happen and know it is either a concern or just scareware??
    Any suggestions?
    Should I be concerned??
    Thanks!!

    Hi
    No virus out there affects a Mac directly. Best way to eliminate these intrusive panels is to add DNS server codes to your System preferenes>Network panel.
    To do so, open the panel, click on your Internet connection on the left, then select "advanced". In the DNS panel copy/paste these openDNS codes on separate lines: 208.67.222.222 and 208.67.220.220. Then, select OK, then "apply".
    Restart Safari.
    In Safari, open Safari Preferences>Security>Show Cookies. In the spotlight panel, type the name of the website triggering the warning. Remove any cookies that appear.
    Lastly, in the Safari Menu, select "empty cache".
    That ought to clean up the problem.

  • Does mac can be infected with virus?

    i've been browsing using firefox and suddenly there is an alert that my mac is infected.. then it prompts to scan and asked to remove the infected applications.. i did not proceed to remove it and just close the windows.. is this true?

    i did not proceed to remove it and just close the windows.
    Hopefully you did not make any purchases, give out your billing information?
    Anytime you see an offer such as that, quit your browser. You can always relaunch your browser.
    It's just an ad trying to get you to purchase security software you do not need.
    Never accept unsolicited offers from the internet.

  • Mac infected with Virus

    Hello
      When I was watching videos on Youtube yesterday, my mouse suddenly moved itself. I paused the video and just watched the mouse and it suddenly just moved. I did not touch the mouse at all and it was dragging and moving. It annoys me and when I try searching the problem up at Google, whichever word I type just gets deleted . The virus prevents me from typing. I closed even the network connections and it still moves by itself. I downloaded VirusBarrier (Free) and scaned and can't find any problems. Right now, it is okay and everything is under control BUT just just in this week, I have experienced 3 times of my computer going the "grey screen of death". It all started yesterday and I experienced a grey screen yesterday. I experienced the grey screen twice today and I feel like it is the virus doing all these. Thank you!

    I have experienced 3 times of my computer going the "grey screen of death"
    The gray screen is not caused by a virus or malware so you can rule that out. And insatlling Virus Barrier may even compound the issue.
    Uninstall Virus Barrier by following the instructions here >  http://oit.ncsu.edu/antivirus/uninstall-intego-virusbarrier/
    Then try troubleshooting >   Mac OS X: Gray screen appears during startup

  • Am I infected by virus? Please help me~

    Dear friends,
    When I online yesterday, I used the Microsoft msn (Mac version) to chat with friends and received a link from my friend. The link said that there are pictures of us in an earlier function. Because we actually had a function the day before I received it. Hence, after I accepted the file transfer, I stopped it as I am afraid of virus in the middle of the transfer...
    Today my friend (he is using windows not Mac) tells me his msn is infected with virus and send the above messages to friends in his contact list unstoppedly and seemingly it is spreading the virus...
    Do u think I will be infected by the virus? Or the Mac is immuned? How can I check for virus infection? How can I remove the virus if infected?
    Pls help help help!!!
    For your information, I do not use any of the BootCamp. Parallel Desktop or VM and not install Windows in my Mac.
    What should I do? I tried to search in the finder for the.exe file or.dll file but none is there. I entered "*.exe" and "*.dll" as searches. Is it correct to search in this way? If not, could u please kindly advise the appropriate way? I love the new Mac very much and don't want it to be infected...
    Beg for your help please.

    As mentioned earlier, there are no known viruses in the wild for OSX. That is not to say you shouldn't use common security practices, such as not running from an administrator user account, only download from trusted sites, and not installing anything unless you know what it is. Even if you don't run Windows, it is possible to pass infected files to other Windows users - in that case, the freeware ClamXav is a popular virus checker.

