This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Antispyware Soft Virus Removal

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Again.

My husbands computer somehow was infected with the Antispyware Soft virus that takes over your computer.
I rebooted in safe mode and ran malwarebytes which found 10 infected items and quarantined them and deleted them, now it is working fine again.

In the information I got from the net about removing it listed some registry keys associated with the virus. Some have gone but some are still there.

My question is, Should I delete the remaining registry values.

Antispyware Soft Associated Registry Values and Keys

* HKEY_CURRENT_USER\Software\avsoft
* HKEY_CURRENT_USER\Software\avsuite
* HKEY_CURRENT_USER\Software\avsuite\knkd=1
* HKEY_CURRENT_USER\Software\avsuite\aazalirt=1
* HKEY_CURRENT_USER\Software\avsuite\skaaanret=1
* HKEY_CURRENT_USER\Software\avsuite\jungertab=1
* HKEY_CURRENT_USER\Software\avsuite\zibaglertz=1
* HKEY_CURRENT_USER\Software\avsuite\iddqdops=1
* HKEY_CURRENT_USER\Software\avsuite\ronitfst=1
* HKEY_CURRENT_USER\Software\avsuite\tobmygers=1
* HKEY_CURRENT_USER\Software\avsuite\jikglond=1
* HKEY_CURRENT_USER\Software\avsuite\tobykke=1
* HKEY_CURRENT_USER\Software\avsuite\klopnidret=1
* HKEY_CURRENT_USER\Software\avsuite\jiklagka=1
* HKEY_CURRENT_USER\Software\avsuite\salrtybek=1
* HKEY_CURRENT_USER\Software\avsuite\seeukluba=1
* HKEY_CURRENT_USER\Software\avsuite\jrjakdsd=1
* HKEY_CURRENT_USER\Software\avsuite\krkdkdkee=1
* HKEY_CURRENT_USER\Software\avsuite\dkewiizkjdks=1
* HKEY_CURRENT_USER\Software\avsuite\dkekkrkska=1
* HKEY_CURRENT_USER\Software\avsuite\rkaskssd=1
* HKEY_CURRENT_USER\Software\avsuite\kuruhccdsdd=1
* HKEY_CURRENT_USER\Software\avsuite\krujmmwlrra=1
* HKEY_CURRENT_USER\Software\avsuite\kkwknrbsggeg=1
* HKEY_CURRENT_USER\Software\avsuite\ktknamwerr=1
* HKEY_CURRENT_USER\Software\avsuite\iqmcnoeqz=1
* HKEY_CURRENT_USER\Software\avsuite\ienotas=1
* HKEY_CURRENT_USER\Software\avsuite\krkmahejdk=1
* HKEY_CURRENT_USER\Software\avsuite\otpeppggq=1
* HKEY_CURRENT_USER\Software\avsuite\krtawefg=1
* HKEY_CURRENT_USER\Software\avsuite\oranerkka=1
* HKEY_CURRENT_USER\Software\avsuite\kitiiwhaas=1
* HKEY_CURRENT_USER\Software\avsuite\otowjdseww=1
* HKEY_CURRENT_USER\Software\avsuite\otnnbektre=1
* HKEY_CURRENT_USER\Software\avsuite\oropbbsee=1
* HKEY_CURRENT_USER\Software\avsuite\irprokwks=1
* HKEY_CURRENT_USER\Software\avsuite\ooorjaas=1
* HKEY_CURRENT_USER\Software\avsuite\id=8.0
* HKEY_CURRENT_USER\Software\avsuite\ready=1


* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\CheckExeSignatures=no
* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\RunInvalidSignatures=1
* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter
* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter\EnabledV8=0
* HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter\Enabled=0
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer=http=127.0.0.1:5555 (THIS ONE IS GONE AS I TURNED OFF THE PROXY SETTING IN HIS IE TOOLS)
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\LowRiskFileTypes=.exe
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\SaveZoneInformation=1
* HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\njjhiffj=C:\Documents and Settings\malwarehelp.org\Local Settings\Application Data\ylyqcrynp\klbqtgitssd.exe

* HKEY_CURRENT_USER\Software\Microsoft\Windows Script
* HKEY_CURRENT_USER\Software\Microsoft\Windows Script\Settings
* HKEY_CURRENT_USER\Software\Microsoft\Windows Script\Settings\JITDebug=1

The striked through ones are not in his registry but all the rest still are.

Any info as to whether I should delete the remaining ones would be helpful.
I got my removal information from http://www.malwarehelp.org/antispyware-sof…moval-2010.html
as it was the only one green in my WOT firefox.

I can log in through his computer and do logs if needed.

Thanks in advance.
Hello,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 48 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________



If you are using Windows Vista/7, you will need to right click and choose "Run as Administrator" to run the tools we will use.


I'll start of with these: ;)

Do not mess with the registry. Doing so might render your computer inoperable!

–Next–

Please download ERUNT from one of the following links:
  • ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.
  • Double click erunt-setup.
  • Choose a language then press Enter or click OK to continue.
  • Click Next on the Welcome window.
  • Install it using the default settings and choose No when asked to add ERUNT to the start up folder.
  • Make sure a check mark is placed beside Launch ERUNT and uncheck Show documentation.
  • Click Finish.
  • Once installed, open ERUNT.exe if it hasn't opened yet then create a registry back up.

How to create ERUNT back up:
  • Open ERUNT.exe, if it hasn't opened yet.
  • Click OK on the welcome screen.
  • Choose the default settings for the back up.
  • Make sure a check mark is placed beside System registry and Current user registry.
  • Click OK.
  • If the destination folder does not exist, ERUNT will prompt you and just click on Yes.
  • A confirmation window will popup when complete.
  • Click OK to close.

