kaz
Members-
Posts
9 -
Joined
-
Last visited
Reputation
0 Neutral-
I guess the previous thing worked. I started up the computer to do the next step and it was working. Thanks! Thanks again for all your help, you were very helpful!
-
Nope it did not work. I can right click on the bottom where the bar is? I forget what its called. Or I can right click on the icons on the bottom right but anything in the desktop is no good and nothing in folders either. Kind of weird. I didn't check if it works in a browser but I can if you think it will help. Let me know. Thanks again
-
Just wanted to say thanks for everything! You were very helpful. Also, for some reason the right click is not working on folders. Could that be a virus/malware? nothing was found when we did our scans.
-
RegUBP2b-KP.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.; A0000162.reg;C:\System Volume Information\_restore{66243962-2BA4-48E6-8796-8797B8E8991E}\RP1;Trojan.StartPage.1505;Deleted.; A0000368.reg;C:\System Volume Information\_restore{66243962-2BA4-48E6-8796-8797B8E8991E}\RP1;Trojan.StartPage.1505;Deleted.;
-
Malwarebytes' Anti-Malware 1.38 Database version: 2335 Windows 5.1.2600 Service Pack 3 6/26/2009 2:37:06 PM mbam-log-2009-06-26 (14-37-06).txt Scan type: Full Scan (C:\|) Objects scanned: 106762 Time elapsed: 20 minute(s), 20 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 9 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 12 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\apar (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\intermplug (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\parttimeb (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{6246ff85-1da0-4486-9b1d-95c0fd31158e} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{6494b9be-3a4c-11de-91d2-bd8055d89593} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{41699f6b-014e-46e5-a097-3d52f79cab65} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{5303e828-3a4c-11de-ac1c-f77f55d89593} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\documents and settings\All Users\Application Data\Microsoft\Network\DLLs (Rogue.SystemGuard2009) -> Quarantined and deleted successfully. C:\Program Files\NoAdware (Rogue.NoAdware) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\kusers.dll (Trojan.BHO) -> Quarantined and deleted successfully. c:\Qoobox\quarantine\C\WINDOWS\system32\becfdefafbfbcebf.dll.vir (Worm.AutoRun) -> Quarantined and deleted successfully. c:\Qoobox\quarantine\C\WINDOWS\system32\fadbefdadd.dll.vir (Worm.AutoRun) -> Quarantined and deleted successfully. c:\Qoobox\quarantine\C\WINDOWS\system32\kdpini.dll.vir (Trojan.BHO) -> Quarantined and deleted successfully. c:\system volume information\_restore{66243962-2ba4-48e6-8796-8797b8e8991e}\RP1\A0000015.dll (Trojan.BHO) -> Quarantined and deleted successfully. c:\system volume information\_restore{66243962-2ba4-48e6-8796-8797b8e8991e}\RP1\A0000025.dll (Worm.AutoRun) -> Quarantined and deleted successfully. c:\system volume information\_restore{66243962-2ba4-48e6-8796-8797b8e8991e}\RP1\A0000027.dll (Worm.AutoRun) -> Quarantined and deleted successfully. c:\WINDOWS\system32\15ada7cb4de13805db514a03f5c7be48.TMP (Worm.AutoRun) -> Quarantined and deleted successfully. c:\WINDOWS\system32\c545a1b00e143396eb1753fe738c832d.TMP (Worm.AutoRun) -> Quarantined and deleted successfully. c:\documents and settings\all users\application data\microsoft\Network\DLLs\c.cgm (Rogue.SystemGuard2009) -> Quarantined and deleted successfully. c:\program files\NoAdware\noadware4_020809.na (Rogue.NoAdware) -> Quarantined and deleted successfully. c:\documents and settings\All Users\Application Data\Microsoft\Network\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully. # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=4065 (20090511) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.066 (20070917) # EOSSerial=05f33e87b4ad4842b2b3326a0b379a9d # end=finished # remove_checked=true # unwanted_checked=false # utc_time=2009-05-11 08:53:14 # local_time=2009-05-11 04:53:14 (-0500, Eastern Daylight Time) # country="United States" # osver=5.1.2600 NT Service Pack 3 # scanned=85090 # found=12 # scan_time=1110 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudSpywareGuard.zip Win32/Bagle.gen.zip worm (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudSpywareGuard1.zip Win32/Bagle.gen.zip worm (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudSpywareGuard2.zip Win32/Bagle.gen.zip worm (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudSpywareGuard3.zip Win32/Bagle.gen.zip worm (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch1.zip Win32/Bagle.gen.zip worm (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch5.zip Win32/Bagle.gen.zip worm (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\KP\Local Settings\Temporary Internet Files\Content.IE5\08UJK75O\g748[1].mp4 Win32/BHO.NNZ trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\KP\Local Settings\Temporary Internet Files\Content.IE5\08UJK75O\g890[1].mp4 Win32/BHO.NNZ trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\KP\Local Settings\Temporary Internet Files\Content.IE5\1OUFF4MU\g210[1].mp4 Win32/BHO.NNZ trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\KP\Local Settings\Temporary Internet Files\Content.IE5\1OUFF4MU\u644[1].ini Win32/BHO.NNZ trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\KP\Local Settings\Temporary Internet Files\Content.IE5\9T7HMVE7\u332[1].ini Win32/BHO.NNZ trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\WINDOWS\system32\kusers.dll a variant of Win32/BHO.NKS trojan (unable to clean - deleted (after the next restart)) 00000000000000000000000000000000 Malwarebytes' Anti-Malware 1.38 Database version: 2339 Windows 5.1.2600 Service Pack 3 6/26/2009 3:43:08 PM mbam-log-2009-06-26 (15-43-08).txt Scan type: Full Scan (C:\|) Objects scanned: 107358 Time elapsed: 20 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
-
I am able to start malwarebytes now!!! Should I update and do a full scan and fix then post results?