  • [REQUEST] rtl8723au_bt bluetooth driver for lenovo yoga 13

    Hello.
    I have a lenovo yoga 13 laptop with 8723 wireless card.
    Wifi is working bacause of dkms-8723au-git package. As I know, in 3.15 kernel it will work out of the box and lwfinger will no longer maintain this source code.
    Bluetooth is not working and there is no bluetooth driver in aur. It is required to install another package from here https://github.com/lwfinger/rtl8723au_bt.
    I cannot build this package, because when I run make command it ends with error make[1]: *** /lib/modules/3.14.4-1-ARCH/build: No such file or directory. Also there was written about no dkms support in code. But I cannot fix it, because I am still noob in Archlinux. And for some reason it is written "Support kernel version 2.6.32~3.13.0" in readme.txt. I have already 3.14.4-1-ARCH kernel.
    Could anyone help me to fix that and make aur package for other people to get  bluetooth work on lenovo yoga 13?

    I think bluez5 is ok, because when I run bluetoothctl it can detect my cluetooth controller now. However, I cannot start working with it
    [ndr@yoga ~]$ sudo bluetoothctl
    [sudo] password for ndr:
    [NEW] Controller 2C:D0:5A:DF:60:07 yoga [default]
    [bluetooth]# help
    Available commands:
    list List available controllers
    show [ctrl] Controller information
    select <ctrl> Select default controller
    devices List available devices
    paired-devices List paired devices
    power <on/off> Set controller power
    pairable <on/off> Set controller pairable mode
    discoverable <on/off> Set controller discoverable mode
    agent <on/off/capability> Enable/disable agent with given capability
    default-agent Set agent as the default one
    scan <on/off> Scan for devices
    info <dev> Device information
    pair <dev> Pair with device
    trust <dev> Trust device
    untrust <dev> Untrust device
    block <dev> Block device
    unblock <dev> Unblock device
    remove <dev> Remove device
    connect <dev> Connect device
    disconnect <dev> Disconnect device
    version Display version
    quit Quit program
    [bluetooth]# version
    Version 5.19
    [bluetooth]# power on
    Failed to set power on: org.bluez.Error.Blocked
    [bluetooth]# list
    Controller 2C:D0:5A:DF:60:07 yoga [default]
    [bluetooth]# devices
    [bluetooth]# show
    Controller 2C:D0:5A:DF:60:07
    Name: yoga
    Alias: yoga
    Class: 0x000000
    Powered: no
    Discoverable: no
    Pairable: yes
    UUID: PnP Information (00001200-0000-1000-8000-00805f9b34fb)
    UUID: Generic Access Profile (00001800-0000-1000-8000-00805f9b34fb)
    UUID: Generic Attribute Profile (00001801-0000-1000-8000-00805f9b34fb)
    UUID: A/V Remote Control (0000110e-0000-1000-8000-00805f9b34fb)
    UUID: A/V Remote Control Target (0000110c-0000-1000-8000-00805f9b34fb)
    Modalias: usb:v1D6Bp0246d0513
    Discovering: no
    [bluetooth]# select 2C:D0:5A:DF:60:07
    [bluetooth]# power on
    Failed to set power on: org.bluez.Error.Blocked
    [DEL ] Controller 2C:D0:5A:DF:60:07 yoga [default]
    [NEW] Controller 2C:D0:5A:DF:60:07 yoga [default]
    [bluetooth]#
    Ok, it is not powered on. In troubleshooting section in wiki there are some instructions about such situation. I do all as described in wiki:
    [ndr@yoga ~]$ hciconfig -a
    hci0: Type: BR/EDR Bus: USB
    BD Address: 2C:D0:5A:DF:60:07 ACL MTU: 820:8 SCO MTU: 255:16
    [b]DOWN[/b]
    RX bytes:558 acl:0 sco:0 events:28 errors:0
    TX bytes:355 acl:0 sco:0 commands:28 errors:0
    Features: 0xff 0xfb 0xff 0xfe 0xdb 0xff 0x7b 0x87
    Packet type: DM1 DM3 DM5 DH1 DH3 DH5 HV1 HV2 HV3
    Link policy: RSWITCH HOLD SNIFF PARK
    Link mode: SLAVE ACCEPT
    [ndr@yoga ~]$ hciconfig -a hci0 up
    Can't init device hci0: Operation not permitted (1)
    [ndr@yoga ~]$ sudo hciconfig -a hci0 up
    [sudo] password for ndr:
    Can't init device hci0: Operation not possible due to RF-kill (132)
    [ndr@yoga ~]$ rfkill unblock all
    bash: rfkill: command not found
    Could you please tell me where to dig next. Why there is not rfkill command?

  • Virus infection with jmp code

    I have been infected with a virus for a few weeks or in one or two cases possibly since May.
    That is based on 3 trojans identified by AVZ which is part of Kaspersky's suite of tools. There is another utility called GMER that has circumvented the attacking and disabling of anti-malware packages which has been a symptom of this trojan - likely the GameThief.Win32.Onlinegame.TGNK identified by AVZ.
    The out put from GMER may be of interest and I wonder if you have any means of blocking it or can block it in an emergency patch. I've had to truncate some of the other bits which were similar apartments due to character limits
    I hope this information is of use and if you recognise the malware please let me know or confirm which it is of Mailfinder, Gamethief or Downloader and more especially a package that can tackle it.
    GMER 2.1.19357 - http://www.gmer.net
    Rootkit scan 2014-08-26 16:23:07
    Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1600JB-00GVA0 rev.08.02D08 149.05GB
    Running: 8xkqoifm.exe; Driver: C:\DOCUME~1\Mark\LOCALS~1\Temp\awloapod.sys
    ---- User code sections - GMER 2.1 ----
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 018D3D20 C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtFlushBuffersFile 7C90D32E 5 Bytes JMP 018BC661 C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtQueryFullAttributesFile 7C90D7AE 5 Bytes JMP 018D3820 C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtReadFile 7C90D9CE 5 Bytes JMP 018BC750 C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtReadFileScatter 7C90D9DE 5 Bytes JMP 0215E1FF C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 018D43D0 C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtWriteFileGather 7C90DF8E 5 Bytes JMP 0215E1AE C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10001F4C C:\Program Files\Mozilla Firefox\mozglue.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 020FF582 C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 020FF55F C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] kernel32.dll!ValidateLocale + B648 7C844EE0 7 Bytes JMP 018D06F3 C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 020FF4E0 C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\firefox.exe[708] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 0200E5A9 C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\plugin-container.exe[1184] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 1052825D C:\Program Files\Mozilla Firefox\xul.dll
    .text C:\Program Files\Mozilla Firefox\plugin-container.exe[1184] USER32.dll!GetMenuContextHelpId + 1A 7E465319 7 Bytes JMP 10521BFA C:\Program Files\Mozilla Firefox\xul.dll
    ---- Devices - GMER 2.1 ----
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys
    ---- Registry - GMER 2.1 ----
    Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeSniffers\VideoFilesContentSniffer@RelPattern *.asf?*.avi?*.divx?*.mov?*.mpeg?*.mpg?*.ogm?*.qt?*.rm?*.wmv?*.mkv?*.vob?*.m1v?*.m2v?*.swf?*.fli?*.flc?*.flic?*.dat?*.mp4?*.mpe?*.3gp?*.3g2?*.ts?*.tp?*.trp?*.k3g?*.flv?*.m4v?*.mpg?VIDEO\*.mpg?*.
    Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
    Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
    Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 ...
    Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
    Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
    Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x46 0x47 0x15 0xB0 ...
    Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
    Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
    Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x7A 0x45 0x05 0xFD ...
    Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
    Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
    Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
    Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
    Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
    Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xCD 0x44 0xCD 0xB9 ...
    Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
    Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
    Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
    Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
    Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
    Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
    Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
    ---- EOF - GMER 2.1 ----

    No because it was hijacked as has happened to every anti-malware package I've installed. The sign of this is icons on the desktop get greyed out but just those associated with malware scanning/killing tools.
    The anonymization of filenames has worked a bit with GMER but I'm now concerned that if I visit the site again I'll get a false file.
    The latest scan with a previous GMER file is now suggesting some tcpip parameters are affected including Lease Obtained, T1, T2 and Lease terminates.
    Even in safe mode I'm now getting problems like almost 100%CPU usage for refreshing Firefox.

Maybe you are looking for