Note: To restore your registry, go to %WINDIR%\ERDNT (ex. C:\WINDOWS\ERDNT) and choose the folder which you want to restore and open ERDNT.exe

–Next–

[external image: Posted Image]
Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Double click GMER.exe.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.

–Next–

OTL:
  • Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Copy and paste the following bold text into the box under Custom Scan

    netsvcs
    %SYSTEMDRIVE%\*.exe
    c:\windows\system32\drivers\*.sys /90
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    /md5stop
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of the OTL.txt and post it with your next reply along with the Extras.txt log.

To post in your next reply:
1. GMER log.
2. OTL logs.
Hi,

Thanks for the reply.

I have run Erunt and saved it successfully.

I downloaded Gmer and tried 5 times to run a complete scan but it renders the computer inoperable every time. It just becomes VERRRRRY slow and wont let me do anything.

I have seen the final results as i let it run overnight and i wrote down the last result before touching the computer so i could run the scan again and stop it when the last entry appeared then save it and that was successful.

I ran OTL but only got one text window open.

These are the results.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-27 12:17:27
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\SHANEM~1\LOCALS~1\Temp\uxtdypog.sys


—- System - GMER 1.0.15 —-

SSDT F7CB887E ZwCreateKey
SSDT F7CB8874 ZwCreateThread
SSDT F7CB8883 ZwDeleteKey
SSDT F7CB888D ZwDeleteValueKey
SSDT F7CB8892 ZwLoadKey
SSDT F7CB8860 ZwOpenProcess
SSDT F7CB8865 ZwOpenThread
SSDT F7CB889C ZwReplaceKey
SSDT F7CB8897 ZwRestoreKey
SSDT F7CB8888 ZwSetValueKey
SSDT F7CB886F ZwTerminateProcess

—- Kernel code sections - GMER 1.0.15 —-

.rsrc C:\WINDOWS\system32\DRIVERS\avipbb.sys entry point in ".rsrc" section [0xAAB8D014]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\svchost.exe[1040] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0084000A
.text C:\WINDOWS\System32\svchost.exe[1040] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0085000A
.text C:\WINDOWS\System32\svchost.exe[1040] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 006E000C
.text C:\WINDOWS\System32\svchost.exe[1040] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00D3000A
.text C:\WINDOWS\Explorer.EXE[2828] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A1000A
.text C:\WINDOWS\Explorer.EXE[2828] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00AB000A
.text C:\WINDOWS\Explorer.EXE[2828] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A0000C

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 857F5D01

—- Registry - GMER 1.0.15 —-

Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{06C441DE-543D-7434-3187-8E0D2F00B734}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{06C441DE-543D-7434-3187-8E0D2F00B734}@hacmimdiaboccofd 0x6D 0x61 0x62 0x6D …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{06C441DE-543D-7434-3187-8E0D2F00B734}@jabmnlhljefnbfanffee 0x64 0x62 0x68 0x6D …

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\DRIVERS\avipbb.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-

OTL logfile created on: 27/05/2010 11:54:57 AM - Run 2
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Shane Murray\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: dd/MM/yyyy

998.00 Mb Total Physical Memory | 625.00 Mb Available Physical Memory | 63.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1500 3000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 280.02 Gb Free Space | 93.94% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHANE
Current User Name: Shane Murray
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Shane Murray\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()
PRC - C:\Program Files\ASUS\EZVCR\Agent.exe (ASUS)
PRC - C:\Program Files\Intel\AMT\LMS.exe (Intel)
PRC - C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
PRC - C:\Program Files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlservr.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Shane Murray\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\cabinet.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (getPlus® Helper) getPlus® – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (LMS) Intel® – C:\Program Files\Intel\AMT\LMS.exe (Intel)
SRV - (MSSQL$JADE) – C:\Program Files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$JADE) – C:\Program Files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlagent.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam Pro 9000(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (u3kmini) – C:\WINDOWS\system32\drivers\u3kmini.sys (ASUSTeK)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (HECI) Intel® – C:\WINDOWS\system32\drivers\HECI.sys (Intel Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (sfng32) – C:\WINDOWS\system32\drivers\sfng32.sys (Sonic Focus, Inc)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (BrSerIf) – C:\WINDOWS\system32\drivers\BrSerIf.sys (Brother Industries Ltd.)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (BrUsbSer) – C:\WINDOWS\system32\drivers\BrUsbSer.sys (Brother Industries Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lowcostit.com.au
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.news.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://google.com.au"
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100503

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/21 11:57:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/10 09:12:55 | 000,000,000 | —D | M]