-
! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SYSTEM\select Current REG_DWORD 0x1 Default REG_DWORD 0x1 Failed REG_DWORD 0x0 LastKnownGood REG_DWORD 0x2 ComboFix 09-06-24.04 - KP 06/25/2009 14:27.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.308 [GMT -4:00] Running from: c:\documents and settings\KP\Desktop\fixfix.exe Command switches used :: c:\documents and settings\KP\Desktop\CFScript.txt . ((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-06-25 ))))))))))))))))))))))))))))))) . 2009-06-25 09:53 . 2009-06-25 09:53 -------- dc----w- c:\windows\system32\dllcache\cache . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-25 00:25 . 2009-02-12 22:17 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-06-25 00:23 . 2009-02-12 22:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-07 03:46 . 2009-06-07 03:46 312847 ------w- c:\windows\system32\c545a1b00e143396eb1753fe738c832d.TMP 2009-06-06 23:19 . 2009-05-18 16:14 205840 ----a-w- c:\windows\system32\kusers.dll 2009-06-04 16:36 . 2009-02-12 22:17 -------- d-----w- c:\program files\SpywareBlaster 2009-05-11 20:34 . 2009-05-11 20:33 -------- d-----w- c:\program files\EsetOnlineScanner 2009-05-07 15:32 . 2001-08-23 12:00 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-29 04:56 . 2001-08-23 12:00 827392 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:55 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-04-17 12:26 . 2001-08-23 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2008-11-09 00:27 585216 ----a-w- c:\windows\system32\rpcrt4.dll . ------- Sigcheck ------- [7] 2004-08-04 07:56 14336 8F078AE4ED187AAABC0A305146DE6716 c:\windows\$NtServicePackUninstall$\svchost.exe [7] 2008-04-14 00:12 14336 27C6D03BCDB8CFEB96B716F3D8BE3E18 c:\windows\ServicePackFiles\i386\svchost.exe [7] 2008-04-14 00:12 14336 27C6D03BCDB8CFEB96B716F3D8BE3E18 c:\windows\system32\svchost.exe [7] 2008-04-14 00:12 14336 27C6D03BCDB8CFEB96B716F3D8BE3E18 c:\windows\system32\dllcache\cache\svchost.exe [-] 2004-06-17 17:58 560128 31FB2D788A9AA618452C02E8375B6DCD c:\windows\$hf_mig$\KB840987\SP1QFE\user32.dll [7] 2004-08-04 07:56 577024 C72661F8552ACE7C5C85E16A3CF505C4 c:\windows\$NtServicePackUninstall$\user32.dll [-] 2001-08-23 12:00 561152 BE57A5C3ABD240514B98F6BCA872FB21 c:\windows\$NtUninstallKB840987$\user32.dll [7] 2008-04-14 00:12 578560 B26B135FF1B9F60C9388B4A7D16F600B c:\windows\ServicePackFiles\i386\user32.dll [7] 2008-04-14 00:12 578560 B26B135FF1B9F60C9388B4A7D16F600B c:\windows\system32\user32.dll [7] 2008-04-14 00:12 578560 B26B135FF1B9F60C9388B4A7D16F600B c:\windows\system32\dllcache\cache\user32.dll [7] 2004-08-04 07:56 82944 2ED0B7F12A60F90092081C50FA0EC2B2 c:\windows\$NtServicePackUninstall$\ws2_32.dll [7] 2008-04-14 00:12 82432 2CCC474EB85CEAA3E1FA1726580A3E5A c:\windows\ServicePackFiles\i386\ws2_32.dll [7] 2008-04-14 00:12 82432 2CCC474EB85CEAA3E1FA1726580A3E5A c:\windows\system32\ws2_32.dll [7] 2008-04-14 00:12 82432 2CCC474EB85CEAA3E1FA1726580A3E5A c:\windows\system32\dllcache\cache\ws2_32.dll [7] 2008-08-20 05:33 667648 C91E3A6EF094202F6B5CA8960DFCF243 c:\windows\$hf_mig$\KB956390\SP2QFE\wininet.dll [7] 2008-08-20 05:30 666112 9AF5F25124FBDC36E2B510729CBA2674 c:\windows\$hf_mig$\KB956390\SP3GDR\wininet.dll [7] 2008-08-20 04:58 666624 94418F53D2612C26DBADC04DAFBC197C c:\windows\$hf_mig$\KB956390\SP3QFE\wininet.dll [7] 2008-08-26 09:08 827904 77C192FE56A70D7FA0247BA0A6201C32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll [7] 2008-10-16 10:20 667648 93C9D0A216498EE14EB9B26119BB95EE c:\windows\$hf_mig$\KB958215\SP2QFE\wininet.dll [7] 2008-10-16 01:00 666112 1576318BF08D28CC61D1278114AD8D5B c:\windows\$hf_mig$\KB958215\SP3GDR\wininet.dll [7] 2008-10-16 01:04 667136 E8FCE58A470999350F64C591557F9E42 c:\windows\$hf_mig$\KB958215\SP3QFE\wininet.dll [7] 2008-10-16 20:24 827904 0D5B75171FF51775B630A431B6C667E8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll [7] 2008-12-20 23:56 827904 044E0A4E9FE97C0FB9AFE9C89E2A82E6 c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll [7] 2009-03-03 00:17 828416 C8667854873938CA13C986F16B0CD183 c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll [7] 2009-04-29 04:49 828928 62CCA075F44015147B8971DAFFBCFF76 c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\wininet.dll [7] 2004-08-04 07:56 656384 C0823FC5469663BA63E7DB88F9919D70 c:\windows\$NtServicePackUninstall$\wininet.dll [7] 2004-08-04 07:56 656384 C0823FC5469663BA63E7DB88F9919D70 c:\windows\$NtUninstallKB956390$\wininet.dll [7] 2008-08-20 05:38 659456 87E694D09893978F22024FEEEDF35342 c:\windows\$NtUninstallKB958215$\wininet.dll [-] 2001-08-23 12:00 593920 CF9F1EEF71F42EDE71B6F4AA05D5CA1A c:\windows\$NtUninstallQ309521$\wininet.dll [7] 2008-10-16 10:37 659456 6F1E4BFD78C4E0D05FF3725D59B72925 c:\windows\ie7\wininet.dll [7] 2007-08-13 23:54 818688 A4A0FC92358F39538A6494C42EF99FE9 c:\windows\ie7updates\KB956390-IE7\wininet.dll [7] 2008-08-26 07:24 826368 EF8EBA98145BFA44E80D17A3B3453300 c:\windows\ie7updates\KB958215-IE7\wininet.dll [7] 2008-10-16 20:38 826368 6741EAF7B7F110E803A6E38F6E5FA6B0 c:\windows\ie7updates\KB961260-IE7\wininet.dll [7] 2008-12-20 23:15 826368 A82935D32D0672E8FF4E91AE398E901C c:\windows\ie7updates\KB963027-IE7\wininet.dll [7] 2009-03-03 00:18 826368 28775945CCD53DEE280EF58DEA1A94C4 c:\windows\ie7updates\KB969897-IE7\wininet.dll [7] 2008-04-14 00:12 666112 7A4F775ABB2F1C97DEF3E73AFA2FAEDD c:\windows\ServicePackFiles\i386\wininet.dll [7] 2008-08-26 07:24 826368 EF8EBA98145BFA44E80D17A3B3453300 c:\windows\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2GDR\wininet.dll [7] 2008-08-26 09:08 827904 77C192FE56A70D7FA0247BA0A6201C32 c:\windows\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2QFE\wininet.dll [7] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D83B0DDB c:\windows\SoftwareDistribution\Download\82c738ec00f0f07f8ea182bc95439593\sp3gdr\wininet.dll [7] 2009-04-29 04:49 828928 62CCA075F44015147B8971DAFFBCFF76 c:\windows\SoftwareDistribution\Download\82c738ec00f0f07f8ea182bc95439593\sp3qfe\wininet.dll [7] 2008-10-16 20:38 826368 6741EAF7B7F110E803A6E38F6E5FA6B0 c:\windows\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2GDR\wininet.dll [7] 2008-10-16 20:24 827904 0D5B75171FF51775B630A431B6C667E8 c:\windows\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2QFE\wininet.dll [7] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D83B0DDB c:\windows\system32\wininet.dll [7] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D83B0DDB c:\windows\system32\dllcache\wininet.dll [7] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D83B0DDB c:\windows\system32\dllcache\cache\wininet.dll [7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys [7] 2004-08-04 06:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtServicePackUninstall$\tcpip.sys [7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys [7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\ServicePackFiles\i386\tcpip.sys [7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\system32\dllcache\tcpip.sys [7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\system32\dllcache\cache\tcpip.sys [7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\system32\drivers\tcpip.sys [-] 2004-05-27 01:38 483328 E7F9D2E4E4A94A6F58014E5FFA16A65E c:\windows\$hf_mig$\KB840987\SP1QFE\winlogon.exe [-] 2004-05-27 01:38 483328 E7F9D2E4E4A94A6F58014E5FFA16A65E c:\windows\$hf_mig$\KB841533\SP1QFE\winlogon.exe [7] 2004-08-04 07:56 502272 01C3346C241652F43AED8E2149881BFE c:\windows\$NtServicePackUninstall$\winlogon.exe [-] 2001-08-23 12:00 430080 2B0E480E975EE51F2D5CE5F068FED6E2 c:\windows\$NtUninstallKB841533$\winlogon.exe [7] 2008-04-14 00:12 507904 ED0EF0A136DEC83DF69F04118870003E c:\windows\ServicePackFiles\i386\winlogon.exe [7] 2008-04-14 00:12 507904 ED0EF0A136DEC83DF69F04118870003E c:\windows\system32\winlogon.exe [7] 2008-04-14 00:12 507904 ED0EF0A136DEC83DF69F04118870003E c:\windows\system32\dllcache\cache\winlogon.exe [7] 2004-08-04 06:14 182912 558635D3AF1C7546D26067D5D9B6959E c:\windows\$NtServicePackUninstall$\ndis.sys [7] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE71721130D c:\windows\ServicePackFiles\i386\ndis.sys [7] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE71721130D c:\windows\system32\dllcache\cache\ndis.sys [7] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE71721130D c:\windows\system32\drivers\ndis.sys [7] 2004-08-04 06:00 29056 4448006B6BC60E6C027932CFC38D6855 c:\windows\$NtServicePackUninstall$\ip6fw.sys [7] 2008-04-13 18:53 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\ServicePackFiles\i386\ip6fw.sys [7] 2008-04-13 18:53 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\system32\dllcache\cache\ip6fw.sys [7] 2008-04-13 18:53 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\system32\drivers\ip6fw.sys [-] 2004-06-17 08:03 1954688 ED0D7A5F1138CCFD3ECAF8F6AC691F13 c:\windows\$hf_mig$\KB840987\SP1QFE\ntkrnlpa.exe [7] 2009-02-06 10:30 2066176 607352B9CB3D708C67F6039097801B5A c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe [7] 2008-08-14 09:18 2062976 63EC865DFF6CCFC7BEF94B5C50297CAD c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe [7] 2008-08-14 09:33 2066048 4AC58F03EB94A72809949D757FC39D80 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe [7] 2008-08-14 20:39 2066048 A25E9B86EFFB2AF33BF51E676B68BFB0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe [7] 2008-08-14 09:22 2057728 BA002228743B6824D87F0551DBC86D45 c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe [7] 2002-02-25 20:33 1897856 01FD1F7C82B263F1667A1CEA095756C5 c:\windows\$NtUninstallKB840987$\ntkrnlpa.exe [7] 2008-08-14 09:33 2066048 4AC58F03EB94A72809949D757FC39D80 c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe [7] 2008-04-13 18:31 2065792 109F8E3E3C82E337BB71B6BC9B895D61 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe [7] 2004-08-04 05:58 2056832 947FB1D86D14AFCFFDB54BF837EC25D0 c:\windows\$NtUninstallKB956841_0$\ntkrnlpa.exe [-] 2001-08-23 12:00 1896704 46E2E3DCF54B819CFB2EBFE48A22B5C9 c:\windows\$NtUninstallQ317277$\ntkrnlpa.exe [7] 2009-02-07 23:02 2066048 5BA7F2141BC6DB06100D0E5A732C617A c:\windows\Driver Cache\i386\ntkrnlpa.exe [7] 2008-04-13 18:31 2065792 109F8E3E3C82E337BB71B6BC9B895D61 c:\windows\ServicePackFiles\i386\ntkrnlpa.exe [7] 2009-02-07 23:02 2066048 5BA7F2141BC6DB06100D0E5A732C617A c:\windows\system32\ntkrnlpa.exe [7] 2009-02-07 23:02 2066048 5BA7F2141BC6DB06100D0E5A732C617A c:\windows\system32\dllcache\ntkrnlpa.exe [7] 2009-02-07 23:02 2066048 5BA7F2141BC6DB06100D0E5A732C617A c:\windows\system32\dllcache\cache\ntkrnlpa.exe [-] 2004-06-17 17:22 2051584 F240DC474F8EDB2D95514D831DF069E5 c:\windows\$hf_mig$\KB840987\SP1QFE\ntoskrnl.exe [7] 2009-02-07 23:35 2189184 EFE8EACE83EAAD5849A7A548FB75B584 c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe [7] 2008-08-14 09:57 2185984 CE69DBD54221F2D40E49FF6DB77C6507 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe [7] 2008-08-14 10:11 2189184 EEAF32F8E15A24F62BECB1BD403BB5C5 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe [7] 2008-08-14 21:11 2189184 31914172342BFF330063F343AC6958FE c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe [7] 2008-08-14 10:00 2180352 21C91DA9CB53AA8A37041BA9684A8458 c:\windows\$NtServicePackUninstall$\ntoskrnl.exe [7] 2002-02-25 20:33 1875584 257AAFD1F77990355BB6E83650D52680 c:\windows\$NtUninstallKB840987$\ntoskrnl.exe [7] 2008-08-14 10:11 2189184 EEAF32F8E15A24F62BECB1BD403BB5C5 c:\windows\$NtUninstallKB956572$\ntoskrnl.exe [7] 2008-04-13 19:27 2188928 0C89243C7C3EE199B96FCC16990E0679 c:\windows\$NtUninstallKB956841$\ntoskrnl.exe [7] 2004-08-04 06:19 2180992 CE218BC7088681FAA06633E218596CA7 c:\windows\$NtUninstallKB956841_0$\ntoskrnl.exe [-] 2001-08-23 12:00 1982208 A29222D5281056E497408FCC9062F749 c:\windows\$NtUninstallQ317277$\ntoskrnl.exe [7] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63F5212B c:\windows\Driver Cache\i386\ntoskrnl.exe [7] 2008-04-13 19:27 2188928 0C89243C7C3EE199B96FCC16990E0679 c:\windows\ServicePackFiles\i386\ntoskrnl.exe [7] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63F5212B c:\windows\system32\ntoskrnl.exe [7] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63F5212B c:\windows\system32\dllcache\ntoskrnl.exe [7] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63F5212B c:\windows\system32\dllcache\cache\ntoskrnl.exe [7] 2008-04-14 00:12 1033728 12896823FB95BFB3DC9B46BCAEDC9923 c:\windows\explorer.exe [7] 2004-08-04 07:56 1032192 A0732187050030AE399B241436565E64 c:\windows\$NtServicePackUninstall$\explorer.exe [7] 2008-04-14 00:12 1033728 12896823FB95BFB3DC9B46BCAEDC9923 c:\windows\ServicePackFiles\i386\explorer.exe [7] 2008-04-14 00:12 1033728 12896823FB95BFB3DC9B46BCAEDC9923 c:\windows\system32\dllcache\cache\explorer.exe [7] 2009-02-06 11:06 110592 020CEAAEDC8EB655B6506B8C70D53BB6 c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe [7] 2004-08-04 07:56 108032 C6CE6EEC82F187615D1002BB3BB50ED4 c:\windows\$NtServicePackUninstall$\services.exe [7] 2008-04-14 00:12 108544 0E776ED5F7CC9F94299E70461B7B8185 c:\windows\$NtUninstallKB956572$\services.exe [7] 2008-04-14 00:12 108544 0E776ED5F7CC9F94299E70461B7B8185 c:\windows\ServicePackFiles\i386\services.exe [7] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225C37315 c:\windows\system32\services.exe [7] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225C37315 c:\windows\system32\dllcache\services.exe [7] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225C37315 c:\windows\system32\dllcache\cache\services.exe [7] 2004-08-04 07:56 13312 84885F9B82F4D55C6146EBF6065D75D2 c:\windows\$NtServicePackUninstall$\lsass.exe [7] 2008-04-14 00:12 13312 BF2466B3E18E970D8A976FB95FC1CA85 c:\windows\ServicePackFiles\i386\lsass.exe [7] 2008-04-14 00:12 13312 