Hi
I posted this on another site a week ago, but have not received any assistance, and then I noticed that this site has seen the issue I'm having a lot and has been more helpful so I'm hoping I've finally come to the right place.
I have an XP Pro SP3 thinkpad that last week had MSE complain about a trojan found in netbt.sys that needed to be removed. I allowed it to remove it. After the reboot, my internet was no longer working. Thinkvantage's Access Connections could no longer acquire an IP address. While doing some research online, I found an XP.zip file that included a netbt registry entries file that I tried to run. I also copied over a netbt.sys from another XP Pro SP3 machine. However, still no internet.
I was able to open up the wireless Network control panel and modify the TCP/IP properties to manually assign an IP address to make the internet work, but this isn't an ideal solution, and of course I'd like to make sure there's nothing else wrong.
I have generated the logs requested and will be pasting them below. My hope is two things. 1) that the kind folks here can confirm that my computer is clean and 2) that the kind folks here can also fix my DHCP/TCP issue.
(I'll also close the thread on the other site if this one gets any noise)
Thanks!
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8351
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
12/11/2011 1:16:53 AM
mbam-log-2011-12-11 (01-16-53).txt
Scan type: Quick scan
Objects scanned: 198900
Time elapsed: 17 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-11 03:04:10
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 HITACHI_ rev.FC2Z
Running: umdim3u3.exe; Driver: C:\DOCUME~1\Justin\LOCALS~1\Temp\pwlyypog.sys
---- System - GMER 1.0.15 ----
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xBA11887E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xBA118BFE]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs tvtumon.sys (Windows Update Monitor Driver/Lenovo)
Device \FileSystem\Fastfat \Fat 9B3BFD20
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat tvtumon.sys (Windows Update Monitor Driver/Lenovo)
---- Files - GMER 1.0.15 ----
File C:\RRbackups\common 0 bytes
File C:\RRbackups\common\css.dat 8192 bytes
File C:\RRbackups\common\hints.dat 8192 bytes
File C:\RRbackups\common\mnd.dat 8192 bytes
File C:\RRbackups\common\regcerts.dat 8192 bytes
File C:\RRbackups\common\restore.log 110 bytes
File C:\RRbackups\common\rr.log 69909 bytes
File C:\RRbackups\common\SAM 28672 bytes
File C:\RRbackups\common\secpolicy.dat 65536 bytes
File C:\RRbackups\common\settings.dat 24576 bytes
File C:\RRbackups\common\system.dat 12288 bytes
File C:\RRbackups\common\tvtcmn.dat 8192 bytes
File C:\RRbackups\common\usersids.dat 18720 bytes
File C:\RRbackups\Documents and Settings 0 bytes
File C:\RRbackups\Documents and Settings\Administrator 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Lenovo\Client Security Solution\enroll.ini 50 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\51fb872f-6841-4fcc-b142-32fbd6e8d2db 388 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\2e511fc9-2bdd-43c0-89b5-49e608c59910 388 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\All Users 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo\Client Security Solution\cspContainer.dat 332 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a077ead69703e3bf1fd373a3c9376faa_bfcc9902-0b0d-478e-b538-18eadc4123e9 901 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_bfcc9902-0b0d-478e-b538-18eadc4123e9 52 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\42e7e898003fbdeb9585806ee1664b51_bfcc9902-0b0d-478e-b538-18eadc4123e9 57 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\6d14e4b1d8ca773bab785d1be032546e_bfcc9902-0b0d-478e-b538-18eadc4123e9 47 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\8f71098770f72c7a67cd8f1151619865_bfcc9902-0b0d-478e-b538-18eadc4123e9 54 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\b973ec0ff915c48a18fe09064ce3a22d_bfcc9902-0b0d-478e-b538-18eadc4123e9 56 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_bfcc9902-0b0d-478e-b538-18eadc4123e9 893 bytes