[2009/06/16 12:29:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Shane Murray\Application Data\Mozilla\Extensions
[2010/05/25 22:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Shane Murray\Application Data\Mozilla\Firefox\Profiles\fpm9a2du.default\extensions
[2009/09/03 14:11:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Shane Murray\Application Data\Mozilla\Firefox\Profiles\fpm9a2du.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/25 22:29:06 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Shane Murray\Application Data\Mozilla\Firefox\Profiles\fpm9a2du.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/05/25 22:29:08 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2004/08/04 22:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [EzAgent] C:\Program Files\ASUS\EZVCR\Agent.exe (ASUS)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [IntelAudioStudio] C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe (Intel Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] File not found
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Scansoft, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk = C:\Program Files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlmaint.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Shane Murray\Start Menu\Programs\Startup\Siebel QuickStart.lnk = C:\sea752\client\BIN\siebel.exe (Siebel Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_17.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: afgonline.com.au ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: afgonline.com.au ([flex] https in Trusted sites)
O15 - HKCU\..Trusted Domains: afgonline.com.au/fins_enu/start.swe?SWECmd=Start&SWEHo;=flex.afgonline.com.au ([flex] https in Trusted sites)
O15 - HKCU\..Trusted Domains: com.au ([*.challenger] https in Trusted sites)
O15 - HKCU\..Trusted Domains: com.au ([flex.afgonline] https in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: SHANE ([]http in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} https://flex.afgonline.com.au/fins_enu/2042…Integration.cab (Siebel Desktop Integration)
O16 - DPF: {B2B2C3F9-CFB2-49CC-942D-103E68E09B74} https://flex.afgonline.com.au/fins_enu/2042…tBound_mail.cab (Siebel Email Support for Microsoft Outlook and Lotus Notes)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CD9C0F1B-D8F9-4229-B76C-5EF6B14372E4} https://flex.afgonline.com.au/fins_enu/2042…x_HI_Client.cab (Siebel High Interactivity Framework)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (RtlGina2.dll) - C:\WINDOWS\System32\RtlGina2.dll ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Shane Murray\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Shane Murray\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/24 12:39:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{362de955-b120-11dd-a883-0019d1557681}\Shell\AutoRun\command - "" = E:\setupSNK.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007/02/24 12:39:08 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17465059307421696)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/27 11:46:51 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Shane Murray\Desktop\OTL.exe
[2010/05/27 07:59:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Shane Murray\Desktop\New Folder
[2010/05/26 18:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Shane Murray\Desktop\gmer
[2010/05/26 18:37:17 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/05/26 18:36:44 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/05/26 18:35:09 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Shane Murray\Desktop\erunt-setup.exe
[2010/05/25 22:35:44 | 000,401,720 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Shane Murray\Desktop\iexplore.exe
[2010/05/25 22:12:02 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/05/25 22:12:00 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/05/25 21:49:08 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2010/05/25 21:39:43 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Shane Murray\Desktop\ATF_Cleaner.exe
[2010/05/25 20:18:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Shane Murray\Local Settings\Application Data\yymvvcjtn
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/27 11:46:58 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shane Murray\Desktop\OTL.exe
[2010/05/27 11:42:55 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/27 11:32:47 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/27 11:32:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/27 11:32:01 | 004,980,736 | -H– | M] () – C:\Documents and Settings\Shane Murray\NTUSER.DAT
[2010/05/27 11:32:01 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Shane Murray\ntuser.ini
[2010/05/26 18:37:44 | 000,284,915 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\gmer.zip
[2010/05/26 18:36:45 | 000,000,611 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\NTREGOPT.lnk
[2010/05/26 18:36:45 | 000,000,592 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\ERUNT.lnk
[2010/05/26 18:35:24 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Shane Murray\Desktop\erunt-setup.exe
[2010/05/25 22:35:42 | 000,401,720 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Shane Murray\Desktop\iexplore.exe
[2010/05/25 22:13:43 | 000,003,739 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/05/25 21:39:43 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Shane Murray\Desktop\ATF_Cleaner.exe
[2010/05/25 20:25:20 | 000,001,882 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
[2010/05/25 19:35:02 | 000,017,408 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\Year-to-date Income Calculator - 1102.xls
[2010/05/20 18:36:18 | 000,234,496 | —- | M] () – C:\Documents and Settings\Shane Murray\My Documents\Powerball200510.doc
[2010/05/12 07:18:38 | 000,040,448 | —- | M] () – C:\Documents and Settings\Shane Murray\My Documents\Publication2.pub
[2010/05/12 07:18:05 | 000,040,448 | —- | M] () – C:\Documents and Settings\Shane Murray\My Documents\Publication1.pub
[2010/05/06 18:34:13 | 000,000,046 | —- | M] () – C:\WINDOWS\cmc2.dat
[2010/05/06 18:32:52 | 000,023,552 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\Copy of INVESTMENT PROPERTY SAMPLE 1.xls
[2010/05/06 18:16:27 | 000,043,520 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\AFASA Qualifier.xls
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/26 18:37:45 | 000,284,915 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\gmer.zip
[2010/05/26 18:36:45 | 000,000,611 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\NTREGOPT.lnk
[2010/05/26 18:36:45 | 000,000,592 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\ERUNT.lnk
[2010/05/25 19:35:02 | 000,017,408 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\Year-to-date Income Calculator - 1102.xls
[2010/05/20 18:35:22 | 000,234,496 | —- | C] () – C:\Documents and Settings\Shane Murray\My Documents\Powerball200510.doc
[2010/05/12 07:18:38 | 000,040,448 | —- | C] () – C:\Documents and Settings\Shane Murray\My Documents\Publication2.pub
[2010/05/12 07:18:04 | 000,040,448 | —- | C] () – C:\Documents and Settings\Shane Murray\My Documents\Publication1.pub
[2010/05/06 18:32:52 | 000,023,552 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\Copy of INVESTMENT PROPERTY SAMPLE 1.xls
[2010/05/06 18:16:26 | 000,043,520 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\AFASA Qualifier.xls
[2010/02/25 10:06:32 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\RtlGina2.dll
[2010/02/25 10:06:31 | 000,966,765 | —- | C] () – C:\WINDOWS\System32\acAuth.dll
[2010/02/25 10:06:31 | 000,356,352 | —- | C] () – C:\WINDOWS\System32\SCMLib.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/05/29 16:27:12 | 000,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/02/23 16:09:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\AOLM.dll
[2007/06/06 16:05:17 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2007/06/06 09:37:21 | 000,000,051 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2007/06/06 09:37:21 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_2460.ini
[2007/03/02 16:31:12 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/03/02 08:51:28 | 000,000,426 | —- | C] () – C:\WINDOWS\brwmark.ini
[2007/03/02 08:51:28 | 000,000,283 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2007/03/02 08:51:28 | 000,000,153 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2007/03/02 08:51:28 | 000,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2007/03/02 08:50:57 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2007/03/02 08:48:02 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2007/03/01 16:12:18 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/02/27 02:21:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/02/25 05:22:32 | 000,192,512 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4618.dll
[2007/02/25 05:22:30 | 000,348,880 | R— | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2007/02/25 05:05:53 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2007/02/24 11:26:00 | 000,001,172 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/08/28 13:20:44 | 000,031,504 | —- | C] () – C:\WINDOWS\ezvcr.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/04 10:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll

========== LOP Check ==========

[2009/10/19 14:16:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cached Installations
[2010/02/09 09:41:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2010/02/09 09:25:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2007/03/02 08:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/03/02 13:07:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2008/08/06 18:52:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipEC
[2010/02/09 09:26:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Shane Murray\Application Data\DriverCure
[2009/05/29 16:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Shane Murray\Application Data\Leadertech
[2009/02/26 13:38:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Shane Murray\Application Data\OfficeUpdate12

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< c:\windows\system32\drivers\*.sys /90 >
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys


< MD5 for: AGP440.SYS >
[2004/08/04 22:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/03/05 09:15:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 22:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2009/03/05 09:15:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 04:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 04:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 22:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/03/05 09:15:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 22:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2009/03/05 09:15:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 04:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 04:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 16:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 22:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2004/08/04 16:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 10:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 10:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 22:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/14 10:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 10:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 22:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 22:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 10:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 10:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< End of report >

Thanks
Hi,

Your computer is infected with a very nasty rootkit. Please post the Extras.txt in your next reply.

Are you familiar with this file? Do not run it.
C:\Documents and Settings\Shane Murray\Desktop\iexplore.exe

and this trusted domain?
O15 - HKCU\..Trusted Domains: SHANE ([]http in Trusted sites)

and also this folder?
C:\Documents and Settings\Shane Murray\Local Settings\Application Data\yymvvcjtn

–Next–

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *avipbb.sys
    *atapi.sys
    
    :dir
    C:\Documents and Settings\Shane Murray\Local Settings\Application Data\yymvvcjtn /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

–Next–

Please go to VirSCAN
  • Click on Browse.
  • On the File Upload window, copy/paste the text below into the File name box:
    C:\Documents and Settings\Shane Murray\Desktop\iexplore.exe
  • Click Upload. Allow the file to be scanned. If it says already scanned – click Reanalyze Now
Repeat the procedure with the following files:
C:\WINDOWS\System32\AOLM.dll
C:\WINDOWS\System32\igfxCoIn_v4618.dll
C:\WINDOWS\System32\Jpeg32.dll


Please post the results in your next reply.

To post in your next reply:
1. Regarding my questions above.
2. Extras.txt
3. Systemlook log.
4. VirSCAN log.
When I run OTL i only get one text box that opens. I ran it 3 times and still only got 1 box. Am I doing something wrong? i am not familiar with the files you mentioned I will ask my hubby. I will do the rest of the scans tonight. Thanks
Hi, Am sorry I missed something. It seems that you have run OTL previously on this machine. Let's concentrate on the scans for now. Thanks. :)
Hi,

In your next post please include Extras.txt by doing the following:
  • Open OTL.exe.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Extra Registry group, click on Use SafeList.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • Post the contents of the logs.
Hi again, When i click on the VirSCAN link it takes me to a page with this only on it. 对不起,由于访问量太大,导致数据库过载,请过一会再试 返回上一页 Am I missing something?? Thanks
Hi,

OTL Extras logfile created on: 27/05/2010 3:42:37 PM - Run 3
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Shane Murray\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: dd/MM/yyyy

998.00 Mb Total Physical Memory | 576.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1500 3000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 280.05 Gb Free Space | 93.95% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHANE
Current User Name: Shane Murray
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"2264:TCP" = 2264:TCP:LocalSubNet:Enabled:SQL_TCP_PORT_2264
"2264:UDP" = 2264:UDP:LocalSubNet:Enabled:SQL_UDP_PORT_2264
"1433:TCP" = 1433:TCP:LocalSubNet:Enabled:SQL_TCP_PORT_1433
"1433:UDP" = 1433:UDP:LocalSubNet:Enabled:SQL_UDP_PORT_1433

