ChristopherLorking Posted March 27, 2012 ID:537897 Share Posted March 27, 2012 Hi there,Attached is a log file from Rootkit Unhooker run on an XP Pro SP3 machine - at the bottom are TWO unknown/hidden drivers.I hope this is the correct place to post this - please let me know if the DDS log needs to be posted BEFORE anyone can help with this issue.If the DDS is required, I will run it as soon as I can and post the log.RkUnhooker report generator v0.7==============================================Rootkit Unhooker kernel version: 3.7.300.505==============================================Windows Major Version: 5Windows Minor Version: 1Windows Build Number: 2600==============================================>DriversDriver: C:\WINDOWS\system32\DRIVERS\igxpmp32.sysAddress: 0xB90D0000Size: 6320128 bytesDriver: C:\WINDOWS\system32\drivers\RtkHDAud.sysAddress: 0xA79D4000Size: 6103040 bytesDriver: C:\WINDOWS\System32\igxpdx32.DLLAddress: 0xBF322000Size: 3518464 bytesDriver: C:\WINDOWS\System32\igxpdv32.DLLAddress: 0xBF05E000Size: 2899968 bytesDriver: C:\WINDOWS\system32\ntkrnlpa.exeAddress: 0x804D7000Size: 2154496 bytesDriver: PnpManagerAddress: 0x804D7000Size: 2154496 bytesDriver: RAWAddress: 0x804D7000Size: 2154496 bytesDriver: WMIxWDMAddress: 0x804D7000Size: 2154496 bytesDriver: Win32kAddress: 0xBF800000Size: 1871872 bytesDriver: C:\WINDOWS\System32\win32k.sysAddress: 0xBF800000Size: 1871872 bytesDriver: Ntfs.sysAddress: 0xB9DC6000Size: 577536 bytesDriver: C:\WINDOWS\system32\DRIVERS\Wdf01000.sysAddress: 0xA7711000Size: 503808 bytesDriver: C:\WINDOWS\system32\DRIVERS\mrxsmb.sysAddress: 0xA77B4000Size: 458752 bytesDriver: mfehidk.sysAddress: 0xB9E6A000Size: 454656 bytesDriver: C:\WINDOWS\system32\DRIVERS\update.sysAddress: 0xB8F0E000Size: 385024 bytesDriver: C:\WINDOWS\system32\DRIVERS\tcpip.sysAddress: 0xA78D4000Size: 364544 bytesDriver: C:\WINDOWS\system32\DRIVERS\srv.sysAddress: 0xA6918000Size: 360448 bytesDriver: C:\WINDOWS\System32\ATMFD.DLLAddress: 0xBF67D000Size: 290816 bytesDriver: C:\WINDOWS\System32\Drivers\HTTP.sysAddress: 0xA59FB000Size: 266240 bytesDriver: C:\WINDOWS\System32\igxpgd32.dllAddress: 0xBF024000Size: 237568 bytesDriver: C:\WINDOWS\system32\DRIVERS\k57xp32.sysAddress: 0xB905E000Size: 221184 bytesDriver: C:\WINDOWS\system32\DRIVERS\rdpdr.sysAddress: 0xB8F6C000Size: 196608 bytesDriver: ACPI.sysAddress: 0xB9F79000Size: 188416 bytesDriver: C:\WINDOWS\system32\DRIVERS\mrxdav.sysAddress: 0xA6A60000Size: 184320 bytesDriver: NDIS.sysAddress: 0xB9D99000Size: 184320 bytesDriver: C:\WINDOWS\system32\drivers\mfeavfk.sysAddress: 0xB8FC4000Size: 176128 bytesDriver: C:\WINDOWS\system32\DRIVERS\rdbss.sysAddress: 0xA7824000Size: 176128 bytesDriver: C:\WINDOWS\system32\DRIVERS\HDAudBus.sysAddress: 0xB9094000Size: 163840 bytesDriver: C:\WINDOWS\system32\DRIVERS\netbt.sysAddress: 0xA7871000Size: 163840 bytesDriver: dmio.sysAddress: 0xB9F23000Size: 155648 bytesDriver: C:\WINDOWS\system32\DRIVERS\ipnat.sysAddress: 0xA7899000Size: 155648 bytesDriver: C:\WINDOWS\system32\drivers\portcls.sysAddress: 0xA79B0000Size: 147456 bytesDriver: C:\WINDOWS\system32\DRIVERS\USBPORT.SYSAddress: 0xB903A000Size: 147456 bytesDriver: C:\WINDOWS\system32\DRIVERS\ks.sysAddress: 0xB9017000Size: 143360 bytesDriver: C:\WINDOWS\System32\Drivers\RDPWD.SYSAddress: 0xA5708000Size: 143360 bytesDriver: C:\WINDOWS\System32\drivers\afd.sysAddress: 0xA784F000Size: 139264 bytesDriver: ACPI_HALAddress: 0x806E5000Size: 134528 bytesDriver: C:\WINDOWS\system32\hal.dllAddress: 0x806E5000Size: 134528 bytesDriver: fltMgr.sysAddress: 0xB9EEB000Size: 131072 bytesDriver: ftdisk.sysAddress: 0xB9F49000Size: 126976 bytesDriver: C:\WINDOWS\system32\drivers\mfeapfk.sysAddress: 0xA55CA000Size: 114688 bytesDriver: Mup.sysAddress: 0xB9D7F000Size: 106496 bytesDriver: atapi.sysAddress: 0xB9F0B000Size: 98304 bytesDriver: C:\WINDOWS\System32\Drivers\dump_atapi.sysAddress: 0xA76F9000Size: 98304 bytesDriver: KSecDD.sysAddress: 0xB9E53000Size: 94208 bytesDriver: C:\WINDOWS\system32\DRIVERS\ndiswan.sysAddress: 0xB9000000Size: 94208 bytesDriver: C:\WINDOWS\system32\drivers\mfetdi2k.sysAddress: 0xA78BF000Size: 86016 bytesDriver: C:\WINDOWS\system32\drivers\wdmaud.sysAddress: 0xA6ADB000Size: 86016 bytesDriver: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYSAddress: 0xB90BC000Size: 81920 bytesDriver: C:\WINDOWS\system32\DRIVERS\ipsec.sysAddress: 0xA792D000Size: 77824 bytesDriver: C:\WINDOWS\System32\drivers\dxg.sysAddress: 0xBF000000Size: 73728 bytesDriver: C:\WINDOWS\System32\igxprd32.dllAddress: 0xBF012000Size: 73728 bytesDriver: sr.sysAddress: 0xB9ED9000Size: 73728 bytesDriver: pci.sysAddress: 0xB9F68000Size: 69632 bytesDriver: C:\WINDOWS\system32\DRIVERS\psched.sysAddress: 0xB8FEF000Size: 69632 bytesDriver: C:\WINDOWS\System32\Drivers\Cdfs.SYSAddress: 0xBA2B8000Size: 65536 bytesDriver: C:\WINDOWS\system32\DRIVERS\cdrom.sysAddress: 0xB96E7000Size: 65536 bytesDriver: C:\WINDOWS\system32\DRIVERS\serial.sysAddress: 0xB9707000Size: 65536 bytesDriver: C:\WINDOWS\system32\drivers\drmk.sysAddress: 0xBA1A8000Size: 61440 bytesDriver: C:\WINDOWS\system32\DRIVERS\redbook.sysAddress: 0xB96D7000Size: 61440 bytesDriver: C:\WINDOWS\system32\drivers\sysaudio.sysAddress: 0xA6C10000Size: 61440 bytesDriver: C:\WINDOWS\system32\DRIVERS\usbhub.sysAddress: 0xBA178000Size: 61440 bytesDriver: C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYSAddress: 0xBA0E8000Size: 53248 bytesDriver: C:\WINDOWS\system32\drivers\mfebopk.sysAddress: 0xA5616000Size: 53248 bytesDriver: C:\WINDOWS\system32\DRIVERS\rasl2tp.sysAddress: 0xBA128000Size: 53248 bytesDriver: VolSnap.sysAddress: 0xBA0C8000Size: 53248 bytesDriver: C:\WINDOWS\system32\DRIVERS\WDFLDR.SYSAddress: 0xBA218000Size: 53248 bytesDriver: C:\WINDOWS\system32\drivers\mfetdik.sysAddress: 0xBA1D8000Size: 49152 bytesDriver: C:\WINDOWS\system32\DRIVERS\raspptp.sysAddress: 0xBA148000Size: 49152 bytesDriver: C:\WINDOWS\System32\Drivers\Fips.SYSAddress: 0xBA1F8000Size: 45056 bytesDriver: C:\WINDOWS\system32\DRIVERS\imapi.sysAddress: 0xB96F7000Size: 45056 bytesDriver: MountMgr.sysAddress: 0xBA0B8000Size: 45056 bytesDriver: C:\WINDOWS\system32\DRIVERS\raspppoe.sysAddress: 0xBA138000Size: 45056 bytesDriver: isapnp.sysAddress: 0xBA0A8000Size: 40960 bytesDriver: C:\WINDOWS\system32\drivers\LMIRfsDriver.sysAddress: 0xA6C40000Size: 40960 bytesDriver: C:\WINDOWS\System32\Drivers\NDProxy.SYSAddress: 0xBA188000Size: 40960 bytesDriver: C:\WINDOWS\system32\DRIVERS\termdd.sysAddress: 0xBA168000Size: 40960 bytesDriver: disk.sysAddress: 0xBA0D8000Size: 36864 bytesDriver: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYSAddress: 0xBA208000Size: 36864 bytesDriver: C:\WINDOWS\system32\DRIVERS\intelppm.sysAddress: 0xB9717000Size: 36864 bytesDriver: C:\WINDOWS\system32\DRIVERS\msgpc.sysAddress: 0xBA158000Size: 36864 bytesDriver: C:\WINDOWS\system32\DRIVERS\netbios.sysAddress: 0xBA1E8000Size: 36864 bytesDriver: C:\WINDOWS\system32\DRIVERS\wanarp.sysAddress: 0xBA2A8000Size: 36864 bytesDriver: C:\WINDOWS\System32\Drivers\Npfs.SYSAddress: 0xBA468000Size: 32768 bytesDriver: C:\WINDOWS\system32\DRIVERS\usbccgp.sysAddress: 0xBA378000Size: 32768 bytesDriver: C:\WINDOWS\system32\DRIVERS\usbehci.sysAddress: 0xBA408000Size: 32768 bytesDriver: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYSAddress: 0xBA450000Size: 28672 bytesDriver: C:\WINDOWS\system32\DRIVERS\NuidFltr.sysAddress: 0xBA480000Size: 28672 bytesDriver: C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYSAddress: 0xBA328000Size: 28672 bytesDriver: C:\WINDOWS\system32\DRIVERS\usbprint.sysAddress: 0xBA470000Size: 28672 bytesDriver: C:\WINDOWS\system32\DRIVERS\kbdclass.sysAddress: 0xBA428000Size: 24576 bytesDriver: C:\WINDOWS\system32\DRIVERS\mouclass.sysAddress: 0xBA430000Size: 24576 bytesDriver: C:\WINDOWS\System32\Drivers\rkhdrv40.SYSAddress: 0xBA4A0000Size: 24576 bytesDriver: C:\WINDOWS\System32\Drivers\TDTCP.SYSAddress: 0xBA4A8000Size: 24576 bytesDriver: C:\WINDOWS\system32\DRIVERS\usbuhci.sysAddress: 0xBA400000Size: 24576 bytesDriver: C:\WINDOWS\System32\drivers\vga.sysAddress: 0xBA458000Size: 24576 bytesDriver: C:\WINDOWS\System32\Drivers\Msfs.SYSAddress: 0xBA460000Size: 20480 bytesDriver: PartMgr.sysAddress: 0xBA330000Size: 20480 bytesDriver: C:\WINDOWS\system32\DRIVERS\ptilink.sysAddress: 0xBA418000Size: 20480 bytesDriver: C:\WINDOWS\system32\DRIVERS\raspti.sysAddress: 0xBA420000Size: 20480 bytesDriver: C:\WINDOWS\system32\DRIVERS\TDI.SYSAddress: 0xBA410000Size: 20480 bytesDriver: C:\WINDOWS\System32\watchdog.sysAddress: 0xBA388000Size: 20480 bytesDriver: C:\WINDOWS\system32\DRIVERS\kbdhid.sysAddress: 0xA779C000Size: 16384 bytesDriver: C:\WINDOWS\system32\DRIVERS\mssmbios.sysAddress: 0xB9D3B000Size: 16384 bytesDriver: C:\WINDOWS\system32\DRIVERS\ndisuio.sysAddress: 0xA75E5000Size: 16384 bytesDriver: C:\WINDOWS\system32\DRIVERS\serenum.sysAddress: 0xBA588000Size: 16384 bytesDriver: C:\WINDOWS\system32\BOOTVID.dllAddress: 0xBA4B8000Size: 12288 bytesDriver: C:\WINDOWS\System32\drivers\Dxapi.sysAddress: 0xA7794000Size: 12288 bytesDriver: C:\WINDOWS\system32\DRIVERS\hidusb.sysAddress: 0xB8236000Size: 12288 bytesDriver: C:\WINDOWS\System32\Drivers\i2omgmt.SYSAddress: 0xB8FB0000Size: 12288 bytesDriver: C:\WINDOWS\system32\DRIVERS\mouhid.sysAddress: 0xB822E000Size: 12288 bytesDriver: C:\WINDOWS\system32\DRIVERS\ndistapi.sysAddress: 0xBA58C000Size: 12288 bytesDriver: C:\WINDOWS\system32\DRIVERS\rasacd.sysAddress: 0xB8FA8000Size: 12288 bytesDriver: 00000018Address: 0xBA5A8000Size: 8192 bytesDriver: C:\WINDOWS\System32\Drivers\Beep.SYSAddress: 0xBA5DA000Size: 8192 bytesDriver: dmload.sysAddress: 0xBA5AE000Size: 8192 bytesDriver: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYSAddress: 0xBA642000Size: 8192 bytesDriver: C:\WINDOWS\System32\Drivers\Fs_Rec.SYSAddress: 0xBA5D8000Size: 8192 bytesDriver: intelide.sysAddress: 0xBA5AC000Size: 8192 bytesDriver: C:\WINDOWS\system32\KDCOM.DLLAddress: 0xBA5A8000Size: 8192 bytesDriver: C:\WINDOWS\System32\Drivers\mnmdd.SYSAddress: 0xBA5DC000Size: 8192 bytesDriver: C:\Program Files\LogMeIn\x86\RaInfo.sysAddress: 0xBA66E000Size: 8192 bytesDriver: C:\WINDOWS\System32\DRIVERS\RDPCDD.sysAddress: 0xBA5DE000Size: 8192 bytesDriver: C:\WINDOWS\system32\DRIVERS\swenum.sysAddress: 0xBA5D2000Size: 8192 bytesDriver: C:\WINDOWS\system32\DRIVERS\USBD.SYSAddress: 0xBA5D4000Size: 8192 bytesDriver: C:\WINDOWS\system32\DRIVERS\WMILIB.SYSAddress: 0xBA5AA000Size: 8192 bytesDriver: C:\WINDOWS\system32\DRIVERS\audstub.sysAddress: 0xBA79F000Size: 4096 bytesDriver: C:\WINDOWS\System32\drivers\dxgthk.sysAddress: 0xBA707000Size: 4096 bytesDriver: C:\WINDOWS\system32\DRIVERS\lmimirr.sysAddress: 0xBA79E000Size: 4096 bytesDriver: C:\WINDOWS\System32\Drivers\Null.SYSAddress: 0xBA776000Size: 4096 bytesDriver: pciide.sysAddress: 0xBA670000Size: 4096 bytes!!!!!!!!!!!Hidden driver: 00000056Loaded from: Address: 0x8AA18053Size: 4013 bytes==============================================>StealthUnknown page with executable codeAddress: 0x8AA1A58FSize: 2673Unknown page with executable codeAddress: 0x8AA18053Size: 4013 Link to post Share on other sites More sharing options...
RPMcMurphy Posted March 29, 2012 ID:538143 Share Posted March 29, 2012 Hello and welcome. Please follow these guidelines while we work on your PC:Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!Please do not run any scans or install/uninstall any applications without being directed to do so.Any underlined text in my posts indicates a clickable link.If you have any questions at all, please stop and ask before proceeding. Please download DDS by sUBs from one of the following links and save it to your desktop.DDS.scrDDS.comDDS.pifDisable any script blocking protection (How to Disable your Security Programs)Double click DDS icon to run the tool (may take up to 3 minutes to run)When done, DDS.txt will open.After a few moments, attach.txt will open in a second window.Save both reports to your desktop.---------------------------------------------------Post the contents of the DDS.txt report in your next replyAttach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD. Download GMER Rootkit Scanner from here to your desktop. Double click the exe file. If asked to allow gmer.sys driver to load, please consent . If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.Click the image to enlarge it In the right panel, you will see several boxes that have been checked. Uncheck the following ... IAT/EAT Drives/Partition other than Systemdrive (typically C:\) Show All (don't miss this one)[*] Then click the Scan button & wait for it to finish.[*] Once done click on the [save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.[*]Save it where you can easily find it, such as your desktop, and post it in reply.**Caution**Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries If you have trouble running GEMR:Make sure that your security software is disabledUncheck the box next to "Files" this time alsoIf you still can't run it, try in the Safe ModePlease include the following in your next post:DDS.txt and Attach.txt logsGMER log Link to post Share on other sites More sharing options...
LDTate Posted April 3, 2012 ID:539604 Share Posted April 3, 2012 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts