Hi,
Thanks for the reply.
I have run Erunt and saved it successfully.
I downloaded Gmer and tried 5 times to run a complete scan but it renders the computer inoperable every time. It just becomes VERRRRRY slow and wont let me do anything.
I have seen the final results as i let it run overnight and i wrote down the last result before touching the computer so i could run the scan again and stop it when the last entry appeared then save it and that was successful.
I ran OTL but only got one text window open.
These are the results.
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-05-27 12:17:27
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\SHANEM~1\LOCALS~1\Temp\uxtdypog.sys
—- System - GMER 1.0.15 —-
SSDT F7CB887E ZwCreateKey
SSDT F7CB8874 ZwCreateThread
SSDT F7CB8883 ZwDeleteKey
SSDT F7CB888D ZwDeleteValueKey
SSDT F7CB8892 ZwLoadKey
SSDT F7CB8860 ZwOpenProcess
SSDT F7CB8865 ZwOpenThread
SSDT F7CB889C ZwReplaceKey
SSDT F7CB8897 ZwRestoreKey
SSDT F7CB8888 ZwSetValueKey
SSDT F7CB886F ZwTerminateProcess
—- Kernel code sections - GMER 1.0.15 —-
.rsrc C:\WINDOWS\system32\DRIVERS\avipbb.sys entry point in ".rsrc" section [0xAAB8D014]
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\System32\svchost.exe[1040] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0084000A
.text C:\WINDOWS\System32\svchost.exe[1040] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0085000A
.text C:\WINDOWS\System32\svchost.exe[1040] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 006E000C
.text C:\WINDOWS\System32\svchost.exe[1040] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00D3000A
.text C:\WINDOWS\Explorer.EXE[2828] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A1000A
.text C:\WINDOWS\Explorer.EXE[2828] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00AB000A
.text C:\WINDOWS\Explorer.EXE[2828] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A0000C
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
Device -> \Driver\atapi \Device\Harddisk0\DR0 857F5D01
—- Registry - GMER 1.0.15 —-
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{06C441DE-543D-7434-3187-8E0D2F00B734}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{06C441DE-543D-7434-3187-8E0D2F00B734}@hacmimdiaboccofd 0x6D 0x61 0x62 0x6D …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{06C441DE-543D-7434-3187-8E0D2F00B734}@jabmnlhljefnbfanffee 0x64 0x62 0x68 0x6D …
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\DRIVERS\avipbb.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
—- EOF - GMER 1.0.15 —-
OTL logfile created on: 27/05/2010 11:54:57 AM - Run 2
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Shane Murray\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: dd/MM/yyyy
998.00 Mb Total Physical Memory | 625.00 Mb Available Physical Memory | 63.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1500 3000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 280.02 Gb Free Space | 93.94% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SHANE
Current User Name: Shane Murray
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Shane Murray\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()
PRC - C:\Program Files\ASUS\EZVCR\Agent.exe (ASUS)
PRC - C:\Program Files\Intel\AMT\LMS.exe (Intel)
PRC - C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
PRC - C:\Program Files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlservr.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Shane Murray\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\cabinet.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (getPlus® Helper) getPlus® – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (LMS) Intel® – C:\Program Files\Intel\AMT\LMS.exe (Intel)
SRV - (MSSQL$JADE) – C:\Program Files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$JADE) – C:\Program Files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlagent.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam Pro 9000(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (u3kmini) – C:\WINDOWS\system32\drivers\u3kmini.sys (ASUSTeK)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (HECI) Intel® – C:\WINDOWS\system32\drivers\HECI.sys (Intel Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (sfng32) – C:\WINDOWS\system32\drivers\sfng32.sys (Sonic Focus, Inc)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (BrSerIf) – C:\WINDOWS\system32\drivers\BrSerIf.sys (Brother Industries Ltd.)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (BrUsbSer) – C:\WINDOWS\system32\drivers\BrUsbSer.sys (Brother Industries Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.lowcostit.com.au
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.news.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://google.com.au"
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100503
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/21 11:57:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/10 09:12:55 | 000,000,000 | —D | M]
[2009/06/16 12:29:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Shane Murray\Application Data\Mozilla\Extensions
[2010/05/25 22:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Shane Murray\Application Data\Mozilla\Firefox\Profiles\fpm9a2du.default\extensions
[2009/09/03 14:11:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Shane Murray\Application Data\Mozilla\Firefox\Profiles\fpm9a2du.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/25 22:29:06 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Shane Murray\Application Data\Mozilla\Firefox\Profiles\fpm9a2du.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/05/25 22:29:08 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2004/08/04 22:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [EzAgent] C:\Program Files\ASUS\EZVCR\Agent.exe (ASUS)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [IntelAudioStudio] C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe (Intel Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] File not found
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Scansoft, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk = C:\Program Files\Microsoft SQL Server\MSSQL$JADE\Binn\sqlmaint.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Shane Murray\Start Menu\Programs\Startup\Siebel QuickStart.lnk = C:\sea752\client\BIN\siebel.exe (Siebel Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_17.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: afgonline.com.au ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: afgonline.com.au ([flex] https in Trusted sites)
O15 - HKCU\..Trusted Domains: afgonline.com.au/fins_enu/start.swe?SWECmd=Start&SWEHo;=flex.afgonline.com.au ([flex] https in Trusted sites)
O15 - HKCU\..Trusted Domains: com.au ([*.challenger] https in Trusted sites)
O15 - HKCU\..Trusted Domains: com.au ([flex.afgonline] https in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: SHANE ([]http in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543}
https://flex.afgonline.com.au/fins_enu/2042…Integration.cab (Siebel Desktop Integration)
O16 - DPF: {B2B2C3F9-CFB2-49CC-942D-103E68E09B74}
https://flex.afgonline.com.au/fins_enu/2042…tBound_mail.cab (Siebel Email Support for Microsoft Outlook and Lotus Notes)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CD9C0F1B-D8F9-4229-B76C-5EF6B14372E4}
https://flex.afgonline.com.au/fins_enu/2042…x_HI_Client.cab (Siebel High Interactivity Framework)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (RtlGina2.dll) - C:\WINDOWS\System32\RtlGina2.dll ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Shane Murray\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Shane Murray\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/24 12:39:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{362de955-b120-11dd-a883-0019d1557681}\Shell\AutoRun\command - "" = E:\setupSNK.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007/02/24 12:39:08 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17465059307421696)
========== Files/Folders - Created Within 30 Days ==========
[2010/05/27 11:46:51 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Shane Murray\Desktop\OTL.exe
[2010/05/27 07:59:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Shane Murray\Desktop\New Folder
[2010/05/26 18:37:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Shane Murray\Desktop\gmer
[2010/05/26 18:37:17 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/05/26 18:36:44 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/05/26 18:35:09 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Shane Murray\Desktop\erunt-setup.exe
[2010/05/25 22:35:44 | 000,401,720 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Shane Murray\Desktop\iexplore.exe
[2010/05/25 22:12:02 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/05/25 22:12:00 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/05/25 21:49:08 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2010/05/25 21:39:43 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Shane Murray\Desktop\ATF_Cleaner.exe
[2010/05/25 20:18:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Shane Murray\Local Settings\Application Data\yymvvcjtn
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/05/27 11:46:58 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shane Murray\Desktop\OTL.exe
[2010/05/27 11:42:55 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/27 11:32:47 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/27 11:32:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/27 11:32:01 | 004,980,736 | -H– | M] () – C:\Documents and Settings\Shane Murray\NTUSER.DAT
[2010/05/27 11:32:01 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Shane Murray\ntuser.ini
[2010/05/26 18:37:44 | 000,284,915 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\gmer.zip
[2010/05/26 18:36:45 | 000,000,611 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\NTREGOPT.lnk
[2010/05/26 18:36:45 | 000,000,592 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\ERUNT.lnk
[2010/05/26 18:35:24 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Shane Murray\Desktop\erunt-setup.exe
[2010/05/25 22:35:42 | 000,401,720 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Shane Murray\Desktop\iexplore.exe
[2010/05/25 22:13:43 | 000,003,739 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/05/25 21:39:43 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Shane Murray\Desktop\ATF_Cleaner.exe
[2010/05/25 20:25:20 | 000,001,882 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
[2010/05/25 19:35:02 | 000,017,408 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\Year-to-date Income Calculator - 1102.xls
[2010/05/20 18:36:18 | 000,234,496 | —- | M] () – C:\Documents and Settings\Shane Murray\My Documents\Powerball200510.doc
[2010/05/12 07:18:38 | 000,040,448 | —- | M] () – C:\Documents and Settings\Shane Murray\My Documents\Publication2.pub
[2010/05/12 07:18:05 | 000,040,448 | —- | M] () – C:\Documents and Settings\Shane Murray\My Documents\Publication1.pub
[2010/05/06 18:34:13 | 000,000,046 | —- | M] () – C:\WINDOWS\cmc2.dat
[2010/05/06 18:32:52 | 000,023,552 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\Copy of INVESTMENT PROPERTY SAMPLE 1.xls
[2010/05/06 18:16:27 | 000,043,520 | —- | M] () – C:\Documents and Settings\Shane Murray\Desktop\AFASA Qualifier.xls
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/05/26 18:37:45 | 000,284,915 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\gmer.zip
[2010/05/26 18:36:45 | 000,000,611 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\NTREGOPT.lnk
[2010/05/26 18:36:45 | 000,000,592 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\ERUNT.lnk
[2010/05/25 19:35:02 | 000,017,408 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\Year-to-date Income Calculator - 1102.xls
[2010/05/20 18:35:22 | 000,234,496 | —- | C] () – C:\Documents and Settings\Shane Murray\My Documents\Powerball200510.doc
[2010/05/12 07:18:38 | 000,040,448 | —- | C] () – C:\Documents and Settings\Shane Murray\My Documents\Publication2.pub
[2010/05/12 07:18:04 | 000,040,448 | —- | C] () – C:\Documents and Settings\Shane Murray\My Documents\Publication1.pub
[2010/05/06 18:32:52 | 000,023,552 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\Copy of INVESTMENT PROPERTY SAMPLE 1.xls
[2010/05/06 18:16:26 | 000,043,520 | —- | C] () – C:\Documents and Settings\Shane Murray\Desktop\AFASA Qualifier.xls
[2010/02/25 10:06:32 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\RtlGina2.dll
[2010/02/25 10:06:31 | 000,966,765 | —- | C] () – C:\WINDOWS\System32\acAuth.dll
[2010/02/25 10:06:31 | 000,356,352 | —- | C] () – C:\WINDOWS\System32\SCMLib.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/05/29 16:27:12 | 000,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/02/23 16:09:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\AOLM.dll
[2007/06/06 16:05:17 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2007/06/06 09:37:21 | 000,000,051 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2007/06/06 09:37:21 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_2460.ini
[2007/03/02 16:31:12 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/03/02 08:51:28 | 000,000,426 | —- | C] () – C:\WINDOWS\brwmark.ini
[2007/03/02 08:51:28 | 000,000,283 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2007/03/02 08:51:28 | 000,000,153 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2007/03/02 08:51:28 | 000,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2007/03/02 08:50:57 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2007/03/02 08:48:02 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2007/03/01 16:12:18 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/02/27 02:21:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/02/25 05:22:32 | 000,192,512 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4618.dll
[2007/02/25 05:22:30 | 000,348,880 | R— | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2007/02/25 05:05:53 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2007/02/24 11:26:00 | 000,001,172 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/08/28 13:20:44 | 000,031,504 | —- | C] () – C:\WINDOWS\ezvcr.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/04 10:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll
========== LOP Check ==========
[2009/10/19 14:16:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cached Installations
[2010/02/09 09:41:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2010/02/09 09:25:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2007/03/02 08:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/03/02 13:07:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2008/08/06 18:52:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipEC
[2010/02/09 09:26:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Shane Murray\Application Data\DriverCure
[2009/05/29 16:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Shane Murray\Application Data\Leadertech
[2009/02/26 13:38:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Shane Murray\Application Data\OfficeUpdate12
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< c:\windows\system32\drivers\*.sys /90 >
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
< MD5 for: AGP440.SYS >
[2004/08/04 22:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/03/05 09:15:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 22:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2009/03/05 09:15:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/14 04:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/14 04:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 22:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/03/05 09:15:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 22:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2009/03/05 09:15:53 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/14 04:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/14 04:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 16:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 22:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2004/08/04 16:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/14 10:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 10:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 22:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/14 10:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 10:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 22:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 22:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 10:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 10:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< End of report >
Thanks