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\PokerStars\PokerStarsUpdate.exe" = C:\Program Files\PokerStars\PokerStarsUpdate.exe:*:Enabled:PokerStars – (PokerStars)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{08094E03-AFE4-4853-9D31-6D0743DF5328}" = QuickTime
"{0A0873E1-D9BA-4994-B85D-A0A331EF1F0C}" = Intel® PRO Network Connections
"{1029655B-AB86-497E-B6DF-90C3EBAD0661}" = ApplyOnline Mobile
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{217B4075-FA84-4363-BD09-0712725CAD7B}" = MSXML
"{2205E3A5-DCDC-461D-8ED6-D6F2341D3B64}" = Intel Audio Studio 2.0
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{240D4AC7-F7BC-4B51-898E-E4CB86485ECE}" = Intel Audio Studio 2.0
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{4102037D-E8E0-48E0-B203-E521D194FB71}" = NETGEAR WG111v2 wireless USB 2.0 adapter
"{429476AD-BC87-4176-932B-D4F1C6F44DA8}" = MortgageXS
"{42CFD768-94A5-4C0D-A49A-88B536BAC551}" = FileNet Desktop eForms
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = ASUSDVD
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D2A1A00-F630-49ED-8E6C-C199544DD3AB}" = ASUS My Cinema-U3000 Mini
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A260B422-70E1-41E2-957D-F76FA21266D5}" = Apple Software Update
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A6E8DFAA-A337-406B-8B63-B709D320275B}" = MortgageXS MSDE Setup
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.1
"{AC76BA86-7AD7-5760-0000-705000000001}" = Adobe Reader Japanese Fonts
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE651735-FDDC-47EA-BFFD-3BF9472B8E85}" = ASUS EZVCR
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D83BD5E2-5AF4-49F6-B5C1-484A9760E73D}" = Brother MFL-Pro Suite
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (JADE)
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6A39BCA-8C6C-4BAA-BE1D-1C3E784ADB95}" = BigPond Broadband Cable Self Install Kit
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Canon Digital Camera USB WIA Driver" = Canon Digital Camera USB WIA Driver
"CCleaner" = CCleaner (remove only)
"Credit Master Suite Version 2.15b" = Credit Master Suite Version 2.15b
"CutePDF Writer Installation" = CutePDF Writer 2.7
"e-Record 5" = e-Record 5
"ERUNT_is1" = ERUNT 1.1j
"HDMI" = Intel® Graphics Media Accelerator Driver
"HECI" = Intel® Active Client Manager 2.0 HECI Driver
"HijackThis" = HijackThis 2.0.2
"Image2PDF" = Image2PDF
"InstallShield_{CE651735-FDDC-47EA-BFFD-3BF9472B8E85}" = ASUS EZVCR
"Lavasoft VX2 Cleaner" = Lavasoft VX2 Cleaner
"lvdrivers_11.80" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MESOL" = Intel® Active Management Technology LMS Service and SOL Driver
"Messenger-Control plug-in for Ad-Aware SE" = Messenger-Control plug-in for Ad-Aware SE
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.14)" = Mozilla Firefox (3.0.14)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NeroMultiInstaller!UninstallKey" = Nero Suite
"OE/W Messengerctrl plug-in for Ad-Aware SE" = OE/W Messengerctrl plug-in for Ad-Aware SE
"PokerStars" = PokerStars
"Siebel Uninstall Manager" = Siebel Systems Uninstallation Manager
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"Westnet Internet Easy Online Signup" = Westnet Internet Easy Online Signup 3.0
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinZip E-Mail Companion" = WinZip E-Mail Companion
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"xat.com JPEG Optimizer" = xat.com JPEG Optimizer

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"3257efbf724af51d" = ANZ Toolkit
"GoToMeeting" = GoToMeeting 4.1.0.366

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 26/05/2010 9:42:53 PM | Computer Name = SHANE | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 26/05/2010 9:42:53 PM | Computer Name = SHANE | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 26/05/2010 10:21:45 PM | Computer Name = SHANE | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 26/05/2010 10:21:45 PM | Computer Name = SHANE | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 26/05/2010 10:21:47 PM | Computer Name = SHANE | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 26/05/2010 10:21:47 PM | Computer Name = SHANE | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 27/05/2010 1:32:27 AM | Computer Name = SHANE | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 27/05/2010 1:32:27 AM | Computer Name = SHANE | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 27/05/2010 1:33:11 AM | Computer Name = SHANE | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 27/05/2010 1:33:11 AM | Computer Name = SHANE | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

[ System Events ]
Error - 25/05/2010 8:05:09 AM | Computer Name = SHANE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 25/05/2010 8:06:12 AM | Computer Name = SHANE | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.

Error - 25/05/2010 8:06:12 AM | Computer Name = SHANE | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 25/05/2010 8:06:12 AM | Computer Name = SHANE | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 26/05/2010 4:22:02 AM | Computer Name = SHANE | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 26/05/2010 4:22:02 AM | Computer Name = SHANE | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 26/05/2010 4:22:41 AM | Computer Name = SHANE | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 001E2AE7D173. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 26/05/2010 4:52:21 AM | Computer Name = SHANE | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 26/05/2010 4:52:21 AM | Computer Name = SHANE | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 26/05/2010 9:30:47 PM | Computer Name = SHANE | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 00000000, parameter2 0000001c, parameter3
00000001, parameter4 8272700c.


< End of report >




SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 15:36 on 27/05/2010 by Shane Murray (Administrator - Elevation successful)

========== filefind ==========

Searching for "*avipbb.sys"
C:\WINDOWS\system32\drivers\avipbb.sys –a— 96104 bytes [03:33 03/08/2009] [00:33 30/03/2009] 452E382340BB0C5E694ED9D3625356D0

Searching for "*atapi.sys"
C:\WINDOWS\$NtServicePackUninstall$\atapi.sys —–c 95360 bytes [23:16 04/03/2009] [06:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\ServicePackFiles\i386\atapi.sys —— 96512 bytes [23:23 13/10/2008] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\atapi.sys –a— 96512 bytes [22:59 03/08/2004] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys –a— 95360 bytes [19:10 24/02/2007] [12:00 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys –a— 95360 bytes [19:10 24/02/2007] [06:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51

========== dir ==========

C:\Documents and Settings\Shane Murray\Local Settings\Application Data\yymvvcjtn - Parameters: "/s"

—Files—
None found.