BF2466B3E18E970D8A976FB95FC1CA85 c:\windows\system32\lsass.exe [7] 2008-04-14 00:12 13312 BF2466B3E18E970D8A976FB95FC1CA85 c:\windows\system32\dllcache\cache\lsass.exe [7] 2004-08-04 07:56 15360 24232996A38C0B0CF151C2140AE29FC8 c:\windows\$NtServicePackUninstall$\ctfmon.exe [7] 2008-04-14 00:12 15360 5F1D5F88303D4A4DBC8E5F97BA967CC3 c:\windows\ServicePackFiles\i386\ctfmon.exe [7] 2008-04-14 00:12 15360 5F1D5F88303D4A4DBC8E5F97BA967CC3 c:\windows\system32\ctfmon.exe [7] 2008-04-14 00:12 15360 5F1D5F88303D4A4DBC8E5F97BA967CC3 c:\windows\system32\dllcache\cache\ctfmon.exe [7] 2004-08-04 07:56 57856 7435B108B935E42EA92CA94F59C8E717 c:\windows\$NtServicePackUninstall$\spoolsv.exe [7] 2008-04-14 00:12 57856 D8E14A61ACC1D4A6CD0D38AEBAC7FA3B c:\windows\ServicePackFiles\i386\spoolsv.exe [7] 2008-04-14 00:12 57856 D8E14A61ACC1D4A6CD0D38AEBAC7FA3B c:\windows\system32\spoolsv.exe [7] 2008-04-14 00:12 57856 D8E14A61ACC1D4A6CD0D38AEBAC7FA3B c:\windows\system32\dllcache\cache\spoolsv.exe [7] 2004-08-04 07:56 111104 4126D27CECE4471E00E425411F7306B5 c:\windows\$NtServicePackUninstall$\wuauclt.exe [7] 2008-04-14 00:12 111104 ED7262E52C31CF1625B65039102BC16C c:\windows\ServicePackFiles\i386\wuauclt.exe [7] 2008-10-16 19:09 51224 E654B78D2F1D791B30D0ED9A8195EC22 c:\windows\system32\wuauclt.exe [7] 2008-10-16 19:09 51224 E654B78D2F1D791B30D0ED9A8195EC22 c:\windows\system32\dllcache\wuauclt.exe [7] 2008-10-16 19:09 51224 E654B78D2F1D791B30D0ED9A8195EC22 c:\windows\system32\dllcache\cache\wuauclt.exe [7] 2004-08-04 07:56 24576 39B1FFB03C2296323832ACBAE50D2AFF c:\windows\$NtServicePackUninstall$\userinit.exe [7] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7380F89 c:\windows\ServicePackFiles\i386\userinit.exe [7] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7380F89 c:\windows\system32\userinit.exe [7] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7380F89 c:\windows\system32\dllcache\cache\userinit.exe [7] 2004-08-04 07:56 295424 B60C877D16D9C880B952FDA04ADF16E6 c:\windows\$NtServicePackUninstall$\termsrv.dll [-] 2001-08-23 12:00 197632 458635D2E4559526CF9C895340A38702 c:\windows\$NtUninstallQ311889$\termsrv.dll [7] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\ServicePackFiles\i386\termsrv.dll [7] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\system32\termsrv.dll [7] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\system32\dllcache\cache\termsrv.dll [-] 2004-06-17 17:58 930816 FCA73DE7B988A2F7837FFBFFCFBED088 c:\windows\$hf_mig$\KB840987\SP1QFE\kernel32.dll [7] 2009-03-21 13:59 991744 DA11D9D6ECBDF0F93436A4B7C13F7BEC c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll [7] 2004-08-04 07:56 983552 888190E31455FAD793312F8D087146EB c:\windows\$NtServicePackUninstall$\kernel32.dll [-] 2001-08-23 12:00 926720 379B0B31D7F8D2C9F7FF302B454A6C54 c:\windows\$NtUninstallKB840987$\kernel32.dll [7] 2008-04-14 00:11 989696 C24B983D211C34DA8FCC1AC38477971D c:\windows\$NtUninstallKB959426$\kernel32.dll [7] 2008-04-14 00:11 989696 C24B983D211C34DA8FCC1AC38477971D c:\windows\ServicePackFiles\i386\kernel32.dll [7] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBBBE95F3 c:\windows\system32\kernel32.dll [7] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBBBE95F3 c:\windows\system32\dllcache\kernel32.dll [7] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBBBE95F3 c:\windows\system32\dllcache\cache\kernel32.dll [7] 2004-08-04 07:56 17408 1B5F6923ABB450692E9FE0672C897AED c:\windows\$NtServicePackUninstall$\powrprof.dll [7] 2008-04-14 00:12 17408 50A166237A0FA771261275A405646CC0 c:\windows\ServicePackFiles\i386\powrprof.dll [7] 2008-04-14 00:12 17408 50A166237A0FA771261275A405646CC0 c:\windows\system32\powrprof.dll [7] 2008-04-14 00:12 17408 50A166237A0FA771261275A405646CC0 c:\windows\system32\dllcache\cache\powrprof.dll [7] 2004-08-04 07:56 110080 87CA7CE6469577F059297B9D6556D66D c:\windows\$NtServicePackUninstall$\imm32.dll [7] 2008-04-14 00:11 110080 0DA85218E92526972A821587E6A8BF8F c:\windows\ServicePackFiles\i386\imm32.dll [7] 2008-04-14 00:11 110080 0DA85218E92526972A821587E6A8BF8F c:\windows\system32\imm32.dll [7] 2008-04-14 00:11 110080 0DA85218E92526972A821587E6A8BF8F c:\windows\system32\dllcache\cache\imm32.dll [7] 2004-08-04 07:56 1580544 30A609E00BD1D4FFC49D6B5A432BE7F2 c:\windows\$NtServicePackUninstall$\sfcfiles.dll [-] 2001-08-23 12:00 1562112 9E415EFDF50F26BCBC97C80F4E6C30CC c:\windows\$NtUninstallQ309521$\sfcfiles.dll [7] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D29CE79 c:\windows\ServicePackFiles\i386\sfcfiles.dll [7] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D29CE79 c:\windows\system32\sfcfiles.dll [7] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D29CE79 c:\windows\system32\dllcache\cache\sfcfiles.dll [7] 2004-08-04 05:58 24576 EBDEE8A2EE5393890A1ACEE971C4C246 c:\windows\$NtServicePackUninstall$\kbdclass.sys [7] 2008-04-13 18:39 24576 463C1EC80CD17420A542B7F36A36F128 c:\windows\ServicePackFiles\i386\kbdclass.sys [7] 2008-04-13 18:39 24576 463C1EC80CD17420A542B7F36A36F128 c:\windows\system32\dllcache\cache\kbdclass.sys [7] 2008-04-13 18:39 24576 463C1EC80CD17420A542B7F36A36F128 c:\windows\system32\drivers\kbdclass.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-05 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648] "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784] "systemguard"="c:\program files\System Guard 2009\systemguard.exe" [bU] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\caeabaafbabae] [bU] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Ares\\Ares.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/3/2008 10:33 PM 24652] S0 099f7efc868878f48d536500a0e0000d;099f7efc868878f48d536500a0e0000d;c:\windows\system32\099f7efc868878f48d536500a0e0000d.sys --> c:\windows\system32\099f7efc868878f48d536500a0e0000d.sys [?] S0 4b63c2aff10254dae185d1bbe7c1a4a5;4b63c2aff10254dae185d1bbe7c1a4a5;c:\windows\system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys --> c:\windows\system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys [?] . . ------- Supplementary Scan ------- . uLocal Page = \blank.htm uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html IE: &Search - ?p=ZKxdm021QUUS FF - ProfilePath - . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-25 14:31 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . c:\program files\AIM6\aolsoftware.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2009-06-25 14:36 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-25 18:36 Pre-Run: 73,983,549,440 bytes free Post-Run: 73,973,960,704 bytes free 249 --- E O F --- 2009-06-25 09:10
-
Hi and thanks! OS: XP Home SP3 IE7 and Firefox is the default browser Here is ARK.txt GMER 1.0.15.14972 - http://www.gmer.net Rootkit scan 2009-06-25 05:38:52 Windows 5.1.2600 Service Pack 3 ---- System - GMER 1.0.15 ---- Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) ZwCreateKey [0xF8575C8E] Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) ZwEnumerateKey [0xF8575D13] Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) ZwOpenKey [0xF8575C10] Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) ZwQueryDirectoryFile [0xF8575999] Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) IoCreateFile Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) NtQueryDirectoryFile ---- Kernel code sections - GMER 1.0.15 ---- PAGE ntoskrnl.exe!ZwOpenKey 80568D59 3 Bytes JMP F8575C14 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) PAGE ntoskrnl.exe!ZwOpenKey + 4 80568D5D 1 Byte [78] PAGE ntoskrnl.exe!IoCreateFile 8056CC6B 5 Bytes JMP F8575872 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) PAGE ntoskrnl.exe!ZwCreateKey 8057065D 3 Bytes JMP F8575C92 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) PAGE ntoskrnl.exe!ZwCreateKey + 4 80570661 1 Byte [78] PAGE ntoskrnl.exe!ZwEnumerateKey 80570D64 7 Bytes JMP F8575D17 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) PAGE ntoskrnl.exe!NtQueryDirectoryFile 80572111 5 Bytes JMP F857599D 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc) ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9D54] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9D54] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9D54] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9D54] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC) ---- Services - GMER 1.0.15 ---- Service C:\WINDOWS\system32\099f7efc868878f48d536500a0e0000d.sys (*** hidden *** ) [bOOT] 099f7efc868878f48d536500a0e0000d <-- ROOTKIT !!! Service C:\WINDOWS\system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys (*** hidden *** ) [bOOT] 4b63c2aff10254dae185d1bbe7c1a4a5 <-- ROOTKIT !!! ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@c ®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\099f7efc868878f4 8d536500a0e0000d&download_period=846000&first_download_delay=180&version=2&ip_0 =586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&i p_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails _3=2&ips_count=4&name=099f7efc868878f48d536500a0e0000d&path=system32\099f7efc86 8878f48d536500a0e0000d.sys&wmid=Dnr001&idate=2009-02-21 12:18:44:953&last_download_time=2009-6-20 16:23:18.0&first_skip=1&last_update_ip_pos=0&fails_0=3 Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@ErrorCo ntrol 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@Tag 7 Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@ImagePa th system32\099f7efc868878f48d536500a0e0000d.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@Display Name 099f7efc868878f48d536500a0e0000d Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@Group System Bus Extender Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d\Securit y Reg HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d\Securit y@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5 Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@c ®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\4b63c2aff10254da e185d1bbe7c1a4a5&download_period=846000&first_download_delay=180&version=2&ip_0 =586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&i p_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails _3=2&ips_count=4&name=4b63c2aff10254dae185d1bbe7c1a4a5&path=system32\4b63c2aff1 0254dae185d1bbe7c1a4a5.sys&wmid=Dep005&idate=2009-02-08 21:49:13:454&last_download_time=2009-6-20 16:23:18.15&first_skip=1&last_update_ip_pos=0&fails_0=2 Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@ErrorCo ntrol 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Tag 6 Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@ImagePa th system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Display Name 4b63c2aff10254dae185d1bbe7c1a4a5 Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Group System Bus Extender Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5\Securit y Reg HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5\Securit y@Security 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@c ®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\099f7efc868878f4 8d536500a0e0000d&download_period=846000&first_download_delay=180&version=2&ip_0 =586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&i p_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails _3=2&ips_count=4&name=099f7efc868878f48d536500a0e0000d&path=system32\099f7efc86 8878f48d536500a0e0000d.sys&wmid=Dnr001&idate=2009-02-21 12:18:44:953&last_download_time=2009-6-20 16:23:18.0&first_skip=1&last_update_ip_pos=0&fails_0=3 Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@Type 1 Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@Start 0 Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@ErrorContro l 0 Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@Tag 7 Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@ImagePath system32\099f7efc868878f48d536500a0e0000d.sys Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@DisplayName 099f7efc868878f48d536500a0e0000d Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@Group System Bus Extender Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d\Security Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d\Security@Se curity 0x01 0x00 0x14 0x80 ... Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5 Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@c ®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\4b63c2aff10254da e185d1bbe7c1a4a5&download_period=846000&first_download_delay=180&version=2&ip_0 =586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&i p_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails _3=2&ips_count=4&name=4b63c2aff10254dae185d1bbe7c1a4a5&path=system32\4b63c2aff1 0254dae185d1bbe7c1a4a5.sys&wmid=Dep005&idate=2009-02-08 21:49:13:454&last_download_time=2009-6-20 16:23:18.15&first_skip=1&last_update_ip_pos=0&fails_0=2 Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Type 1 Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Start 0 Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@ErrorContro l 0 Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Tag 6 Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@ImagePath system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@DisplayName 4b63c2aff10254dae185d1bbe7c1a4a5 Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Group System Bus Extender Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5\Security Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5\Security@Se curity 0x01 0x00 0x14 0x80 ... ---- Files - GMER 1.0.15 ---- File C:\WINDOWS\system32\099f7efc868878f48d536500a0e0000d.sys 39936 bytes executable <-- ROOTKIT !!! File C:\WINDOWS\system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys 39936 bytes executable <-- ROOTKIT !!! ---- EOF - GMER 1.0.15 ---- =============================================================================== Here is the combofix ComboFix 09-06-24.04 - KP 06/25/2009 5:45.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.261 [GMT -4:00] Running from: c:\documents and settings\KP\Desktop\fixfix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\becfdefafbfbcebf.dll c:\windows\system32\caeabaafbabae.dll c:\windows\system32\fadbefdadd.dll c:\windows\reged.exe c:\windows\sys.com c:\windows\system32\kdpini.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_MYWEBSEARCHSERVICE ((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-06-25 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-25 00:25 . 2009-02-12 22:17 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-06-25 00:23 . 2009-02-12 22:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-07 03:46 . 2009-06-07 03:46 312847 ------w- c:\windows\system32\c545a1b00e143396eb1753fe738c832d.TMP 2009-06-06 23:19 . 2009-05-18 16:14 205840 ----a-w- c:\windows\system32\kusers.dll 2009-06-04 16:36 . 2009-02-12 22:17 -------- d-----w- c:\program files\SpywareBlaster 2009-05-11 20:34 . 2009-05-11 20:33 -------- d-----w- c:\program files\EsetOnlineScanner 2009-05-07 15:32 . 2001-08-23 12:00 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-29 04:56 . 2001-08-23 12:00 827392 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:55 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-04-17 12:26 . 2001-08-23 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2008-11-09 00:27 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-17 09:14 . 2009-04-05 17:42 66576 ----a-w- c:\program files\mozilla firefox\components\fadbefdadd.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "SpybotDeletingD7526"="del" [X] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648] "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784] "AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Ares\\Ares.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/3/2008 10:33 PM 24652] . Contents of the 'Scheduled Tasks' folder . - - - - ORPHANS REMOVED - - - - BHO-{F70F6880-3A4B-11DE-8230-0B7C55D89593} - (no file) HKCU-Run-DriverCure - c:\program files\ParetoLogic\DriverCure\DriverCure.exe HKLM-Run-systemguard - c:\program files\System Guard 2009\systemguard.exe Notify-caeabaafbabae - (no file) . ------- Supplementary Scan ------- . uLocal Page = \blank.htm uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html IE: &Search - ?p=ZKxdm021QUUS FF - ProfilePath - . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-25 05:50 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\windows\system32\099f7efc868878f48d536500a0e0000d.sys 39936 bytes executable c:\windows\system32\_099f7efc868878f48d536500a0e0000d.sys_.vir 39936 bytes executable c:\windows\system32\_4b63c2aff10254dae185d1bbe7c1a4a5.sys_.vir 39936 bytes executable c:\windows\system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys 39936 bytes executable scan completed successfully hidden files: 4 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\099f7efc868878f48d536500a0e0000d] "ImagePath"="system32\099f7efc868878f48d536500a0e0000d.sys" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\4b63c2aff10254dae185d1bbe7c1a4a5] "ImagePath"="system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys" . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\wscntfy.exe c:\program files\AIM6\aolsoftware.exe . ************************************************************************** . Completion time: 2009-06-25 5:54 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-25 09:54 Pre-Run: 74,055,819,264 bytes free Post-Run: 73,980,219,392 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn 117 --- E O F --- 2009-06-25 09:10
-
Hi, I can't get malewarebytes to start. I tried installing nod32 also and that won't install. Something is keeping the programs from starting up. Ive tried renaming the mbam.exe to another name and that has not worked. I used that avira antivirus and it scanned and did not allow me to start up malewarebytes in safe mode. Spybot is allowed to start though, which is wierd. I scan and it finds some stuff and deletes it but does not seem to have any affect on me getting malewarebytes to work or nod32. I also can't go to websites for nod32 or malewarebytes...etc. Seems to be blocking sites like that. I believe I have had antivirus2009 installed but I deleted it I believe and spybot deleted it too I think. Ive run out of ideas so I am posting here. I am about ready to format but thought id give this a try first. Any help would be greatly appreciated. Thanks in advance.