Jump to content

I think I have a Rootkit


Brokenpc
 Share

Recommended Posts

My PC is infected, It wont let me run any virus removal software.

I have installed and tried SmitfraudFix, ComboFix1, Microsoft Malicious Software Removal tool, Malewarebytes and Webroot Antivirus/ Spyware Remover.

I get a quick window like its going to run then nothing, I got RootRepeal to run and saved a log file but dont know witch .sis file might need to be removed. Please Help!

Here is the log

ROOTREPEAL © AD, 2007-2009

==================================================

Scan Start Time: 2009/09/21 22:51

Program Version: Version 1.3.5.0

Windows Version: Windows XP SP3

==================================================

Drivers

-------------------

Name: 1394BUS.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\1394BUS.SYS

Address: 0xF74F0000 Size: 57344 File Visible: - Signed: Yes

Status: -

Name: 2.tmp

Image Path: C:\WINDOWS\system32\2.tmp

Address: 0xF7A92000 Size: 6144 File Visible: No Signed: Yes

Status: -

Name: ACPI.sys

Image Path: ACPI.sys

Address: 0xF73A1000 Size: 187776 File Visible: - Signed: Yes

Status: -

Name: ACPI_HAL

Image Path: \Driver\ACPI_HAL

Address: 0x804D7000 Size: 2150400 File Visible: - Signed: Yes

Status: -

Name: afd.sys

Image Path: C:\WINDOWS\System32\drivers\afd.sys

Address: 0xF0D77000 Size: 138496 File Visible: - Signed: Yes

Status: -

Name: ALCXWDM.SYS

Image Path: C:\WINDOWS\system32\drivers\ALCXWDM.SYS

Address: 0xF6585000 Size: 3842560 File Visible: - Signed: Yes

Status: -

Name: AmdK8.sys

Image Path: C:\WINDOWS\system32\DRIVERS\AmdK8.sys

Address: 0xF76A0000 Size: 57344 File Visible: - Signed: Yes

Status: -

Name: arp1394.sys

Image Path: C:\WINDOWS\system32\DRIVERS\arp1394.sys

Address: 0xF7600000 Size: 60800 File Visible: - Signed: Yes

Status: -

Name: atapi.sys

Image Path: atapi.sys

Address: 0xF7333000 Size: 96512 File Visible: - Signed: Yes

Status: -

Name: atinavxx.sys

Image Path: C:\WINDOWS\system32\DRIVERS\atinavxx.sys

Address: 0xF6B16000 Size: 135296 File Visible: - Signed: Yes

Status: -

Name: ATMFD.DLL

Image Path: C:\WINDOWS\System32\ATMFD.DLL

Address: 0xBFFA0000 Size: 286720 File Visible: - Signed: Yes

Status: -

Name: audstub.sys

Image Path: C:\WINDOWS\system32\DRIVERS\audstub.sys

Address: 0xF7B61000 Size: 3072 File Visible: - Signed: Yes

Status: -

Name: BdaSup.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\BdaSup.SYS

Address: 0xF79A4000 Size: 12288 File Visible: - Signed: Yes

Status: -

Name: Beep.SYS

Image Path: C:\WINDOWS\System32\Drivers\Beep.SYS

Address: 0xF79F8000 Size: 4224 File Visible: - Signed: Yes

Status: -

Name: BOOTVID.dll

Image Path: C:\WINDOWS\system32\BOOTVID.dll

Address: 0xF78E0000 Size: 12288 File Visible: - Signed: Yes

Status: -

Name: Cdfs.SYS

Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS

Address: 0xF7620000 Size: 63744 File Visible: - Signed: Yes

Status: -

Name: cdrom.sys

Image Path: C:\WINDOWS\system32\DRIVERS\cdrom.sys

Address: 0xF76C0000 Size: 62976 File Visible: - Signed: Yes

Status: -

Name: CLASSPNP.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS

Address: 0xF7530000 Size: 53248 File Visible: - Signed: Yes

Status: -

Name: disk.sys

Image Path: disk.sys

Address: 0xF7520000 Size: 36352 File Visible: - Signed: Yes

Status: -

Name: dmio.sys

Image Path: dmio.sys

Address: 0xF734B000 Size: 153344 File Visible: - Signed: Yes

Status: -

Name: dmload.sys

Image Path: dmload.sys

Address: 0xF79D4000 Size: 5888 File Visible: - Signed: Yes

Status: -

Name: drmk.sys

Image Path: C:\WINDOWS\system32\drivers\drmk.sys

Address: 0xF76E0000 Size: 61440 File Visible: - Signed: Yes

Status: -

Name: dump_atapi.sys

Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys

Address: 0xF0BD6000 Size: 98304 File Visible: No Signed: Yes

Status: -

Name: dump_WMILIB.SYS

Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS

Address: 0xF7A00000 Size: 8192 File Visible: No Signed: Yes

Status: -

Name: Dxapi.sys

Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys

Address: 0xF5603000 Size: 12288 File Visible: - Signed: Yes

Status: -

Name: dxg.sys

Image Path: C:\WINDOWS\System32\drivers\dxg.sys

Address: 0xBF9C3000 Size: 73728 File Visible: - Signed: Yes

Status: -

Name: dxgthk.sys

Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys

Address: 0xF7B00000 Size: 4096 File Visible: - Signed: Yes

Status: -

Name: Fastfat.SYS

Image Path: C:\WINDOWS\System32\Drivers\Fastfat.SYS

Address: 0xBAD0C000 Size: 143744 File Visible: - Signed: Yes

Status: -

Name: Fips.SYS

Image Path: C:\WINDOWS\System32\Drivers\Fips.SYS

Address: 0xF75E0000 Size: 44544 File Visible: - Signed: Yes

Status: -

Name: fltmgr.sys

Image Path: fltmgr.sys

Address: 0xF72FA000 Size: 129792 File Visible: - Signed: Yes

Status: -

Name: Fs_Rec.SYS

Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS

Address: 0xF79F6000 Size: 7936 File Visible: - Signed: Yes

Status: -

Name: ftdisk.sys

Image Path: ftdisk.sys

Address: 0xF7371000 Size: 125056 File Visible: - Signed: Yes

Status: -

Name: GEARAspiWDM.sys

Image Path: C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys

Address: 0xF7800000 Size: 21120 File Visible: - Signed: Yes

Status: -

Name: hal.dll

Image Path: C:\WINDOWS\system32\hal.dll

Address: 0x806E4000 Size: 134400 File Visible: - Signed: Yes

Status: -

Name: HIDCLASS.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS

Address: 0xF7630000 Size: 36864 File Visible: - Signed: Yes

Status: -

Name: HIDPARSE.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS

Address: 0xF7868000 Size: 28672 File Visible: - Signed: Yes

Status: -

Name: hidusb.sys

Image Path: C:\WINDOWS\system32\DRIVERS\hidusb.sys

Address: 0xF7988000 Size: 10368 File Visible: - Signed: Yes

Status: -

Name: HSF_CNXT.sys

Image Path: C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys

Address: 0xF6930000 Size: 717952 File Visible: - Signed: Yes

Status: -

Name: HSF_DPV.sys

Image Path: C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys

Address: 0xF69E0000 Size: 1035008 File Visible: - Signed: Yes

Status: -

Name: HSFHWBS2.sys

Image Path: C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys

Address: 0xF6ADD000 Size: 231168 File Visible: - Signed: Yes

Status: -

Name: HTTP.sys

Image Path: C:\WINDOWS\System32\Drivers\HTTP.sys

Address: 0xBA43F000 Size: 264832 File Visible: - Signed: Yes

Status: -

Name: imapi.sys

Image Path: C:\WINDOWS\system32\DRIVERS\imapi.sys

Address: 0xF76B0000 Size: 42112 File Visible: - Signed: Yes

Status: -

Name: ipnat.sys

Image Path: C:\WINDOWS\system32\DRIVERS\ipnat.sys

Address: 0xF0CB6000 Size: 152832 File Visible: - Signed: Yes

Status: -

Name: ipsec.sys

Image Path: C:\WINDOWS\system32\DRIVERS\ipsec.sys

Address: 0xF0E1A000 Size: 75264 File Visible: - Signed: Yes

Status: -

Name: isapnp.sys

Image Path: isapnp.sys

Address: 0xF74D0000 Size: 37248 File Visible: - Signed: Yes

Status: -

Name: kbdclass.sys

Image Path: C:\WINDOWS\system32\DRIVERS\kbdclass.sys

Address: 0xF7838000 Size: 24576 File Visible: - Signed: Yes

Status: -

Name: kbdhid.sys

Image Path: C:\WINDOWS\system32\DRIVERS\kbdhid.sys

Address: 0xF7994000 Size: 14592 File Visible: - Signed: Yes

Status: -

Name: KDCOM.DLL

Image Path: C:\WINDOWS\system32\KDCOM.DLL

Address: 0xF79D0000 Size: 8192 File Visible: - Signed: Yes

Status: -

Name: kmixer.sys

Image Path: C:\WINDOWS\system32\drivers\kmixer.sys

Address: 0xB9AE2000 Size: 172416 File Visible: - Signed: Yes

Status: -

Name: ks.sys

Image Path: C:\WINDOWS\system32\DRIVERS\ks.sys

Address: 0xF6B38000 Size: 143360 File Visible: - Signed: Yes

Status: -

Name: KSecDD.sys

Image Path: KSecDD.sys

Address: 0xF72D1000 Size: 92288 File Visible: - Signed: Yes

Status: -

Name: mdmxsdk.sys

Image Path: C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys

Address: 0xBAE2C000 Size: 12544 File Visible: - Signed: Yes

Status: -

Name: mnmdd.SYS

Image Path: C:\WINDOWS\System32\Drivers\mnmdd.SYS

Address: 0xF79FA000 Size: 4224 File Visible: - Signed: Yes

Status: -

Name: Modem.SYS

Image Path: C:\WINDOWS\System32\Drivers\Modem.SYS

Address: 0xF7808000 Size: 30080 File Visible: - Signed: Yes

Status: -

Name: mouclass.sys

Image Path: C:\WINDOWS\system32\DRIVERS\mouclass.sys

Address: 0xF7840000 Size: 23040 File Visible: - Signed: Yes

Status: -

Name: mouhid.sys

Image Path: C:\WINDOWS\system32\DRIVERS\mouhid.sys

Address: 0xF7998000 Size: 12160 File Visible: - Signed: Yes

Status: -

Name: MountMgr.sys

Image Path: MountMgr.sys

Address: 0xF7500000 Size: 42368 File Visible: - Signed: Yes

Status: -

Name: mrxdav.sys

Image Path: C:\WINDOWS\system32\DRIVERS\mrxdav.sys

Address: 0xBAC3F000 Size: 180608 File Visible: - Signed: Yes

Status: -

Name: mrxsmb.sys

Image Path: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

Address: 0xF0CDC000 Size: 455296 File Visible: - Signed: Yes

Status: -

Name: Msfs.SYS

Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS

Address: 0xF7878000 Size: 19072 File Visible: - Signed: Yes

Status: -

Name: msgpc.sys

Image Path: C:\WINDOWS\system32\DRIVERS\msgpc.sys

Address: 0xF7730000 Size: 35072 File Visible: - Signed: Yes

Status: -

Name: mssmbios.sys

Image Path: C:\WINDOWS\system32\DRIVERS\mssmbios.sys

Address: 0xF79C4000 Size: 15488 File Visible: - Signed: Yes

Status: -

Name: Mup.sys

Image Path: Mup.sys

Address: 0xF71FD000 Size: 105344 File Visible: - Signed: Yes

Status: -

Name: NDIS.sys

Image Path: NDIS.sys

Address: 0xF7217000 Size: 182656 File Visible: - Signed: Yes

Status: -

Name: ndistapi.sys

Image Path: C:\WINDOWS\system32\DRIVERS\ndistapi.sys

Address: 0xF79A8000 Size: 10112 File Visible: - Signed: Yes

Status: -

Name: ndisuio.sys

Image Path: C:\WINDOWS\system32\DRIVERS\ndisuio.sys

Address: 0xBAEF0000 Size: 14592 File Visible: - Signed: Yes

Status: -

Name: ndiswan.sys

Image Path: C:\WINDOWS\system32\DRIVERS\ndiswan.sys

Address: 0xF644C000 Size: 91520 File Visible: - Signed: Yes

Status: -

Name: NDProxy.SYS

Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS

Address: 0xF7560000 Size: 40576 File Visible: - Signed: Yes

Status: -

Name: netbios.sys

Image Path: C:\WINDOWS\system32\DRIVERS\netbios.sys

Address: 0xF75C0000 Size: 34688 File Visible: - Signed: Yes

Status: -

Name: netbt.sys

Image Path: C:\WINDOWS\system32\DRIVERS\netbt.sys

Address: 0xF0D99000 Size: 162816 File Visible: - Signed: Yes

Status: -

Name: nic1394.sys

Image Path: C:\WINDOWS\system32\DRIVERS\nic1394.sys

Address: 0xF75B0000 Size: 61824 File Visible: - Signed: Yes

Status: -

Name: Npfs.SYS

Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS

Address: 0xF7880000 Size: 30848 File Visible: - Signed: Yes

Status: -

Name: Ntfs.sys

Image Path: Ntfs.sys

Address: 0xF7244000 Size: 574976 File Visible: - Signed: Yes

Status: -

Name: ntkrnlpa.exe

Image Path: C:\WINDOWS\system32\ntkrnlpa.exe

Address: 0x804D7000 Size: 2150400 File Visible: - Signed: Yes

Status: -

Name: Null.SYS

Image Path: C:\WINDOWS\System32\Drivers\Null.SYS

Address: 0xF7BE7000 Size: 2944 File Visible: - Signed: Yes

Status: -

Name: nv4_disp.dll

Image Path: C:\WINDOWS\System32\nv4_disp.dll

Address: 0xBF9D5000 Size: 6057984 File Visible: - Signed: Yes

Status: -

Name: nv4_mini.sys

Image Path: C:\WINDOWS\system32\DRIVERS\nv4_mini.sys

Address: 0xF6BDB000 Size: 6132576 File Visible: - Signed: Yes

Status: -

Name: nvata.sys

Image Path: nvata.sys

Address: 0xF731A000 Size: 98432 File Visible: - Signed: Yes

Status: -

Name: NVENETFD.sys

Image Path: C:\WINDOWS\system32\DRIVERS\NVENETFD.sys

Address: 0xF7590000 Size: 54784 File Visible: - Signed: Yes

Status: -

Name: nvnetbus.sys

Image Path: C:\WINDOWS\system32\DRIVERS\nvnetbus.sys

Address: 0xF76F0000 Size: 40960 File Visible: - Signed: Yes

Status: -

Name: NVNRM.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\NVNRM.SYS

Address: 0xF6477000 Size: 958464 File Visible: - Signed: Yes

Status: -

Name: ohci1394.sys

Image Path: ohci1394.sys

Address: 0xF74E0000 Size: 61696 File Visible: - Signed: Yes

Status: -

Name: parport.sys

Image Path: C:\WINDOWS\system32\DRIVERS\parport.sys

Address: 0xF6463000 Size: 80128 File Visible: - Signed: Yes

Status: -

Name: PartMgr.sys

Image Path: PartMgr.sys

Address: 0xF7758000 Size: 19712 File Visible: - Signed: Yes

Status: -

Name: ParVdm.SYS

Image Path: C:\WINDOWS\System32\Drivers\ParVdm.SYS

Address: 0xF7A80000 Size: 6784 File Visible: - Signed: Yes

Status: -

Name: pci.sys

Image Path: pci.sys

Address: 0xF7390000 Size: 68224 File Visible: - Signed: Yes

Status: -

Name: pciide.sys

Image Path: pciide.sys

Address: 0xF7A98000 Size: 3328 File Visible: - Signed: Yes

Status: -

Name: PCIIDEX.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS

Address: 0xF7750000 Size: 28672 File Visible: - Signed: Yes

Status: -

Name: PnpManager

Image Path: \Driver\PnpManager

Address: 0x804D7000 Size: 2150400 File Visible: - Signed: Yes

Status: -

Name: portcls.sys

Image Path: C:\WINDOWS\system32\drivers\portcls.sys

Address: 0xF6561000 Size: 147456 File Visible: - Signed: Yes

Status: -

Name: psched.sys

Image Path: C:\WINDOWS\system32\DRIVERS\psched.sys

Address: 0xF62DB000 Size: 69120 File Visible: - Signed: Yes

Status: -

Name: ptilink.sys

Image Path: C:\WINDOWS\system32\DRIVERS\ptilink.sys

Address: 0xF7828000 Size: 17792 File Visible: - Signed: Yes

Status: -

Name: rasacd.sys

Image Path: C:\WINDOWS\system32\DRIVERS\rasacd.sys

Address: 0xF7968000 Size: 8832 File Visible: - Signed: Yes

Status: -

Name: rasl2tp.sys

Image Path: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

Address: 0xF7700000 Size: 51328 File Visible: - Signed: Yes

Status: -

Name: raspppoe.sys

Image Path: C:\WINDOWS\system32\DRIVERS\raspppoe.sys

Address: 0xF7710000 Size: 41472 File Visible: - Signed: Yes

Status: -

Name: raspptp.sys

Image Path: C:\WINDOWS\system32\DRIVERS\raspptp.sys

Address: 0xF7720000 Size: 48384 File Visible: - Signed: Yes

Status: -

Name: raspti.sys

Image Path: C:\WINDOWS\system32\DRIVERS\raspti.sys

Address: 0xF7830000 Size: 16512 File Visible: - Signed: Yes

Status: -

Name: RAW

Image Path: \FileSystem\RAW

Address: 0x804D7000 Size: 2150400 File Visible: - Signed: Yes

Status: -

Name: rdbss.sys

Image Path: C:\WINDOWS\system32\DRIVERS\rdbss.sys

Address: 0xF0D4C000 Size: 175744 File Visible: - Signed: Yes

Status: -

Name: RDPCDD.sys

Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys

Address: 0xF79FC000 Size: 4224 File Visible: - Signed: Yes

Status: -

Name: rdpdr.sys

Image Path: C:\WINDOWS\system32\DRIVERS\rdpdr.sys

Address: 0xF561B000 Size: 196224 File Visible: - Signed: Yes

Status: -

Name: redbook.sys

Image Path: C:\WINDOWS\system32\DRIVERS\redbook.sys

Address: 0xF76D0000 Size: 57600 File Visible: - Signed: Yes

Status: -

Name: rootrepeal.sys

Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys

Address: 0xBA538000 Size: 49152 File Visible: No Signed: Yes

Status: -

Name: sr.sys

Image Path: sr.sys

Address: 0xF72E8000 Size: 73472 File Visible: - Signed: Yes

Status: -

Name: srv.sys

Image Path: C:\WINDOWS\system32\DRIVERS\srv.sys

Address: 0xBAB9D000 Size: 333952 File Visible: - Signed: Yes

Status: -

Name: swenum.sys

Image Path: C:\WINDOWS\system32\DRIVERS\swenum.sys

Address: 0xF79F2000 Size: 4352 File Visible: - Signed: Yes

Status: -

Name: sysaudio.sys

Image Path: C:\WINDOWS\system32\drivers\sysaudio.sys

Address: 0xBAB7D000 Size: 60800 File Visible: - Signed: Yes

Status: -

Name: tcpip.sys

Image Path: C:\WINDOWS\system32\DRIVERS\tcpip.sys

Address: 0xF0DC1000 Size: 361600 File Visible: - Signed: Yes

Status: -

Name: TDI.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\TDI.SYS

Address: 0xF7818000 Size: 20480 File Visible: - Signed: Yes

Status: -

Name: termdd.sys

Image Path: C:\WINDOWS\system32\DRIVERS\termdd.sys

Address: 0xF7740000 Size: 40704 File Visible: - Signed: Yes

Status: -

Name: update.sys

Image Path: C:\WINDOWS\system32\DRIVERS\update.sys

Address: 0xF54F5000 Size: 384768 File Visible: - Signed: Yes

Status: -

Name: usbccgp.sys

Image Path: C:\WINDOWS\system32\DRIVERS\usbccgp.sys

Address: 0xF7890000 Size: 32128 File Visible: - Signed: Yes

Status: -

Name: USBD.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\USBD.SYS

Address: 0xF79F4000 Size: 8192 File Visible: - Signed: Yes

Status: -

Name: usbehci.sys

Image Path: C:\WINDOWS\system32\DRIVERS\usbehci.sys

Address: 0xF77F8000 Size: 30208 File Visible: - Signed: Yes

Status: -

Name: usbhub.sys

Image Path: C:\WINDOWS\system32\DRIVERS\usbhub.sys

Address: 0xF7570000 Size: 59520 File Visible: - Signed: Yes

Status: -

Name: usbohci.sys

Image Path: C:\WINDOWS\system32\DRIVERS\usbohci.sys

Address: 0xF77F0000 Size: 17152 File Visible: - Signed: Yes

Status: -

Name: USBPORT.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS

Address: 0xF6BA3000 Size: 147456 File Visible: - Signed: Yes

Status: -

Name: USBSTOR.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

Address: 0xF7888000 Size: 26368 File Visible: - Signed: Yes

Status: -

Name: vga.sys

Image Path: C:\WINDOWS\System32\drivers\vga.sys

Address: 0xF7870000 Size: 20992 File Visible: - Signed: Yes

Status: -

Name: VIDEOPRT.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS

Address: 0xF6BC7000 Size: 81920 File Visible: - Signed: Yes

Status: -

Name: VolSnap.sys

Image Path: VolSnap.sys

Address: 0xF7510000 Size: 52352 File Visible: - Signed: Yes

Status: -

Name: wanarp.sys

Image Path: C:\WINDOWS\system32\DRIVERS\wanarp.sys

Address: 0xF75F0000 Size: 34560 File Visible: - Signed: Yes

Status: -

Name: watchdog.sys

Image Path: C:\WINDOWS\System32\watchdog.sys

Address: 0xF78A0000 Size: 20480 File Visible: - Signed: Yes

Status: -

Name: wdmaud.sys

Image Path: C:\WINDOWS\system32\drivers\wdmaud.sys

Address: 0xBA778000 Size: 83072 File Visible: - Signed: Yes

Status: -

Name: Win32k

Image Path: \Driver\Win32k

Address: 0xBF800000 Size: 1847296 File Visible: - Signed: Yes

Status: -

Name: win32k.sys

Image Path: C:\WINDOWS\System32\win32k.sys

Address: 0xBF800000 Size: 1847296 File Visible: - Signed: Yes

Status: -

Name: win32k.sys:1

Image Path: C:\WINDOWS\win32k.sys:1

Address: 0xF78A8000 Size: 20480 File Visible: No Signed: Yes

Status: -

Name: win32k.sys:2

Image Path: C:\WINDOWS\win32k.sys:2

Address: 0xF7610000 Size: 61440 File Visible: No Signed: Yes

Status: -

Name: WMILIB.SYS

Image Path: C:\WINDOWS\system32\DRIVERS\WMILIB.SYS

Address: 0xF79D2000 Size: 8192 File Visible: - Signed: Yes

Status: -

Name: WMIxWDM

Image Path: \Driver\WMIxWDM

Address: 0x804D7000 Size: 2150400 File Visible: - Signed: Yes

Status: -

e file.

Link to post
Share on other sites

  • 2 weeks later...

Hello and welcome to the Malwarebytes forum!

Please follow the instructions mentioned over here: http://www.malwarebytes.org/forums/index.php?showtopic=9573

Download and run RootRepeal CR

Please download RootRepeal from the following location and save it to your desktop.

  • Unzip the RootRepeal.zip file it to it's own folder. (If you did not use the "Direct Download" mirror to download RootRepeal).
  • Close/Disable all other programs especially your security programs (anti-spyware, anti-virus, and firewall) Refer to this page, if you are unsure how.
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Double-click on RootRepeal.exe to run it. If you are using Vista, please right-click and run as Administrator...
  • Click the reportTab.png tab at the bottom.
  • Now press the btnScan.png button.
  • A box will pop up, check the boxes beside All Seven options/scan area
    RR_checkbox.jpg
  • Now click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button. saveReport.png
  • Save it as RepealScan and save it to your desktop
  • Reconnect to the internet.
  • Post the contents of that log in your reply please.

Then, please give me an update of the condition of your machine and what problems or symptoms you may have.

With Regards,

Extremeboy

Link to post
Share on other sites

Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 from the last day I replied initially, the topic will need to be closed.

Thanks for understanding.

With Regards,

Extremeboy

Link to post
Share on other sites

Hello.

Due to Lack of feedback, this topic is now Closed.

If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter.

Everyone else please start a new topic.

With Regards,

Extremeboy

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.