File C:\RRbackups\Documents and Settings\Default User 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo\Client Security Solution\enroll.ini 50 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\51fb872f-6841-4fcc-b142-32fbd6e8d2db 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\2e511fc9-2bdd-43c0-89b5-49e608c59910 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\Justin 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Lenovo\Client Security Solution\enroll.ini 50 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Lenovo\Client Security Solution\hibernation.dat 4 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008\6b29ae44e85efac3c72ff4d1865d73f1_bfcc9902-0b0d-478e-b538-18eadc4123e9 53 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008\83aa4cc77f591dfc2374580bbd95f6ba_bfcc9902-0b0d-478e-b538-18eadc4123e9 45 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008\8f71098770f72c7a67cd8f1151619865_bfcc9902-0b0d-478e-b538-18eadc4123e9 54 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008\932a2db58c237abd381d22df4c63a04a_bfcc9902-0b0d-478e-b538-18eadc4123e9 87 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008\f35b96bef1df0a2ec96bc1a4549be72b_bfcc9902-0b0d-478e-b538-18eadc4123e9 47 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\51fb872f-6841-4fcc-b142-32fbd6e8d2db 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\2e511fc9-2bdd-43c0-89b5-49e608c59910 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\092bb204-1787-4f48-8e7f-c08d5df38720 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\140b0fb4-1c81-4e5a-8efb-24892900935d 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\3194e0e8-c281-41aa-88a7-72dcc45347cb 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\531f034e-780c-4437-a180-5697fbb18d6e 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\6cc21406-d65b-40d1-8106-bb0b3eb38ea4 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\91b37299-705a-4855-83f7-a2d58fc57bce 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\9620ab5b-4ff5-4d65-bd9d-5b4c944b45ba 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\a133bf55-b5fc-4a16-a94a-c57c5a6807f0 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\ca5da676-e931-4e7d-ad5b-181037cdd1ad 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\LocalService 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA\S-1-5-20 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA\S-1-5-20\94498385663a229a93d423c6d144ae0b_bfcc9902-0b0d-478e-b538-18eadc4123e9 2519 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\020bf4dd-ff6c-4298-9597-6260adeea609 388 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\4fca3875-abda-428a-a5c3-449f675140c3 388 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\fdbd7737-6c76-4338-9a26-c39b0a632edb 388 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
I posted this on another site a week ago, but have not received any assistance, and then I noticed that this site has seen the issue I'm having a lot and has been more helpful so I'm hoping I've finally come to the right place.
I have an XP Pro SP3 thinkpad that last week had MSE complain about a trojan found in netbt.sys that needed to be removed. I allowed it to remove it. After the reboot, my internet was no longer working. Thinkvantage's Access Connections could no longer acquire an IP address. While doing some research online, I found an XP.zip file that included a netbt registry entries file that I tried to run. I also copied over a netbt.sys from another XP Pro SP3 machine. However, still no internet.
I was able to open up the wireless Network control panel and modify the TCP/IP properties to manually assign an IP address to make the internet work, but this isn't an ideal solution, and of course I'd like to make sure there's nothing else wrong.
I have generated the logs requested and will be pasting them below. My hope is two things. 1) that the kind folks here can confirm that my computer is clean and 2) that the kind folks here can also fix my DHCP/TCP issue.
(I'll also close the thread on the other site if this one gets any noise)
Thanks!
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8351
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
12/11/2011 1:16:53 AM
mbam-log-2011-12-11 (01-16-53).txt
Scan type: Quick scan
Objects scanned: 198900
Time elapsed: 17 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-11 03:04:10
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 HITACHI_ rev.FC2Z
Running: umdim3u3.exe; Driver: C:\DOCUME~1\Justin\LOCALS~1\Temp\pwlyypog.sys
---- System - GMER 1.0.15 ----
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xBA11887E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xBA118BFE]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs tvtumon.sys (Windows Update Monitor Driver/Lenovo)
Device \FileSystem\Fastfat \Fat 9B3BFD20
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat tvtumon.sys (Windows Update Monitor Driver/Lenovo)
---- Files - GMER 1.0.15 ----
File C:\RRbackups\common 0 bytes
File C:\RRbackups\common\css.dat 8192 bytes
File C:\RRbackups\common\hints.dat 8192 bytes
File C:\RRbackups\common\mnd.dat 8192 bytes
File C:\RRbackups\common\regcerts.dat 8192 bytes
File C:\RRbackups\common\restore.log 110 bytes
File C:\RRbackups\common\rr.log 69909 bytes
File C:\RRbackups\common\SAM 28672 bytes
File C:\RRbackups\common\secpolicy.dat 65536 bytes
File C:\RRbackups\common\settings.dat 24576 bytes
File C:\RRbackups\common\system.dat 12288 bytes
File C:\RRbackups\common\tvtcmn.dat 8192 bytes
File C:\RRbackups\common\usersids.dat 18720 bytes
File C:\RRbackups\Documents and Settings 0 bytes
File C:\RRbackups\Documents and Settings\Administrator 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Lenovo\Client Security Solution\enroll.ini 50 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\51fb872f-6841-4fcc-b142-32fbd6e8d2db 388 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\2e511fc9-2bdd-43c0-89b5-49e608c59910 388 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\All Users 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo\Client Security Solution\cspContainer.dat 332 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a077ead69703e3bf1fd373a3c9376faa_bfcc9902-0b0d-478e-b538-18eadc4123e9 901 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_bfcc9902-0b0d-478e-b538-18eadc4123e9 52 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\42e7e898003fbdeb9585806ee1664b51_bfcc9902-0b0d-478e-b538-18eadc4123e9 57 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\6d14e4b1d8ca773bab785d1be032546e_bfcc9902-0b0d-478e-b538-18eadc4123e9 47 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\8f71098770f72c7a67cd8f1151619865_bfcc9902-0b0d-478e-b538-18eadc4123e9 54 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\b973ec0ff915c48a18fe09064ce3a22d_bfcc9902-0b0d-478e-b538-18eadc4123e9 56 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_bfcc9902-0b0d-478e-b538-18eadc4123e9 893 bytes
File C:\RRbackups\Documents and Settings\Default User 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo\Client Security Solution\enroll.ini 50 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\51fb872f-6841-4fcc-b142-32fbd6e8d2db 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\2e511fc9-2bdd-43c0-89b5-49e608c59910 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\Justin 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Lenovo\Client Security Solution\enroll.ini 50 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Lenovo\Client Security Solution\hibernation.dat 4 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008\6b29ae44e85efac3c72ff4d1865d73f1_bfcc9902-0b0d-478e-b538-18eadc4123e9 53 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008\83aa4cc77f591dfc2374580bbd95f6ba_bfcc9902-0b0d-478e-b538-18eadc4123e9 45 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008\8f71098770f72c7a67cd8f1151619865_bfcc9902-0b0d-478e-b538-18eadc4123e9 54 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008\932a2db58c237abd381d22df4c63a04a_bfcc9902-0b0d-478e-b538-18eadc4123e9 87 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2909370959-4291373459-806592016-1008\f35b96bef1df0a2ec96bc1a4549be72b_bfcc9902-0b0d-478e-b538-18eadc4123e9 47 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\51fb872f-6841-4fcc-b142-32fbd6e8d2db 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1476223887-1840006797-2070763024-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\2e511fc9-2bdd-43c0-89b5-49e608c59910 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-1506970853-2517358612-4125041461-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\092bb204-1787-4f48-8e7f-c08d5df38720 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\140b0fb4-1c81-4e5a-8efb-24892900935d 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\3194e0e8-c281-41aa-88a7-72dcc45347cb 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\531f034e-780c-4437-a180-5697fbb18d6e 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\6cc21406-d65b-40d1-8106-bb0b3eb38ea4 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\91b37299-705a-4855-83f7-a2d58fc57bce 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\9620ab5b-4ff5-4d65-bd9d-5b4c944b45ba 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\a133bf55-b5fc-4a16-a94a-c57c5a6807f0 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\ca5da676-e931-4e7d-ad5b-181037cdd1ad 388 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\Protect\S-1-5-21-2909370959-4291373459-806592016-1008\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Justin\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\LocalService 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA\S-1-5-20 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA\S-1-5-20\94498385663a229a93d423c6d144ae0b_bfcc9902-0b0d-478e-b538-18eadc4123e9 2519 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\020bf4dd-ff6c-4298-9597-6260adeea609 388 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\4fca3875-abda-428a-a5c3-449f675140c3 388 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\fdbd7737-6c76-4338-9a26-c39b0a632edb 388 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes