I'm not sure if it is malware or not but I figured it was the best place to start. I ran the TFC but when it finished, or appeared to finish, nothing came up. Nothing was happening for a long period of time (over ten minutes) so I clicked on exit but nothing happened. I tried the 'x' in the top right corner and it still didnt work. I went to the task manager and it stated that the program was not responding. When I clicked to shut it down the entire screen went black except for "safe mode" in the four corners. I'm not sure if this finished doing its thing or not because of this. After this I downloaded and ran ERUNT and let it do its thing.
I also ran MBAM. It stated there were 2 infected files. I clicked to remove them and restarted the computer but it was no better. I then ran it again in safe mode and it stated there were no infected files. I will include the Log at the end.
I have downloaded and run GMER and OTL as well and will include the Log's at the bottom.
MBAM Log:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4235
Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 8.0.6001.18904
24/06/2010 7:10:15 PM
mbam-log-2010-06-24 (19-10-15).txt
Scan type: Quick scan
Objects scanned: 125536
Time elapsed: 4 minute(s), 16 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL Log (Extras Log did not appear along with OTL after running it twice):
OTL logfile created on: 24/06/2010 8:17:51 PM - Run 2
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Users\Benjamin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.87 Gb Total Space | 135.11 Gb Free Space | 60.90% Space Free | Partition Type: NTFS
Drive D: | 11.01 Gb Total Space | 1.52 Gb Free Space | 13.77% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: BENJAMIN-PC
Current User Name: Benjamin
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/06/24 19:54:01 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\Benjamin\Desktop\OTL.exe
PRC - [2009/04/11 03:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010/06/24 19:54:01 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\Benjamin\Desktop\OTL.exe
MOD - [2010/03/05 11:01:02 | 000,420,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
MOD - [2009/04/11 03:28:25 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiutils.dll
MOD - [2009/04/11 03:28:25 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wbemsvc.dll
MOD - [2009/04/11 03:28:25 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wbemprox.dll
MOD - [2009/04/11 03:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\fastprox.dll
MOD - [2009/04/11 03:27:47 | 000,241,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\rsaenh.dll
MOD - [2009/04/11 03:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/20 23:24:58 | 000,188,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wbemdisp.dll
MOD - [2008/01/20 23:24:37 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
MOD - [2008/01/20 23:24:13 | 000,376,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sxs.dll
MOD - [2008/01/20 23:23:53 | 000,357,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbemcomn.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/05/17 06:57:49 | 000,055,992 | ---- | M] (F-Secure Corporation) [On_Demand | Stopped] -- C:\Program Files\eastlinkinternetsecurityservices\ORSP Client\fsorsp.exe -- (FSORSPClient)
SRV - [2010/05/11 15:23:35 | 002,478,640 | ---- | M] () [Auto | Stopped] -- c:\Program Files\Common Files\Akamai\rswin_3697.dll -- (Akamai)
SRV - [2010/03/05 12:44:23 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/11/18 13:08:32 | 000,188,840 | ---- | M] (F-Secure Corporation) [Auto | Stopped] -- C:\Program Files\eastlinkinternetsecurityservices\Common\FSMA32.EXE -- (FSMA)
SRV - [2009/11/18 13:07:30 | 000,524,712 | ---- | M] (F-Secure Corporation) [On_Demand | Stopped] -- C:\Program Files\eastlinkinternetsecurityservices\FWES\Program\fsdfwd.exe -- (FSDFWD)
SRV - [2009/11/18 13:06:20 | 000,221,608 | ---- | M] (F-Secure Corporation) [Auto | Stopped] -- C:\Program Files\eastlinkinternetsecurityservices\Anti-Virus\fsgk32st.exe -- (F-Secure Gatekeeper Handler Starter)
SRV - [2009/09/24 22:27:04 | 000,793,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2008/01/20 23:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/01/04 18:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Stopped] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
========== Driver Services (SafeList) ==========
DRV - [2010/06/02 10:10:03 | 000,113,864 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\eastlinkinternetsecurityservices\Anti-Virus\minifilter\fsgk.sys -- (F-Secure Gatekeeper)
DRV - [2010/03/30 07:39:18 | 000,033,920 | ---- | M] () [Kernel | Boot | Stopped] -- C:\Windows\system32\Drivers\fsbts.sys -- (fsbts)
DRV - [2010/03/25 07:22:30 | 000,035,792 | ---- | M] (F-Secure Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\fses.sys -- (FSES)
DRV - [2009/11/18 13:08:18 | 000,069,928 | ---- | M] (F-Secure Corporation) [Kernel | System | Stopped] -- C:\Program Files\eastlinkinternetsecurityservices\HIPS\drivers\fshs.sys -- (F-Secure HIPS)
DRV - [2009/11/18 13:07:30 | 000,072,904 | ---- | M] (F-Secure Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\fsdfw.sys -- (FSFW)
DRV - [2009/11/18 13:06:22 | 000,041,640 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Program Files\eastlinkinternetsecurityservices\Anti-Virus\win2k\fsfilter.sys -- (F-Secure Filter)
DRV - [2009/11/18 13:06:22 | 000,027,048 | ---- | M] () [Kernel | Disabled | Stopped] -- C:\Program Files\eastlinkinternetsecurityservices\Anti-Virus\win2k\fsrec.sys -- (F-Secure Recognizer)
DRV - [2009/11/18 13:06:22 | 000,014,248 | ---- | M] () [Kernel | System | Stopped] -- C:\Program Files\eastlinkinternetsecurityservices\Anti-Virus\minifilter\fsvista.sys -- (fsvista)
DRV - [2009/04/11 01:42:54 | 000,073,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2009/01/07 17:57:58 | 000,030,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\point32k.sys -- (Point32)
DRV - [2008/07/03 14:03:48 | 002,152,088 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/05/22 16:20:54 | 000,020,640 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\PC-Doctor for Windows\pcd5srvc.pkms -- (PCD5SRVC{BD6912E3-AC9D80E8-05040000})
DRV - [2008/03/25 06:44:24 | 002,307,072 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\igdkmd32.sys -- (igfx)
DRV - [2008/02/14 11:56:02 | 000,118,784 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/02/12 12:27:34 | 000,207,360 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HSXHWBS3.sys -- (HSXHWBS3)
DRV - [2008/02/12 12:26:20 | 000,661,504 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HSX_CNXT.sys -- (winachsf)
DRV - [2008/02/12 12:25:22 | 000,985,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HSX_DP.sys -- (HSF_DP)
DRV - [2008/01/20 23:23:27 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008/01/20 23:23:27 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008/01/20 23:23:27 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008/01/20 23:23:26 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008/01/20 23:23:26 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008/01/20 23:23:26 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008/01/20 23:23:25 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008/01/20 23:23:25 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008/01/20 23:23:24 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008/01/20 23:23:24 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel®
DRV - [2008/01/20 23:23:24 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008/01/20 23:23:23 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008/01/20 23:23:23 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008/01/20 23:23:23 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008/01/20 23:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008/01/20 23:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008/01/20 23:23:23 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2008/01/20 23:23:22 | 000,342,584 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008/01/20 23:23:21 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008/01/20 23:23:21 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008/01/20 23:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008/01/20 23:23:20 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008/01/20 23:23:00 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008/01/20 23:23:00 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008/01/20 23:23:00 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/10/18 12:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2006/11/02 06:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 06:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 06:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 06:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 06:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 06:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 06:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 06:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 06:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 06:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 06:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 05:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 05:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 05:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 05:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 05:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 05:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 04:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...rio&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...rio&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.acadiau.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\eastlinkinternetsecurityservices\NRS\litmu[email protected] [2010/05/26 08:07:59 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2006/09/18 18:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\eastlinkinternetsecurityservices\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\eastlinkinternetsecurityservices\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DVDAgent] c:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\eastlinkinternetsecurityservices\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files\eastlinkinternetsecurityservices\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [EPSON Stylus CX4800 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [HPADVISOR] File not found
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident\4.0; File not found
O4 - Startup: C:\Users\Benjamin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\eastlinkinternetsecurityservices\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\eastlinkinternetsecurityservices\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\eastlinkinternetsecurityservices\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\eastlinkinternetsecurityservices\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\eastlinkinternetsecurityservices\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\eastlinkinternetsecurityservices\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\eastlinkinternetsecurityservices\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Benjamin\Desktop\March 2nd\DSCN5672.JPG
O24 - Desktop BackupWallPaper: C:\Users\Benjamin\Desktop\March 2nd\DSCN5672.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/18 14:03:16 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{94dbfd15-1929-11de-89f8-0021856052f9}\Shell\AutoRun\command - "" = G:\RECYCLER\s-124-52-632-236-125-2632636\autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/20 23:34:27 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: aux - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\Windows\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - C:\Windows\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\Windows\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\Windows\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\Windows\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.iyuv - C:\Windows\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\Windows\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\Windows\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\Windows\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\Windows\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\Windows\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\Windows\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - C:\Windows\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\Windows\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 90 Days ==========
[2010/06/24 19:53:58 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Users\Benjamin\Desktop\OTL.exe
[2010/06/24 18:36:32 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010/06/24 18:24:51 | 000,000,000 | ---D | C] -- C:\Users\Benjamin\AppData\Roaming\Malwarebytes
[2010/06/24 18:24:41 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/06/24 18:24:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/06/24 18:24:40 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/06/24 18:24:40 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/24 18:23:33 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/06/24 18:22:39 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/06/24 17:18:31 | 000,444,416 | ---- | C] (OldTimer Tools) -- C:\Users\Benjamin\Desktop\TFC.exe