No folders found.

-=End Of File=-



Jotti logo


Jotti's malware scan
Filename: iexplore.exe
Status:
Scan finished. 1 out of 19 scanners reported malware.
Scan taken on: Thu 27 May 2010 07:53:14 (CET) Permalink


[CPsecure]
2010-05-27 W32.W.Huhk.a



Filename: AOLM.dll
Status:
Scan finished. 0 out of 19 scanners reported malware.
Scan taken on: Thu 27 May 2010 07:55:41 (CET) Permalink



Filename: igfxCoIn_v4618.dll
Status:
Scan finished. 0 out of 19 scanners reported malware.
Scan taken on: Thu 27 May 2010 07:58:00 (CET) Permalink



Filename: Jpeg32.dll
Status:
Scan finished. 0 out of 19 scanners reported malware.
Scan taken on: Thu 27 May 2010 07:59:40 (CET) Permalink


Thanks
Hi, Sorry forgot to answer the questions at the top of the post. We are not familiar with any of those files. When I right click on the iexplore from the desktop it gives me this information. Type of File: Application Description: Hijack This Size: 392KB Created: 25 May 2010 10:35.44PM Modified: 25 May 2010 10:35.42PM That is the night that the virus occurred but it was around 8.00PM we got the virus. My husband clicked on a photo on the carpoint website and that is when all the scans and alerts started. The Application data\yymvvctjn folder was created on same night 25 may 2010 at 8:13pm. It is an empty folder. And not familiar with the trusted domain SHANE either.
Hi,

Please do the following:

Download Combofix from any of the links below. You must rename it before saving it. Save it as SubsFix.exe

* IMPORTANT !!! Save SubsFix.exe to your Desktop

Link 1
Link 2

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 10-05-26.03 - Shane Murray 27/05/2010 17:42:11.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.998.660 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\SubsFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Shane Murray\g2mdlhlpx.exe
c:\windows\system32\Thumbs.db
c:\windows\system32\Vb40032.dll

.
((((((((((((((((((((((((( Files Created from 2010-04-27 to 2010-05-27 )))))))))))))))))))))))))))))))
.

2010-05-26 08:36 . 2010-05-26 08:36 ——– d—–w- c:\program files\ERUNT
2010-05-25 12:11 . 2010-05-25 12:11 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2010-05-25 10:18 . 2010-05-25 12:04 ——– d—–w- c:\documents and settings\Shane Murray\Local Settings\Application Data\yymvvcjtn
2010-05-24 08:24 . 2010-05-24 08:24 503808 —-a-w- c:\documents and settings\Shane Murray\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-3f52d106-n\msvcp71.dll
2010-05-24 08:24 . 2010-05-24 08:24 499712 —-a-w- c:\documents and settings\Shane Murray\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-3f52d106-n\jmc.dll
2010-05-24 08:24 . 2010-05-24 08:24 348160 —-a-w- c:\documents and settings\Shane Murray\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-3f52d106-n\msvcr71.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-26 08:39 . 2009-01-21 23:55 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-05-25 12:04 . 2010-03-05 23:57 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-13 11:15 . 2007-08-06 00:05 ——– d—–w- c:\program files\FMSI
2010-05-06 08:34 . 2008-06-25 04:48 46 —-a-w- c:\windows\cmc2.dat
2010-04-29 05:39 . 2010-03-05 23:57 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 05:39 . 2010-03-05 23:57 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-10 05:18 . 2008-06-25 04:49 45 —-a-w- c:\windows\cm2.dat
2010-04-09 23:12 . 2007-03-02 02:05 ——– d—–w- c:\program files\Common Files\Adobe
2010-03-09 11:09 . 2007-02-24 01:25 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-03-05 23:43 . 2009-10-13 23:09 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-03-05 23:43 . 2010-03-05 23:43 152576 —-a-w- c:\documents and settings\Shane Murray\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-03-05 23:42 . 2010-03-05 23:42 79488 —-a-w- c:\documents and settings\Shane Murray\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-12 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-06-08 9129984]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-06-15 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-06-15 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-06-15 81920]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"SetDefPrt"="c:\program files\Brother\Brmfl04g\BrStDvPt.exe" [2004-11-11 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-11-11 864256]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-26 282624]
"EzAgent"="c:\program files\ASUS\EZVCR\Agent.exe" [2006-07-26 122880]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-11 32768]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-03-05 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\Shane Murray\Start Menu\Programs\Startup\
Siebel QuickStart.lnk - c:\sea752\client\BIN\siebel.exe [2007-3-7 286992]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2010-2-25 1261568]
Service Manager.lnk - c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlmaint.exe [2002-12-17 156224]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\PokerStars\\PokerStarsUpdate.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [03/08/2009 1:33 PM 108289]
R2 MSSQL$JADE;MSSQL$JADE;c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlservr.exe -sJADE –> c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlservr.exe -sJADE [?]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [25/02/2010 10:06 AM 194304]
S3 SQLAgent$JADE;SQLAgent$JADE;c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlagent.EXE -i JADE –> c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlagent.EXE -i JADE [?]
S3 u3kmini;ASUS My Cinema-U3000 Mini;c:\windows\system32\drivers\u3kmini.sys [06/06/2007 4:05 PM 352000]
.
Contents of the 'Scheduled Tasks' folder

