buttergun909
Topic Starter
Hello,
I got this malware a few days ago, and with help from another board, I've been able to discern that uacinit.dll is the problem. I found a few threads here on this particular problem, and it seems all of you have been able to help people get rid of the problem. So, I'm hoping you can help me, too!
I've ran several reports, which I will paste and attach. Below I will paste the DDS.txt and the GMER.txt. I will attach the ATTACH.tx.
Please let me know if anything can be done. I really appreciate any help. Thanks!
DDS.txt:
DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 23:31:06.93 on Sat 06/06/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1015.333 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Joe\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/webhp?complete=0&hl=en
mDefault_Page_URL = hxxp://www.dell.com
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [DellTransferAgent] "c:\documents and settings\all users\application data\dell\transferagent\TransferAgent.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [ShStatEXE] "c:\program files\network associates\virusscan\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\network associates\common framework\UpdaterUI.exe" /StartedFromRunKey
mRun: [Network Associates Error Reporting Service] "c:\program files\common files\network associates\talkback\tbmon.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_06\bin\jusched.exe"
mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe"
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\GetFlash.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: turbotax.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: ckpNotify - ckpNotify.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
============= SERVICES / DRIVERS ===============
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2006-4-29 58464]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944]
R2 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2007-9-28 156976]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\network associates\common framework\FrameworkService.exe [2006-4-29 102463]
R2 McTaskManager;Network Associates Task Manager;c:\program files\network associates\virusscan\vstskmgr.exe [2004-9-22 28672]
R2 Scap;SecureClient Application Policy Module;c:\windows\system32\drivers\scap.sys [2006-4-29 17456]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [2006-4-29 670128]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [2006-4-29 2041904]
S3 McShield;Network Associates McShield;c:\program files\network associates\virusscan\mcshield.exe [2004-9-22 221191]
S3 NaiAvFilter1;NaiAvFilter1;c:\windows\system32\drivers\naiavf5x.sys [2006-4-29 108480]
S3 OMVA;VPN-1 SecureClient Adapter;c:\windows\system32\drivers\OMVA.sys [2006-4-29 14924]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]
============== File Associations ===============
scrfile="%1" %*
=============== Created Last 30 ================
2009-06-05 22:10 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-06-05 22:09 –d—– c:\program files\SUPERAntiSpyware
2009-06-05 22:09 –d—– c:\docume~1\joe\applic~1\SUPERAntiSpyware.com
2009-06-05 22:08 –d—– c:\program files\common files\Wise Installation Wizard
2009-06-05 22:07 –d—– c:\program files\Windows Installer Clean Up
2009-06-05 22:07 –d—– c:\program files\MSECACHE
2009-06-04 22:46 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-04 22:46 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-04 22:46 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-06-03 23:32 102,664 a——- c:\windows\system32\drivers\tmcomm.sys
2009-06-03 23:31 –d—– c:\documents and settings\joe\.housecall6.6
2009-05-25 20:02 1,720,086 a——- c:\windows\system32\TmpA2069984
2009-05-23 02:38 225,280 a——- c:\windows\system32\rewire.dll
2009-05-23 02:38 1,294,336 a——- c:\windows\system32\vorbis.acm
2009-05-23 02:35 –d—– c:\program files\Image-Line
2009-05-23 02:35 1,777,664 a——- c:\windows\system32\gdiplus.dll
2009-05-23 01:07 –d—– C:\ConverterOutput
2009-05-23 01:06 –d—– c:\program files\Cucusoft
==================== Find3M ====================
2009-03-29 20:46 249,856 a——- c:\windows\system32\pdfmona.dll
2009-03-29 20:46 51,716 a——- c:\windows\system32\pdf995mon.dll
2007-11-08 20:35 246 a——- c:\program files\common files\rybiv
2007-02-10 00:56 491,768 a——- c:\program files\ie6setup.exe
2009-02-03 14:37 152 —shr– c:\windows\system32\987C99206F.sys
2009-02-03 14:37 7,518 a–sh— c:\windows\system32\KGyGaAvL.sys
============= FINISH: 23:32:16.95 ===============
GMER.txt:
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-07 15:29:02
Windows 5.0.2195
—- System - GMER 1.0.15 —-
Code 8627F8C8 ZwEnumerateKey
Code 85F8E9A0 ZwFlushInstructionCache
Code 8651900E IofCallDriver
Code 8633EE7E IofCompleteRequest
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!IofCallDriver 804EE0F6 5 Bytes JMP 86519013
.text ntkrnlpa.exe!IofCompleteRequest 804EE186 5 Bytes JMP 8633EE83
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805AAEDE 5 Bytes JMP 85F8E9A4
PAGE ntkrnlpa.exe!ZwEnumerateKey 80619A6E 5 Bytes JMP 8627F8CC
—- User code sections - GMER 1.0.15 —-
.text C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe[140] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0098000A
.text C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe[140] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0099000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe[192] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A3000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe[192] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A4000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe[248] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0091000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe[248] ntdll.dll!LdrUnloadDll 7C91718B 3 Bytes JMP 0092000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe[248] ntdll.dll!LdrUnloadDll + 4 7C91718F 1 Byte [84]
.text C:\WINDOWS\system32\WLTRAY.exe[256] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00B3000A
.text C:\WINDOWS\system32\WLTRAY.exe[256] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00B4000A
.text C:\Program Files\iTunes\iTunesHelper.exe[300] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0098000A
.text C:\Program Files\iTunes\iTunesHelper.exe[300] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0099000A
.text C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe[308] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0099000A
.text C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe[308] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009A000A
.text C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe[468] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A2000A
.text C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe[468] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A3000A
.text C:\Program Files\DellSupport\DSAgnt.exe[532] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009C000A
.text C:\Program Files\DellSupport\DSAgnt.exe[532] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009D000A
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[548] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0076000A
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[548] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0077000A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[592] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 007E000A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[592] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0081000A
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[684] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0086000A
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[684] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0087000A
.text C:\WINDOWS\system32\winlogon.exe[704] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0063000A
.text C:\WINDOWS\system32\winlogon.exe[704] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0064000A
.text C:\WINDOWS\system32\services.exe[748] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0063000A
.text C:\WINDOWS\system32\services.exe[748] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0064000A
.text C:\WINDOWS\system32\lsass.exe[760] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006E000A
.text C:\WINDOWS\system32\lsass.exe[760] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0071000A
.text C:\WINDOWS\System32\alg.exe[1232] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006E000A
.text C:\WINDOWS\System32\alg.exe[1232] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006F000A
.text C:\WINDOWS\system32\spoolsv.exe[1560] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0096000A
.text C:\WINDOWS\system32\spoolsv.exe[1560] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0097000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1660] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006B000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1660] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006C000A
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1744] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A5000A
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1744] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A7000A
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[1796] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006D000A
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[1796] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006E000A
.text C:\Program Files\Network Associates\VirusScan\vstskmgr.exe[1876] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006D000A
.text C:\Program Files\Network Associates\VirusScan\vstskmgr.exe[1876] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006E000A
.text C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe[1900] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006C000A
.text C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe[1900] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006D000A
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1920] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0099000A
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1920] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009A000A
.text C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe[1996] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009B000A
.text C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe[1996] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009C000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A7000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A8000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WININET.dll!HttpAddRequestHeadersA 771C40B2 5 Bytes JMP 00B3000C
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WININET.dll!HttpAddRequestHeadersW 771CEF4C 5 Bytes JMP 00BE000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00BFF9F0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00C008A0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WS2_32.dll!send 71AB428A 5 Bytes JMP 00C00780 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 00BFFDA0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00C00A60 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\iPod\bin\iPodService.exe[2372] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0071000A
.text C:\Program Files\iPod\bin\iPodService.exe[2372] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0072000A
.text C:\Documents and Settings\Joe\Desktop\bunny.scr.exe[2416] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00B5000A
.text C:\Documents and Settings\Joe\Desktop\bunny.scr.exe[2416] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00B6000A
.text c:\program files\common files\installshield\updateservice\isuspm.exe[2948] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0097000A
.text c:\program files\common files\installshield\updateservice\isuspm.exe[2948] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0098000A
.text C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe[2956] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009E000A
.text C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe[2956] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009F000A
.text C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe[3176] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00AD000A
.text C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe[3176] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00AE000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A7000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A8000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WININET.dll!HttpAddRequestHeadersA 771C40B2 5 Bytes JMP 00B3000C
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WININET.dll!HttpAddRequestHeadersW 771CEF4C 5 Bytes JMP 00BE000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00BFF9F0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00C008A0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WS2_32.dll!send 71AB428A 5 Bytes JMP 00C00780 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 00BFFDA0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00C00A60 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\WINDOWS\Explorer.EXE[3604] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00AA000A
.text C:\WINDOWS\Explorer.EXE[3604] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00AB000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe[3648] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00C8000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe[3648] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00C9000A
.text C:\WINDOWS\system32\ctfmon.exe[3880] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0097000A
.text C:\WINDOWS\system32\ctfmon.exe[3880] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0098000A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3908] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009D000A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3908] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009E000A
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3932] ntdll.dll!LdrLoadDll 7C9161CA 3 Bytes JMP 0092000A
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3932] ntdll.dll!LdrLoadDll + 4 7C9161CE 1 Byte [84]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3932] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0093000A
.text C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE[4040] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0095000A
.text C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE[4040] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0096000A
.text C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe[4060] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0095000A
.text C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe[4060] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0096000A
.text C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe[4080] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0097000A
.text C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe[4080] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0098000A
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip Scap.sys (Check Point Software Technologies)
AttachedDevice \Driver\Tcpip \Device\Ip mvstdi5x.sys (Anti-Virus Mini-Firewall Driver/Network Associates, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mvstdi5x.sys (Anti-Virus Mini-Firewall Driver/Network Associates, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Scap.sys (Check Point Software Technologies)
AttachedDevice \Driver\Tcpip \Device\Udp mvstdi5x.sys (Anti-Virus Mini-Firewall Driver/Network Associates, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Scap.sys (Check Point Software Technologies)
AttachedDevice \Driver\Tcpip \Device\RawIp Scap.sys (Check Point Software Technologies)
AttachedDevice \Driver\Tcpip \Device\RawIp mvstdi5x.sys (Anti-Virus Mini-Firewall Driver/Network Associates, Inc.)
Device \FileSystem\Fastfat \Fat A8D9FC8A
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Processes - GMER 1.0.15 —-
Library \\?\globalroot\systemroot\system32\UACxtciihkobvukjrq.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [916] 0x029B0000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1028] 0x00890000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1072] 0x00890000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1132] 0x00890000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1208] 0x00890000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1720] 0x00890000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\Iexplore.exe [2056] 0x00BF0000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\Iexplore.exe [3416] 0x00BF0000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\IEXPLORE.EXE [3716] 0x00BF0000
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\system32\drivers\UACkcmyktuwuyxiddb.sys (*** hidden *** ) [SYSTEM] UACd.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACkcmyktuwuyxiddb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACkcmyktuwuyxiddb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACgroqpxdaiqjitbo.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACntrgtvsjdyiejax.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACetephdptpxbrelj.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UACnosqlrgsbswwfwa.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACiqmlbwhtsvalfvq.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacmal \\?\globalroot\systemroot\system32\UACdomqieruwpyqdyx.db
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacrem \\?\globalroot\systemroot\system32\UACxtciihkobvukjrq.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UACcofmkbapdnxtqgx.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACnlxdontvnnseyvv.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACxusrkqbjqmqyuky.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACkcmyktuwuyxiddb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACkcmyktuwuyxiddb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACgroqpxdaiqjitbo.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACntrgtvsjdyiejax.dat
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACetephdptpxbrelj.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UACnosqlrgsbswwfwa.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACiqmlbwhtsvalfvq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacmal \\?\globalroot\systemroot\system32\UACdomqieruwpyqdyx.db
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacrem \\?\globalroot\systemroot\system32\UACxtciihkobvukjrq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UACcofmkbapdnxtqgx.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACnlxdontvnnseyvv.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACxusrkqbjqmqyuky.log
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion@ProductName Microsoft Windows XP
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion@CurrentVersion 5.1
Reg HKLM\SOFTWARE\Classes\UACTLS.UAAddressBookButtonCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAAddressBookButtonCtrl.5@ UAAddressBookBttn Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAAddressBookButtonCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAAddressBookButtonCtrl.5\CLSID@ {C0E10003-001C-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAButtonCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAButtonCtrl.5@ UAButton Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAButtonCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAButtonCtrl.5\CLSID@ {C0E10003-0007-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UACheckBoxCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UACheckBoxCtrl.5@ UACheckBox Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UACheckBoxCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UACheckBoxCtrl.5\CLSID@ {C0E10003-0013-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UADropDwnCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UADropDwnCtrl.5@ UADropDown Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UADropDwnCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UADropDwnCtrl.5\CLSID@ {C0E10003-000A-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAEditCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAEditCtrl.5@ UAEdit Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAEditCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAEditCtrl.5\CLSID@ {C0E10003-0023-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryButtonCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryButtonCtrl.5@ UAGalleryBttn Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryButtonCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryButtonCtrl.5\CLSID@ {C0E10003-0010-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryCtrl.5@ UAGallery Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryCtrl.5\CLSID@ {C0E10003-0019-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGraphicDropDown.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGraphicDropDown.5@ UAGraphicDropDown Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGraphicDropDown.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGraphicDropDown.5\CLSID@ {C0E10003-0026-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAHelpCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAHelpCtrl.5@ UAHelp Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAHelpCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAHelpCtrl.5\CLSID@ {C0E10003-002F-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAPartsListCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAPartsListCtrl.5@ UAPartsList Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAPartsListCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAPartsListCtrl.5\CLSID@ {C0E10003-000D-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UARadioBttnCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UARadioBttnCtrl.5@ UARadioButton Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UARadioBttnCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UARadioBttnCtrl.5\CLSID@ {C0E10003-0016-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAScrapBookButtonCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAScrapBookButtonCtrl.5@ UAScrapBookBttn Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAScrapBookButtonCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAScrapBookButtonCtrl.5\CLSID@ {C0E10003-001F-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UATextCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UATextCtrl.5@ UAText Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UATextCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UATextCtrl.5\CLSID@ {C0E10003-002C-0005-C0E1-C0E1C0E1C0E1}
—- Files - GMER 1.0.15 —-
File C:\Documents and Settings\Joe\Favorites\uacinit.dll Please help remove malicous malware!.url 253 bytes
File C:\Documents and Settings\Joe\Local Settings\Temp\UACd4f3.tmp 343040 bytes executable
File C:\WINDOWS\system32\drivers\UACkcmyktuwuyxiddb.sys 53248 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\UACcofmkbapdnxtqgx.log 44335 bytes
File C:\WINDOWS\system32\UACdomqieruwpyqdyx.db 1110399 bytes
File C:\WINDOWS\system32\UACetephdptpxbrelj.dll 19968 bytes executable
File C:\WINDOWS\system32\UACgroqpxdaiqjitbo.dll 25088 bytes executable
File C:\WINDOWS\system32\uacinit.dll 5712 bytes
File C:\WINDOWS\system32\UACiqmlbwhtsvalfvq.dll 19456 bytes executable
File C:\WINDOWS\system32\UACnosqlrgsbswwfwa.dll 17408 bytes executable
File C:\WINDOWS\system32\UACntrgtvsjdyiejax.dat 224 bytes
File C:\WINDOWS\system32\UACqldkboqehkhvyof.dll 66560 bytes
File C:\WINDOWS\system32\uactmp.db 3976714 bytes
File C:\WINDOWS\system32\UACxtciihkobvukjrq.dll 30208 bytes executable
File C:\WINDOWS\TEMP\UAC8e7f.tmp 66560 bytes
—- EOF - GMER 1.0.15 —-
My PC is running fine – only issue is, if I do a Google search, the font displays too large. Also, I can't open any spyware programs, ie Malware Anti Bytes or Spybot. Double-clicking, right-clicking, etc, do not work – the only thing that does is renaming the program, right-clicking, clicking the Properties button, and setting in the Compatibility mode to run on Windows 2000. But other than that – no popups or anthing.
Thanks!!
EDIT: One strange thing I have noticed – I can't add favorites anymore. I keep adding this post as a favorite, but it won't display in my Favorites dropdown…I get a listing stating "empty," which links to nothing. ALSO, my history shows websites I have NOT visited…creepy!
I got this malware a few days ago, and with help from another board, I've been able to discern that uacinit.dll is the problem. I found a few threads here on this particular problem, and it seems all of you have been able to help people get rid of the problem. So, I'm hoping you can help me, too!
I've ran several reports, which I will paste and attach. Below I will paste the DDS.txt and the GMER.txt. I will attach the ATTACH.tx.
Please let me know if anything can be done. I really appreciate any help. Thanks!
DDS.txt:
DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 23:31:06.93 on Sat 06/06/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1015.333 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Joe\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/webhp?complete=0&hl=en
mDefault_Page_URL = hxxp://www.dell.com
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ModemOnHold] c:\program files\netwaiting\netWaiting.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [DellTransferAgent] "c:\documents and settings\all users\application data\dell\transferagent\TransferAgent.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [ShStatEXE] "c:\program files\network associates\virusscan\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\network associates\common framework\UpdaterUI.exe" /StartedFromRunKey
mRun: [Network Associates Error Reporting Service] "c:\program files\common files\network associates\talkback\tbmon.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_06\bin\jusched.exe"
mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe"
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\GetFlash.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: turbotax.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: ckpNotify - ckpNotify.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
============= SERVICES / DRIVERS ===============
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2006-4-29 58464]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944]
R2 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2007-9-28 156976]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\network associates\common framework\FrameworkService.exe [2006-4-29 102463]
R2 McTaskManager;Network Associates Task Manager;c:\program files\network associates\virusscan\vstskmgr.exe [2004-9-22 28672]
R2 Scap;SecureClient Application Policy Module;c:\windows\system32\drivers\scap.sys [2006-4-29 17456]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [2006-4-29 670128]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [2006-4-29 2041904]
S3 McShield;Network Associates McShield;c:\program files\network associates\virusscan\mcshield.exe [2004-9-22 221191]
S3 NaiAvFilter1;NaiAvFilter1;c:\windows\system32\drivers\naiavf5x.sys [2006-4-29 108480]
S3 OMVA;VPN-1 SecureClient Adapter;c:\windows\system32\drivers\OMVA.sys [2006-4-29 14924]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]
============== File Associations ===============
scrfile="%1" %*
=============== Created Last 30 ================
2009-06-05 22:10 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-06-05 22:09 –d—– c:\program files\SUPERAntiSpyware
2009-06-05 22:09 –d—– c:\docume~1\joe\applic~1\SUPERAntiSpyware.com
2009-06-05 22:08 –d—– c:\program files\common files\Wise Installation Wizard
2009-06-05 22:07 –d—– c:\program files\Windows Installer Clean Up
2009-06-05 22:07 –d—– c:\program files\MSECACHE
2009-06-04 22:46 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-04 22:46 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-04 22:46 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-06-03 23:32 102,664 a——- c:\windows\system32\drivers\tmcomm.sys
2009-06-03 23:31 –d—– c:\documents and settings\joe\.housecall6.6
2009-05-25 20:02 1,720,086 a——- c:\windows\system32\TmpA2069984
2009-05-23 02:38 225,280 a——- c:\windows\system32\rewire.dll
2009-05-23 02:38 1,294,336 a——- c:\windows\system32\vorbis.acm
2009-05-23 02:35 –d—– c:\program files\Image-Line
2009-05-23 02:35 1,777,664 a——- c:\windows\system32\gdiplus.dll
2009-05-23 01:07 –d—– C:\ConverterOutput
2009-05-23 01:06 –d—– c:\program files\Cucusoft
==================== Find3M ====================
2009-03-29 20:46 249,856 a——- c:\windows\system32\pdfmona.dll
2009-03-29 20:46 51,716 a——- c:\windows\system32\pdf995mon.dll
2007-11-08 20:35 246 a——- c:\program files\common files\rybiv
2007-02-10 00:56 491,768 a——- c:\program files\ie6setup.exe
2009-02-03 14:37 152 —shr– c:\windows\system32\987C99206F.sys
2009-02-03 14:37 7,518 a–sh— c:\windows\system32\KGyGaAvL.sys
============= FINISH: 23:32:16.95 ===============
GMER.txt:
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-07 15:29:02
Windows 5.0.2195
—- System - GMER 1.0.15 —-
Code 8627F8C8 ZwEnumerateKey
Code 85F8E9A0 ZwFlushInstructionCache
Code 8651900E IofCallDriver
Code 8633EE7E IofCompleteRequest
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!IofCallDriver 804EE0F6 5 Bytes JMP 86519013
.text ntkrnlpa.exe!IofCompleteRequest 804EE186 5 Bytes JMP 8633EE83
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805AAEDE 5 Bytes JMP 85F8E9A4
PAGE ntkrnlpa.exe!ZwEnumerateKey 80619A6E 5 Bytes JMP 8627F8CC
—- User code sections - GMER 1.0.15 —-
.text C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe[140] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0098000A
.text C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe[140] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0099000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe[192] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A3000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe[192] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A4000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe[248] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0091000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe[248] ntdll.dll!LdrUnloadDll 7C91718B 3 Bytes JMP 0092000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe[248] ntdll.dll!LdrUnloadDll + 4 7C91718F 1 Byte [84]
.text C:\WINDOWS\system32\WLTRAY.exe[256] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00B3000A
.text C:\WINDOWS\system32\WLTRAY.exe[256] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00B4000A
.text C:\Program Files\iTunes\iTunesHelper.exe[300] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0098000A
.text C:\Program Files\iTunes\iTunesHelper.exe[300] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0099000A
.text C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe[308] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0099000A
.text C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe[308] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009A000A
.text C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe[468] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A2000A
.text C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe[468] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A3000A
.text C:\Program Files\DellSupport\DSAgnt.exe[532] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009C000A
.text C:\Program Files\DellSupport\DSAgnt.exe[532] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009D000A
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[548] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0076000A
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[548] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0077000A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[592] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 007E000A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[592] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0081000A
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[684] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0086000A
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[684] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0087000A
.text C:\WINDOWS\system32\winlogon.exe[704] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0063000A
.text C:\WINDOWS\system32\winlogon.exe[704] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0064000A
.text C:\WINDOWS\system32\services.exe[748] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0063000A
.text C:\WINDOWS\system32\services.exe[748] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0064000A
.text C:\WINDOWS\system32\lsass.exe[760] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006E000A
.text C:\WINDOWS\system32\lsass.exe[760] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0071000A
.text C:\WINDOWS\System32\alg.exe[1232] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006E000A
.text C:\WINDOWS\System32\alg.exe[1232] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006F000A
.text C:\WINDOWS\system32\spoolsv.exe[1560] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0096000A
.text C:\WINDOWS\system32\spoolsv.exe[1560] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0097000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1660] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006B000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1660] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006C000A
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1744] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A5000A
.text C:\Program Files\Maxtor\Sync\SyncServices.exe[1744] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A7000A
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[1796] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006D000A
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[1796] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006E000A
.text C:\Program Files\Network Associates\VirusScan\vstskmgr.exe[1876] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006D000A
.text C:\Program Files\Network Associates\VirusScan\vstskmgr.exe[1876] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006E000A
.text C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe[1900] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006C000A
.text C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe[1900] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006D000A
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1920] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0099000A
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1920] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009A000A
.text C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe[1996] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009B000A
.text C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe[1996] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009C000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A7000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A8000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WININET.dll!HttpAddRequestHeadersA 771C40B2 5 Bytes JMP 00B3000C
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WININET.dll!HttpAddRequestHeadersW 771CEF4C 5 Bytes JMP 00BE000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00BFF9F0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00C008A0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WS2_32.dll!send 71AB428A 5 Bytes JMP 00C00780 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 00BFFDA0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[2056] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00C00A60 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\iPod\bin\iPodService.exe[2372] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0071000A
.text C:\Program Files\iPod\bin\iPodService.exe[2372] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0072000A
.text C:\Documents and Settings\Joe\Desktop\bunny.scr.exe[2416] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00B5000A
.text C:\Documents and Settings\Joe\Desktop\bunny.scr.exe[2416] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00B6000A
.text c:\program files\common files\installshield\updateservice\isuspm.exe[2948] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0097000A
.text c:\program files\common files\installshield\updateservice\isuspm.exe[2948] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0098000A
.text C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe[2956] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009E000A
.text C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe[2956] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009F000A
.text C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe[3176] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00AD000A
.text C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe[3176] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00AE000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A7000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A8000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WININET.dll!HttpAddRequestHeadersA 771C40B2 5 Bytes JMP 00B3000C
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WININET.dll!HttpAddRequestHeadersW 771CEF4C 5 Bytes JMP 00BE000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00BFF9F0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00C008A0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WS2_32.dll!send 71AB428A 5 Bytes JMP 00C00780 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 00BFFDA0 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[3416] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00C00A60 \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
.text C:\WINDOWS\Explorer.EXE[3604] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00AA000A
.text C:\WINDOWS\Explorer.EXE[3604] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00AB000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe[3648] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00C8000A
.text C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe[3648] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00C9000A
.text C:\WINDOWS\system32\ctfmon.exe[3880] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0097000A
.text C:\WINDOWS\system32\ctfmon.exe[3880] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0098000A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3908] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009D000A
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[3908] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009E000A
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3932] ntdll.dll!LdrLoadDll 7C9161CA 3 Bytes JMP 0092000A
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3932] ntdll.dll!LdrLoadDll + 4 7C9161CE 1 Byte [84]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[3932] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0093000A
.text C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE[4040] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0095000A
.text C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE[4040] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0096000A
.text C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe[4060] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0095000A
.text C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe[4060] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0096000A
.text C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe[4080] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0097000A
.text C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe[4080] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0098000A
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip Scap.sys (Check Point Software Technologies)
AttachedDevice \Driver\Tcpip \Device\Ip mvstdi5x.sys (Anti-Virus Mini-Firewall Driver/Network Associates, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mvstdi5x.sys (Anti-Virus Mini-Firewall Driver/Network Associates, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Scap.sys (Check Point Software Technologies)
AttachedDevice \Driver\Tcpip \Device\Udp mvstdi5x.sys (Anti-Virus Mini-Firewall Driver/Network Associates, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Scap.sys (Check Point Software Technologies)
AttachedDevice \Driver\Tcpip \Device\RawIp Scap.sys (Check Point Software Technologies)
AttachedDevice \Driver\Tcpip \Device\RawIp mvstdi5x.sys (Anti-Virus Mini-Firewall Driver/Network Associates, Inc.)
Device \FileSystem\Fastfat \Fat A8D9FC8A
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Processes - GMER 1.0.15 —-
Library \\?\globalroot\systemroot\system32\UACxtciihkobvukjrq.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [916] 0x029B0000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1028] 0x00890000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1072] 0x00890000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1132] 0x00890000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1208] 0x00890000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1720] 0x00890000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\Iexplore.exe [2056] 0x00BF0000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\Iexplore.exe [3416] 0x00BF0000
Library \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\IEXPLORE.EXE [3716] 0x00BF0000
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\system32\drivers\UACkcmyktuwuyxiddb.sys (*** hidden *** ) [SYSTEM] UACd.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACkcmyktuwuyxiddb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACkcmyktuwuyxiddb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACgroqpxdaiqjitbo.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACntrgtvsjdyiejax.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACetephdptpxbrelj.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UACnosqlrgsbswwfwa.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACiqmlbwhtsvalfvq.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacmal \\?\globalroot\systemroot\system32\UACdomqieruwpyqdyx.db
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacrem \\?\globalroot\systemroot\system32\UACxtciihkobvukjrq.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UACcofmkbapdnxtqgx.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACnlxdontvnnseyvv.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACxusrkqbjqmqyuky.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACkcmyktuwuyxiddb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACkcmyktuwuyxiddb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACgroqpxdaiqjitbo.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACntrgtvsjdyiejax.dat
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACetephdptpxbrelj.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UACnosqlrgsbswwfwa.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACiqmlbwhtsvalfvq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacmal \\?\globalroot\systemroot\system32\UACdomqieruwpyqdyx.db
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacrem \\?\globalroot\systemroot\system32\UACxtciihkobvukjrq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACqldkboqehkhvyof.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UACcofmkbapdnxtqgx.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACnlxdontvnnseyvv.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACxusrkqbjqmqyuky.log
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion@ProductName Microsoft Windows XP
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion@CurrentVersion 5.1
Reg HKLM\SOFTWARE\Classes\UACTLS.UAAddressBookButtonCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAAddressBookButtonCtrl.5@ UAAddressBookBttn Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAAddressBookButtonCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAAddressBookButtonCtrl.5\CLSID@ {C0E10003-001C-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAButtonCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAButtonCtrl.5@ UAButton Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAButtonCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAButtonCtrl.5\CLSID@ {C0E10003-0007-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UACheckBoxCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UACheckBoxCtrl.5@ UACheckBox Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UACheckBoxCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UACheckBoxCtrl.5\CLSID@ {C0E10003-0013-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UADropDwnCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UADropDwnCtrl.5@ UADropDown Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UADropDwnCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UADropDwnCtrl.5\CLSID@ {C0E10003-000A-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAEditCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAEditCtrl.5@ UAEdit Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAEditCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAEditCtrl.5\CLSID@ {C0E10003-0023-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryButtonCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryButtonCtrl.5@ UAGalleryBttn Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryButtonCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryButtonCtrl.5\CLSID@ {C0E10003-0010-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryCtrl.5@ UAGallery Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGalleryCtrl.5\CLSID@ {C0E10003-0019-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGraphicDropDown.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGraphicDropDown.5@ UAGraphicDropDown Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGraphicDropDown.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAGraphicDropDown.5\CLSID@ {C0E10003-0026-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAHelpCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAHelpCtrl.5@ UAHelp Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAHelpCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAHelpCtrl.5\CLSID@ {C0E10003-002F-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAPartsListCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAPartsListCtrl.5@ UAPartsList Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAPartsListCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAPartsListCtrl.5\CLSID@ {C0E10003-000D-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UARadioBttnCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UARadioBttnCtrl.5@ UARadioButton Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UARadioBttnCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UARadioBttnCtrl.5\CLSID@ {C0E10003-0016-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UAScrapBookButtonCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UAScrapBookButtonCtrl.5@ UAScrapBookBttn Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UAScrapBookButtonCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UAScrapBookButtonCtrl.5\CLSID@ {C0E10003-001F-0005-C0E1-C0E1C0E1C0E1}
Reg HKLM\SOFTWARE\Classes\UACTLS.UATextCtrl.5
Reg HKLM\SOFTWARE\Classes\UACTLS.UATextCtrl.5@ UAText Control
Reg HKLM\SOFTWARE\Classes\UACTLS.UATextCtrl.5\CLSID
Reg HKLM\SOFTWARE\Classes\UACTLS.UATextCtrl.5\CLSID@ {C0E10003-002C-0005-C0E1-C0E1C0E1C0E1}
—- Files - GMER 1.0.15 —-
File C:\Documents and Settings\Joe\Favorites\uacinit.dll Please help remove malicous malware!.url 253 bytes
File C:\Documents and Settings\Joe\Local Settings\Temp\UACd4f3.tmp 343040 bytes executable
File C:\WINDOWS\system32\drivers\UACkcmyktuwuyxiddb.sys 53248 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\UACcofmkbapdnxtqgx.log 44335 bytes
File C:\WINDOWS\system32\UACdomqieruwpyqdyx.db 1110399 bytes
File C:\WINDOWS\system32\UACetephdptpxbrelj.dll 19968 bytes executable
File C:\WINDOWS\system32\UACgroqpxdaiqjitbo.dll 25088 bytes executable
File C:\WINDOWS\system32\uacinit.dll 5712 bytes
File C:\WINDOWS\system32\UACiqmlbwhtsvalfvq.dll 19456 bytes executable
File C:\WINDOWS\system32\UACnosqlrgsbswwfwa.dll 17408 bytes executable
File C:\WINDOWS\system32\UACntrgtvsjdyiejax.dat 224 bytes
File C:\WINDOWS\system32\UACqldkboqehkhvyof.dll 66560 bytes
File C:\WINDOWS\system32\uactmp.db 3976714 bytes
File C:\WINDOWS\system32\UACxtciihkobvukjrq.dll 30208 bytes executable
File C:\WINDOWS\TEMP\UAC8e7f.tmp 66560 bytes
—- EOF - GMER 1.0.15 —-
My PC is running fine – only issue is, if I do a Google search, the font displays too large. Also, I can't open any spyware programs, ie Malware Anti Bytes or Spybot. Double-clicking, right-clicking, etc, do not work – the only thing that does is renaming the program, right-clicking, clicking the Properties button, and setting in the Compatibility mode to run on Windows 2000. But other than that – no popups or anthing.
Thanks!!
EDIT: One strange thing I have noticed – I can't add favorites anymore. I keep adding this post as a favorite, but it won't display in my Favorites dropdown…I get a listing stating "empty," which links to nothing. ALSO, my history shows websites I have NOT visited…creepy!