[2010/06/23 19:44:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[2010/06/23 19:38:20 | 000,000,000 | ---D | C] -- C:\Users\Benjamin\AppData\Roaming\WinBatch
[2010/05/30 20:24:04 | 000,000,000 | ---D | C] -- C:\Users\Benjamin\Desktop\Cameron
========== Files - Modified Within 90 Days ==========
[2010/06/24 20:18:15 | 003,407,872 | -HS- | M] () -- C:\Users\Benjamin\ntuser.dat
[2010/06/24 20:03:30 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/06/24 20:03:12 | 167,755,549 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/06/24 19:54:01 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\Benjamin\Desktop\OTL.exe
[2010/06/24 19:25:57 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/24 19:25:57 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/24 19:25:53 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/06/24 19:23:48 | 000,524,288 | -HS- | M] () -- C:\Users\Benjamin\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/06/24 19:23:48 | 000,065,536 | -HS- | M] () -- C:\Users\Benjamin\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/06/24 19:22:18 | 001,678,774 | -H-- | M] () -- C:\Users\Benjamin\AppData\Local\IconCache.db
[2010/06/24 19:22:17 | 000,000,424 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{18BE3ED8-5A60-462C-92BF-F6C87935EB11}.job
[2010/06/24 18:32:47 | 000,293,376 | ---- | M] () -- C:\Users\Benjamin\Desktop\gmer.exe
[2010/06/24 18:32:33 | 000,284,915 | ---- | M] () -- C:\Users\Benjamin\Desktop\gmer.zip
[2010/06/24 18:24:44 | 000,000,824 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/24 18:22:52 | 000,000,919 | ---- | M] () -- C:\Users\Benjamin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/06/24 18:22:39 | 000,000,739 | ---- | M] () -- C:\Users\Benjamin\Desktop\NTREGOPT.lnk
[2010/06/24 18:22:39 | 000,000,720 | ---- | M] () -- C:\Users\Benjamin\Desktop\ERUNT.lnk
[2010/06/24 17:59:01 | 000,333,192 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/06/24 17:18:32 | 000,444,416 | ---- | M] (OldTimer Tools) -- C:\Users\Benjamin\Desktop\TFC.exe
[2010/06/24 15:08:37 | 000,001,356 | ---- | M] () -- C:\Users\Benjamin\AppData\Local\d3d9caps.dat
[2010/06/24 13:49:19 | 000,000,508 | ---- | M] () -- C:\Windows\tasks\Scheduled scanning task.job
[2010/06/23 21:24:14 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLec.DAT
[2010/06/23 21:24:14 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLds.DAT
[2010/06/17 19:43:55 | 000,023,128 | ---- | M] () -- C:\error.fstmp
[2010/06/17 00:00:02 | 000,000,000 | ---- | M] () -- C:\infect.fstmp
[2010/06/07 18:01:37 | 000,058,368 | ---- | M] () -- C:\Users\Benjamin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/07 05:09:54 | 004,486,516 | ---- | M] () -- C:\Users\Benjamin\Desktop\DSCN6236.AVI
[2010/06/06 02:11:18 | 005,637,372 | ---- | M] () -- C:\Users\Benjamin\Desktop\DSCN6227.AVI
[2010/06/05 10:13:14 | 000,702,128 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/06/05 10:13:14 | 000,607,070 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/06/05 10:13:14 | 000,108,692 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/05/26 01:28:06 | 001,934,672 | ---- | M] () -- C:\Users\Benjamin\Desktop\DSCN6057.JPG
[2010/05/24 20:19:08 | 000,161,366 | ---- | M] () -- C:\Users\Benjamin\Desktop\green.htm
[2010/05/17 19:41:44 | 000,000,433 | ---- | M] () -- C:\Users\Benjamin\Application Data\Microsoft\Internet Explorer\Quick Launch\parentsDEC06 - Shortcut.lnk
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/06 14:21:37 | 000,317,285 | ---- | M] () -- C:\Windows\System32\EPPRTDRV.CAB
[2010/04/06 14:21:36 | 000,449,762 | ---- | M] () -- C:\Windows\System32\EPSETUP.CAB
[2010/04/06 14:21:36 | 000,008,284 | ---- | M] () -- C:\Windows\System32\eps_icon.avi
[2010/04/06 14:21:33 | 000,613,965 | ---- | M] () -- C:\Windows\System32\EPSTP32U.CAB
[2010/04/06 14:20:47 | 000,000,771 | ---- | M] () -- C:\Users\Public\Desktop\EPSON Scan.lnk
[2010/04/04 21:00:15 | 000,010,851 | ---- | M] () -- C:\Users\Benjamin\Desktop\newborn3.jpg
[2010/03/30 07:39:18 | 000,033,920 | ---- | M] () -- C:\Windows\System32\drivers\fsbts.sys
[2010/03/29 10:54:14 | 000,000,623 | ---- | M] () -- C:\Users\Benjamin\Application Data\Microsoft\Internet Explorer\Quick Launch\DSCN4961 - Shortcut.lnk
========== Files Created - No Company Name ==========
[2010/06/24 18:36:23 | 167,755,549 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/06/24 18:32:32 | 000,284,915 | ---- | C] () -- C:\Users\Benjamin\Desktop\gmer.zip
[2010/06/24 18:24:44 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/24 18:22:52 | 000,000,919 | ---- | C] () -- C:\Users\Benjamin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/06/24 18:22:39 | 000,000,739 | ---- | C] () -- C:\Users\Benjamin\Desktop\NTREGOPT.lnk
[2010/06/24 18:22:39 | 000,000,720 | ---- | C] () -- C:\Users\Benjamin\Desktop\ERUNT.lnk
[2010/06/17 00:00:02 | 000,023,128 | ---- | C] () -- C:\error.fstmp
[2010/06/17 00:00:02 | 000,000,000 | ---- | C] () -- C:\infect.fstmp
[2010/06/07 18:01:36 | 004,486,516 | ---- | C] () -- C:\Users\Benjamin\Desktop\DSCN6236.AVI
[2010/06/06 14:22:02 | 005,637,372 | ---- | C] () -- C:\Users\Benjamin\Desktop\DSCN6227.AVI
[2010/05/26 14:43:00 | 001,934,672 | ---- | C] () -- C:\Users\Benjamin\Desktop\DSCN6057.JPG
[2010/05/24 20:19:06 | 000,161,366 | ---- | C] () -- C:\Users\Benjamin\Desktop\green.htm
[2010/05/17 19:41:44 | 000,000,433 | ---- | C] () -- C:\Users\Benjamin\Application Data\Microsoft\Internet Explorer\Quick Launch\parentsDEC06 - Shortcut.lnk
[2010/04/06 14:21:36 | 000,008,284 | ---- | C] () -- C:\Windows\System32\eps_icon.avi
[2010/04/06 14:21:34 | 000,317,285 | ---- | C] () -- C:\Windows\System32\EPPRTDRV.CAB
[2010/04/06 14:21:33 | 000,613,965 | ---- | C] () -- C:\Windows\System32\EPSTP32U.CAB
[2010/04/06 14:21:33 | 000,449,762 | ---- | C] () -- C:\Windows\System32\EPSETUP.CAB
[2010/04/06 14:21:33 | 000,005,729 | ---- | C] () -- C:\Windows\System32\EPSTP32U.DAT
[2010/04/06 14:20:47 | 000,000,771 | ---- | C] () -- C:\Users\Public\Desktop\EPSON Scan.lnk
[2010/04/04 21:01:23 | 000,010,851 | ---- | C] () -- C:\Users\Benjamin\Desktop\newborn3.jpg
[2010/03/29 10:54:14 | 000,000,623 | ---- | C] () -- C:\Users\Benjamin\Application Data\Microsoft\Internet Explorer\Quick Launch\DSCN4961 - Shortcut.lnk
[2009/09/17 08:07:38 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/02/10 11:33:44 | 000,033,920 | ---- | C] () -- C:\Windows\System32\drivers\fsbts.sys
[2008/08/18 14:33:39 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1461.dll
[2008/08/18 13:44:22 | 000,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom25.dll
[2008/08/18 13:44:22 | 000,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes25.dll
[2006/11/02 09:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 04:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2010/01/10 14:22:05 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Elluminate
[2010/03/26 00:00:00 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\F-Secure
[2009/11/28 21:57:34 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\GanymedeNet
[2008/12/08 23:41:32 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Nikon
[2010/02/17 11:32:16 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Out of the Park Developments
[2009/03/29 18:41:01 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\Template
[2008/12/16 13:09:07 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\WildTangent
[2010/06/23 19:38:20 | 000,000,000 | ---D | M] -- C:\Users\Benjamin\AppData\Roaming\WinBatch
[2010/06/24 19:24:29 | 000,032,600 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/24 13:49:19 | 000,000,508 | ---- | M] () -- C:\Windows\Tasks\Scheduled scanning task.job
[2010/06/24 19:22:17 | 000,000,424 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{18BE3ED8-5A60-462C-92BF-F6C87935EB11}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/08/18 14:03:16 | 000,000,074 | ---- | M] () -- C:\autoexec.bat
[2009/04/11 03:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2008/08/18 14:25:26 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2006/09/18 18:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010/06/17 19:43:55 | 000,023,128 | ---- | M] () -- C:\error.fstmp
[2010/06/23 19:47:31 | 000,000,250 | ---- | M] () -- C:\FINIS_IT.TXT
[2010/06/17 00:00:02 | 000,000,000 | ---- | M] () -- C:\infect.fstmp
[2009/07/10 14:44:47 | 000,000,741 | -H-- | M] () -- C:\IPH.PH
[2010/06/24 20:03:12 | 2449,948,672 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2006/11/02 09:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 08:31:42 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtmsft.dll
[2009/03/08 08:31:37 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\dxtrans.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2008/01/21 00:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 00:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 00:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 07:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 07:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\user32.dll /md5 >
[2009/04/11 03:28:25 | 000,627,712 | ---- | M] (Microsoft Corporation) MD5=75510147B94598407666F4802797C75A -- C:\Windows\System32\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2008/01/20 23:24:48 | 000,179,200 | ---- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B -- C:\Windows\System32\ws2_32.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< End of report >
GMER Log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-24 20:48:58
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Benjamin\AppData\Local\Temp\kxlyikow.sys
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!SetWindowsHookExW 772F87AD 5 Bytes JMP 71F09A75 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!CallNextHookEx 772F8E3B 5 Bytes JMP 71EFD101 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!UnhookWindowsHookEx 772F98DB 5 Bytes JMP 71E7466E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!CreateWindowExW 77301305 5 Bytes JMP 71F0DAC4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!DialogBoxParamW 773210B0 5 Bytes JMP 71E35505 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!DialogBoxIndirectParamW 77322EF5 5 Bytes JMP 7200473F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!DialogBoxParamA 77338152 5 Bytes JMP 720046DC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!DialogBoxIndirectParamA 7733847D 5 Bytes JMP 720047A2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!MessageBoxIndirectA 7734D4D9 5 Bytes JMP 72004671 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!MessageBoxIndirectW 7734D5D3 5 Bytes JMP 72004606 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!MessageBoxExA 7734D639 5 Bytes JMP 720045A4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] USER32.dll!MessageBoxExW 7734D65D 5 Bytes JMP 72004542 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] ole32.dll!OleLoadFromStream 76761E12 5 Bytes JMP 72004AA7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[356] ole32.dll!CoCreateInstance 76799EA6 5 Bytes JMP 71F0DB20 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!SetWindowsHookExW 772F87AD 5 Bytes JMP 71F09A75 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!CallNextHookEx 772F8E3B 5 Bytes JMP 71EFD101 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!UnhookWindowsHookEx 772F98DB 5 Bytes JMP 71E7466E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!CreateWindowExW 77301305 5 Bytes JMP 71F0DAC4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!DialogBoxParamW 773210B0 5 Bytes JMP 71E35505 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!DialogBoxIndirectParamW 77322EF5 5 Bytes JMP 7200473F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!DialogBoxParamA 77338152 5 Bytes JMP 720046DC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!DialogBoxIndirectParamA 7733847D 5 Bytes JMP 720047A2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!MessageBoxIndirectA 7734D4D9 5 Bytes JMP 72004671 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!MessageBoxIndirectW 7734D5D3 5 Bytes JMP 72004606 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!MessageBoxExA 7734D639 5 Bytes JMP 720045A4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] USER32.dll!MessageBoxExW 7734D65D 5 Bytes JMP 72004542 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] ole32.dll!OleLoadFromStream 76761E12 5 Bytes JMP 72004AA7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[496] ole32.dll!CoCreateInstance 76799EA6 5 Bytes JMP 71F0DB20 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2008] USER32.dll!CreateWindowExW 77301305 5 Bytes JMP 71F0DAC4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2008] USER32.dll!DialogBoxParamW 773210B0 5 Bytes JMP 71E35505 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2008] USER32.dll!DialogBoxIndirectParamW 77322EF5 5 Bytes JMP 7200473F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2008] USER32.dll!DialogBoxParamA 77338152 5 Bytes JMP 720046DC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2008] USER32.dll!DialogBoxIndirectParamA 7733847D 5 Bytes JMP 720047A2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2008] USER32.dll!MessageBoxIndirectA 7734D4D9 5 Bytes JMP 72004671 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2008] USER32.dll!MessageBoxIndirectW 7734D5D3 5 Bytes JMP 72004606 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2008] USER32.dll!MessageBoxExA 7734D639 5 Bytes JMP 720045A4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2008] USER32.dll!MessageBoxExW 7734D65D 5 Bytes JMP 72004542 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Any help that you can provide would be awesome.
Thanks