2010-04-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 05:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.news.com.au/
mStart Page = hxxp://home.sweetim.com
uInternet Connection Wizard,ShellNext = hxxp://www.lowcostit.com.au/
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: afgonline.com.au
Trusted Zone: afgonline.com.au\flex
Trusted Zone: afgonline.com.au/fins_enu/start.swe?SWECmd=Start&SWEHo=flex.afgonline.com.au\flex
Trusted Zone: com.au\*.challenger
Trusted Zone: com.au\flex.afgonline
Trusted Zone: localhost
Trusted Zone: SHANE
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} - hxxps://flex.afgonline.com.au/fins_enu/20420/applets/SiebelAx_Desktop_Integration.cab
DPF: {B2B2C3F9-CFB2-49CC-942D-103E68E09B74} - hxxps://flex.afgonline.com.au/fins_enu/20420/applets/SiebelAx_OutBound_mail.cab
DPF: {CD9C0F1B-D8F9-4229-B76C-5EF6B14372E4} - hxxps://flex.afgonline.com.au/fins_enu/20420/applets/SiebelAx_HI_Client.cab
FF - ProfilePath - c:\documents and settings\Shane Murray\Application Data\Mozilla\Firefox\Profiles\fpm9a2du.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com.au
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-SigmatelSysTrayApp - sttray.exe
AddRemove-HijackThis - c:\documents and settings\Shane Murray\Desktop\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-27 17:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x85785D01]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf76eaf28
\Driver\ACPI -> ACPI.sys @ 0xf755dcb8
\Driver\atapi -> atapi.sys @ 0xf74ef852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-396895343-660526286-4143499738-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-396895343-660526286-4143499738-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{06C441DE-543D-7434-3187-8E0D2F00B734}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"hacmimdiaboccofd"=hex:6d,61,62,6d,63,6e,6c,6c,62,6e,67,6f,64,6c,64,6b,6f,6d,
69,6c,61,68,64,70,63,6f,00,00
"jabmnlhljefnbfanffee"=hex:64,62,68,6d,6c,67,6b,62,65,70,68,63,70,67,62,62,70,
6d,63,63,6c,65,62,64,68,66,66,64,6d,62,70,68,6c,6b,67,6f,6f,6e,6c,62,00,e2
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(852)
c:\windows\system32\RtlGina2.dll
Hi

here is the combofix log.

Thanks


Completion time: 2010-05-27 17:50:21
ComboFix-quarantined-files.txt 2010-05-27 07:50

Pre-Run: 300,644,700,160 bytes free
Post-Run: 301,210,255,360 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - F3741CAA11E0F6A2DB1E8C013B5241BB

Thanks again for your prompt replies.
Hi,

As this machine is infected with a rootkit, the capabilities of this particular rootkit may include keylogging and password stealing so I advise you to take all precautions to safeguard your accounts, passwords, and sensitive data. If you have entered any credit card details or use your computer for financial/banking transactions, you should notify your banks and financial institutions that you may have been a victim of identity theft and to put a watch on your accounts. For more information, please read How to report ID theft, fraud, drive-by installs, hijacking and malware. I also recommend that you change your online passwords for email, banks, etc., immediately – from a clean computer. It bears repeating to change passwords from a clean computer only.

Please do the following:

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/Antispyware_…5411#entry65541

Collect::
C:\Documents and Settings\Shane Murray\Desktop\iexplore.exe

Folder::
C:\Documents and Settings\Shane Murray\Local Settings\Application Data\yymvvcjtn

TDL::
C:\WINDOWS\system32\DRIVERS\avipbb.sys

REGNULL::
[HKEY_USERS\S-1-5-21-396895343-660526286-4143499738-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{06C441DE-543D-7434-3187-8E0D2F00B734}*]

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Hi I disabled avira when i started combo fix but when combofix rebooted the machine avira was active again i think. Would this change the outcome of the combofix? Anyhow this is the log it produced. Thanks ComboFix 10-05-26.03 - Shane Murray 27/05/2010 19:53:02.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.998.709 [GMT 10:00] Running from: c:\documents and settings\[removed]\Desktop\SubsFix.exe Command switches used :: c:\documents and settings\Shane Murray\Desktop\CFScript.txt AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} file zipped: c:\documents and settings\Shane Murray\Desktop\iexplore.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Shane Murray\Desktop\iexplore.exe c:\documents and settings\Shane Murray\Local Settings\Application Data\yymvvcjtn Infected copy of c:\windows\system32\DRIVERS\avipbb.sys was found and disinfected Restored copy from - Kitty had a snack :P Infected copy of c:\windows\system32\DRIVERS\avipbb.sys was found and disinfected Restored copy from - Kitty ate it :P Infected copy of c:\windows\system32\DRIVERS\avipbb.sys was found and disinfected Restored copy from - Kitty had a snack :P Infected copy of c:\windows\system32\DRIVERS\avipbb.sys was found and disinfected Restored copy from - Kitty ate it :P . ((((((((((((((((((((((((( Files Created from 2010-04-27 to 2010-05-27 ))))))))))))))))))))))))))))))) . 2010-05-26 11:15 . 2009-02-12 09:35 38208 —-a-w- c:\documents and settings\Shane Murray\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2010-05-26 08:36 . 2010-05-26 08:36 ——– d—–w- c:\program files\ERUNT 2010-05-25 12:11 . 2010-05-25 12:11 ——– d-s—w- c:\documents and settings\NetworkService\UserData 2010-05-24 08:24 . 2010-05-24 08:24 503808 —-a-w- c:\documents and settings\Shane Murray\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-3f52d106-n\msvcp71.dll 2010-05-24 08:24 . 2010-05-24 08:24 499712 —-a-w- c:\documents and settings\Shane Murray\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-3f52d106-n\jmc.dll 2010-05-24 08:24 . 2010-05-24 08:24 348160 —-a-w- c:\documents and settings\Shane Murray\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-3f52d106-n\msvcr71.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-05-26 08:39 . 2009-01-21 23:55 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8 2010-05-25 12:04 . 2010-03-05 23:57 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-05-13 11:15 . 2007-08-06 00:05 ——– d—–w- c:\program files\FMSI 2010-05-06 08:34 . 2008-06-25 04:48 46 —-a-w- c:\windows\cmc2.dat 2010-04-29 05:39 . 2010-03-05 23:57 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-29 05:39 . 2010-03-05 23:57 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-04-10 05:18 . 2008-06-25 04:49 45 —-a-w- c:\windows\cm2.dat 2010-04-09 23:12 . 2007-03-02 02:05 ——– d—–w- c:\program files\Common Files\Adobe 2010-03-09 11:09 . 2007-02-24 01:25 430080 —-a-w- c:\windows\system32\vbscript.dll 2010-03-05 23:43 . 2009-10-13 23:09 411368 —-a-w- c:\windows\system32\deploytk.dll 2010-03-05 23:43 . 2010-03-05 23:43 152576 —-a-w- c:\documents and settings\Shane Murray\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2010-03-05 23:42 . 2010-03-05 23:42 79488 —-a-w- c:\documents and settings\Shane Murray\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll . ((((((((((((((((((((((((((((( SnapShot@2010-05-27_07.48.21 ))))))))))))))))))))))))))))))))))))))))) . + 2010-05-27 09:58 . 2010-05-27 09:58 16384 c:\windows\Temp\Perflib_Perfdata_1b0.dat + 2010-05-27 09:58 . 2010-05-27 09:58 16384 c:\windows\Temp\Perflib_Perfdata_134.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-12 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-06-08 9129984] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-06-15 98304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-06-15 86016] "Persistence"="c:\windows\system32\igfxpers.exe" [2006-06-15 81920] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648] "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393] "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960] "SetDefPrt"="c:\program files\Brother\Brmfl04g\BrStDvPt.exe" [2004-11-11 49152] "ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-11-11 864256] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-26 282624] "EzAgent"="c:\program files\ASUS\EZVCR\Agent.exe" [2006-07-26 122880] "RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-11 32768] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-03-05 149280] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2008-04-14 53760] c:\documents and settings\Shane Murray\Start Menu\Programs\Startup\ Siebel QuickStart.lnk - c:\sea752\client\BIN\siebel.exe [2007-3-7 286992] c:\documents and settings\All Users\Start Menu\Programs\Startup\ NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2010-2-25 1261568] Service Manager.lnk - c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlmaint.exe [2002-12-17 156224] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "DisableNotifications"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\PokerStars\\PokerStarsUpdate.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [03/08/2009 1:33 PM 108289] R2 MSSQL$JADE;MSSQL$JADE;c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlservr.exe -sJADE –> c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlservr.exe -sJADE [?] R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [25/02/2010 10:06 AM 194304] S3 SQLAgent$JADE;SQLAgent$JADE;c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlagent.EXE -i JADE –> c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlagent.EXE -i JADE [?] S3 u3kmini;ASUS My Cinema-U3000 Mini;c:\windows\system32\drivers\u3kmini.sys [06/06/2007 4:05 PM 352000] . Contents of the 'Scheduled Tasks' folder 2010-04-17 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 05:42] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.news.com.au/ mStart Page = hxxp://home.sweetim.com uInternet Connection Wizard,ShellNext = hxxp://www.lowcostit.com.au/ uInternet Settings,ProxyOverride = uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 Trusted Zone: afgonline.com.au Trusted Zone: afgonline.com.au\flex Trusted Zone: afgonline.com.au/fins_enu/start.swe?SWECmd=Start&SWEHo;=flex.afgonline.com.au\flex Trusted Zone: com.au\*.challenger Trusted Zone: com.au\flex.afgonline Trusted Zone: localhost Trusted Zone: SHANE DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} - hxxps://flex.afgonline.com.au/fins_enu/20420/applets/SiebelAx_Desktop_Integration.cab DPF: {B2B2C3F9-CFB2-49CC-942D-103E68E09B74} - hxxps://flex.afgonline.com.au/fins_enu/20420/applets/SiebelAx_OutBound_mail.cab DPF: {CD9C0F1B-D8F9-4229-B76C-5EF6B14372E4} - hxxps://flex.afgonline.com.au/fins_enu/20420/applets/SiebelAx_HI_Client.cab FF - ProfilePath - c:\documents and settings\Shane Murray\Application Data\Mozilla\Firefox\Profiles\fpm9a2du.default\ FF - prefs.js: browser.startup.homepage - hxxp://google.com.au FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\avipbb] "ImagePath"="System32\Drivers\avipbb.svs" . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\S-1-5-21-396895343-660526286-4143499738-1004\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(856) c:\windows\system32\RtlGina2.dll - - - - - - - > 'explorer.exe'(3212) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ———————— Other Running Processes ———————— . c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Intel\AMT\LMS.exe c:\program files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlservr.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe . ************************************************************************** . Completion time: 2010-05-27 20:01:23 - machine was rebooted ComboFix-quarantined-files.txt 2010-05-27 10:01 ComboFix2.txt 2010-05-27 07:50 Pre-Run: 301,136,076,800 bytes free Post-Run: 301,102,059,520 bytes free - - End Of File - - 9D7590A700CB99B5B5BCBF410879D0F9 Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI