Hi jmw3,
Thank you for your reply, regrettably I have to inform you that I had installed two programs in an attempt to combat the infection; Spybot SD and Avast! Antivirus.
Not surprisingly these were not successful in eliminating the infection. I apologise for doing this, and will now only install programs as instructed by yourself.
Below I have posted a new HijackThis! log, run in normal mode. In addition to both the DDS and Gmer logs.
Once again,
Thanks for your assistance in the matter.
HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:19:12, on 11/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Apps\SCS\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Apple\library\system\machd.exe
C:\Apple\library\system\nmserver.exe
C:\WINDOWS\system32\APSmscan.exe
C:\Apps\SCS\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\COMMON~1\MICROS~1\VS7Debug\mdm.exe
C:\Apps\LotusNotes\ntmulti.exe
C:\Apps\SCS\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Apps\SCS\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Apps\SCS\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\AcroRead\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Apps\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Apps\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [DesktopAlerter] C:\Apps\DskAlert\DskAlert.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\Apps\SCS\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Apps\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Apps\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Apps\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Apps\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Apps\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Apps\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Apps\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Apps\Adobe\Acrobat\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Apps\Office\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=globalvillage.givaudan.com
O16 - DPF: JavaConnect -
http://sametime/sametime/javaconnect/JavaConnect.cab
O16 - DPF: Oracle Express Web Agent 6_3_3 -
http://gvemsfmps01/oew-install/java/owa633.cab
O16 - DPF: Sametime Meeting Room Client ST30IF3 -
http://sametime/sametime/stmeetingroomclie…gRoomClient.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {A25BE7A9-3102-46B4-BAAE-462471B60ACB} (STConnectivityAgent Control) -
http://sametime/sametime/javaconnect/InstallSTConnAgent.cab
O16 - DPF: {F5131C24-E56D-11CF-B78A-444553540000} (Ikonic Menu Control) -
O16 - DPF: {FA236A66-D7DA-11D3-80F3-0050DA0F154D} (CswMolx1 Control) -
O23 - Service: Apple_Mach_Daemon - Unknown owner - C:\Apple\library\system\machd.exe
O23 - Service: Apple_Netname_Server - Unknown owner - C:\Apple\library\system\nmserver.exe
O23 - Service: Intranet Server Client Software Usage (APSMScan) - Unknown owner - C:\WINDOWS\system32\APSmscan.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Apps\SCS\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Apps\SCS\Symantec Client Firewall\ISSVC.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Apps\LotusNotes\ntmulti.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\Apps\Oracle8\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Apps\SCS\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Apps\SCS\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Apps\SCS\Symantec Client Firewall\SymSPort.exe
–
End of file - 9351 bytes
DDS log:
DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 15:28:11.50 on 11/06/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.503.234 [GMT 1:00]
AV: avast! antivirus 4.8.1335 [VPS 090610-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Client Firewall *enabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Apps\SCS\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Apple\library\system\machd.exe
C:\Apple\library\system\nmserver.exe
C:\WINDOWS\system32\APSmscan.exe
C:\Apps\SCS\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\COMMON~1\MICROS~1\VS7Debug\mdm.exe
C:\Apps\LotusNotes\ntmulti.exe
C:\Apps\SCS\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Apps\SCS\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Apps\SCS\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\Red Star\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
mDefault_Page_URL =
mStart Page =
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\apps\acroread\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [DesktopAlerter] c:\apps\dskalert\DskAlert.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\apps\scs\symant~1\VPTray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_06\bin\jusched.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dPolicies-system: SetVisualStyle =
IE: Convert link target to Adobe PDF - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\apps\adobe\acrobat\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\apps\office\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: JavaConnect - hxxp://sametime/sametime/javaconnect/JavaConnect.cab
DPF: Oracle Express Web Agent 6_3_3 - hxxp://gvemsfmps01/oew-install/java/owa633.cab
DPF: Sametime Meeting Room Client ST30IF3 - hxxp://sametime/sametime/stmeetingroomclient/STMeetingRoomClient.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A25BE7A9-3102-46B4-BAAE-462471B60ACB} - hxxp://sametime/sametime/javaconnect/InstallSTConnAgent.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {F5131C24-E56D-11CF-B78A-444553540000}
DPF: {FA236A66-D7DA-11D3-80F3-0050DA0F154D}
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-5-24 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-11 114768]
R1 SAVRT;SAVRT;c:\apps\scs\symantec antivirus\savrt.sys [2005-12-19 337592]
R1 SAVRTPEL;SAVRTPEL;c:\apps\scs\symantec antivirus\Savrtpel.sys [2005-12-19 54968]
R2 Apple_Mach_Daemon;Apple_Mach_Daemon;c:\apple\library\system\machd.exe [2007-10-12 72192]
R2 Apple_Netname_Server;Apple_Netname_Server;c:\apple\library\system\nmserver.exe [2007-10-12 114688]
R2 APSMDrv;Intranet Server Client Software Usage driver;c:\windows\system32\drivers\APSMDrv.sys [2007-10-30 3223]
R2 APSMScan;Intranet Server Client Software Usage;c:\windows\system32\APSmscan.exe [2007-10-30 20480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-11 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-6-11 138680]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-20 192160]
R2 ccProxy;Symantec Network Proxy;c:\program files\common files\symantec shared\ccProxy.exe [2006-7-20 202400]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-20 169632]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\apps\scs\symantec antivirus\Rtvscan.exe [2006-8-3 1807600]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-6-11 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-6-11 352920]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-5-24 101936]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2007-10-11 87936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090524.003\naveng.sys [2009-5-24 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090524.003\navex15.sys [2009-5-24 876144]
S3 APSINV;APSINV;c:\windows\system32\drivers\APSINV.SYS [2007-10-30 23408]
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\apps\oracle8\bin\ONRSD.EXE [2007-10-11 411244]
S3 SavRoam;SAVRoam;c:\apps\scs\symantec antivirus\SavRoam.exe [2006-8-3 115952]
=============== Created Last 30 ================
2009-06-11 13:44 16,384 a——t c:\temp\Perflib_Perfdata_6b8.dat
2009-06-11 02:37 –d—– c:\temp\_avast4_
2009-06-10 21:05 4,185 a——- c:\windows\wininit.ini
2009-06-10 20:12 –d—– c:\windows\pss
2009-06-10 14:25 –d—– c:\program files\Trend Micro
2009-06-10 12:16 –d—– c:\program files\Spybot - Search & Destroy
2009-06-10 12:16 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-06-09 17:04 –d—– c:\program files\Loaris Trojan Remover
2009-06-09 16:25 5,712 ——– c:\windows\system32\uacinit.dll
2009-06-09 16:25 224 ——– c:\windows\system32\UACpegowktusiuxtpe.dat
2009-06-09 16:22 –d—– c:\docume~1\redsta~1\applic~1\ptidl
2009-06-09 16:07 323,584 a——- c:\windows\system32\AUDIOGENIE2.DLL
2009-06-09 16:04 –d—– c:\windows\Replay Media Catcher
2009-06-08 15:57 –d—– c:\docume~1\redsta~1\applic~1\FileOpen
2009-05-31 14:55 406 a——- c:\windows\system32\ioloBootDefrag.cfg
2009-05-31 14:55 –d—– c:\docume~1\redsta~1\applic~1\iolo
2009-05-31 14:55 –d—– c:\docume~1\alluse~1\applic~1\iolo
2009-05-24 19:09 –ds—- c:\documents and settings\red star\UserData
2009-05-24 18:52 –d—– c:\documents and settings\Red Star
2009-05-24 18:36 15,688 a——- c:\windows\system32\lsdelete.exe
2009-05-24 18:24 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-05-24 18:21 -cd-h— c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-24 18:21 –d—– c:\program files\Lavasoft
==================== Find3M ====================
============= FINISH: 15:28:45.76 ===============
DDS Attach log:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-05-14.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 11/10/2007 16:01:27
System Uptime: 06/11/2009 13:43:06 (-3550 hours ago)
Motherboard: Dell Inc. | | 0XD762
Processor: Intel® Pentium® M processor 1.73GHz | Microprocessor | 1730/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 20 GiB total, 4.866 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 7 GiB total, 3.387 GiB free.
F: is Removable
G: is FIXED (NTFS) - 10 GiB total, 2.123 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1: 11/10/2007 16:06:10 - System Checkpoint
RP2: 11/10/2007 16:19:42 - Installed TI_Inst
==== Installed Programs ======================
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Shockwave Player
avast! Antivirus
Corel Paint Shop Pro X
Critical Update for Windows Media Player 11 (KB959772)
FLV Player
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Java™ 6 Update 6
LimeWire 4.18.3
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Nero OEM
PeerGuardian 2.0
QuickTime
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB963027)
Spybot - Search & Destroy
Symantec Client Security
TI_Inst
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
==== Event Viewer Messages From Past Week ========
11/06/2009 13:12:39, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi eeCtrl Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SAVRT SAVRTPEL SYMTDI Tcpip
10/06/2009 21:39:06, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_1258.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:40, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_10082.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:40, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_10081.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:40, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_10079.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:40, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_10029.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:40, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_10017.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:40, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_10010.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:40, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_10007.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:39, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_10006.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:39, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_10000.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:32, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_28599.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:32, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_28598.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:32, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_28597.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:32, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_28595.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:32, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_28594.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:32, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_28593.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:32, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_28592.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:32, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_28591.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:32, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_21866.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:32, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_20905.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:31, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_20866.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:31, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_20261.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:31, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_20127.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:38:14, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_28603.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:37:22, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_28605.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:37, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_1026.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:36, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_950.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:36, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_949.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:36, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_936.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:36, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_932.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:36, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_875.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:36, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_874.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:36, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_869.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:36, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_866.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:36, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_865.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:35, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_863.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:35, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_861.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:35, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_860.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:35, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_857.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:35, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_855.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:35, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_852.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:35, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_850.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:34, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_775.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:34, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_737.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:34, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_500.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:34, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_437.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
10/06/2009 21:36:34, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\c_037.nls. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
09/06/2009 23:14:14, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
09/06/2009 23:10:21, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
09/06/2009 22:46:08, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD eeCtrl Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SAVRT SAVRTPEL SYMTDI Tcpip
09/06/2009 22:46:08, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
09/06/2009 22:46:08, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
09/06/2009 22:46:08, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
09/06/2009 22:46:08, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
09/06/2009 02:11:28, error: Dhcp [1002] - The IP address lease [removed] for the Network Card with network address 0015C51EBA89 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
07/06/2009 17:55:17, error: Dhcp [1002] - The IP address lease 192.168.100.10 for the Network Card with network address 0015C51EBA89 has been denied by the DHCP server [removed] (The DHCP Server sent a DHCPNACK message).
==== End Of File ===========================
Gmer log:
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-06-12 01:26:29
Windows 5.1.2600 Service Pack 3
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAAA876B8]
SSDT 82C900D0 ZwConnectPort
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAAA87574]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAAF31CC0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAAA8714C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAAA8764E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAAA8708C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAAA870F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAAA8776E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAAA8772E]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAAF31F20]
—- Devices - GMER 1.0.15 —-
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
—- Services - GMER 1.0.15 —-
Service system32\drivers\UACqgdkeqoyxjbnfva.sys (*** hidden *** ) [SYSTEM] UACd.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACqgdkeqoyxjbnfva.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACqgdkeqoyxjbnfva.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@group file system
—- EOF - GMER 1.0.15 —-