hevonen
Topic Starter
Hello,
My computer seems to have the b.exe virus. After F-Secure started alerting me about it I ran a full scan and as a result it "isolated" two viruses which I though I deleted from the "isolated" folder (named Trojan FraudPack.ums or something). However, when I look at Task Manager I can see b.exe is running. F-Secure claims there are no viruses on my computer now.
I haven't had any problems yet that I've noticed but naturally want to have my computer virus-free. Could you please tell me what I have to do? I have very basic computer skills.
Thank you very much in advance.
EDIT Oct 9: F-Secure also now spotted Packed.Win32.Krap.ae virus that it isolated in the isolated folder. I haven't done anything about it (for now) since it says it's a secure place to keep it as I don't know if that would alter the information in the logs below? Let me know what I should do when you have the chance. Also, is it safe to back up files(mainly word documents and pictures) to memory sticks or will the virus(es) spread there as well?
(P.S. I'm not sure if I'm using correct terminoly with "isolated" etc as the programs I have on my computer are in my native language of Finnish)
EDIT: I only now realized I posted the wrong attachment. I added it now.
DDS (Ver_09-09-29.01) - NTFSx86
Run by [removed] at 12:56:36,71 on ke 07.10.2009
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_15
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1035.18.1791.870 [GMT 3:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: Saunalahti Turvapaketti 7.00 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\CTsvcCDA.EXE
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Saunalahti Turvapaketti\Anti-Virus\fsgk32st.exe
C:\Program Files\Saunalahti Turvapaketti\Common\FSMA32.EXE
C:\Program Files\Saunalahti Turvapaketti\Anti-Virus\FSGK32.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Saunalahti Turvapaketti\Anti-Virus\fssm32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe
C:\Windows\system32\conime.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Creative\Software Update 3\SoftAuto.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Saunalahti Turvapaketti\Common\FSLAUNCHER0.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\merkku\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.fi/
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
BHO: Adobe PDF Reader -linkkiavustaja: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: XML Class: {500bca15-57a7-4eaf-8143-8c619470b13d} - c:\windows\system32\msxml71.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\google\google_bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: []
uRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
uRun: [SmpcSys] c:\program files\packard bell\setupmypc\SmpSys.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
uRun: [Creative Detector] c:\program files\creative\mediasource\detector\CTDetect.exe /R
uRun: [Veoh] "c:\program files\veoh networks\veoh\VeohClient.exe" /VeohHide
uRun: [SoftAuto.exe] "c:\program files\creative\software update 3\SoftAuto.exe"
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [PopRock] c:\users\merkku\appdata\local\temp\b.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [toolbar_eula_launcher] c:\program files\packard bell\google_eula\EULALauncher.exe
mRun: [F-Secure Manager] "c:\program files\saunalahti turvapaketti\common\FSM32.EXE" /splash
mRun: [F-Secure TNB] "c:\program files\saunalahti turvapaketti\fsgui\TNBUtil.exe" /CHECKALL /WAITFORSW
mRun: [OpwareSE2] "c:\program files\scansoft\omnipagese2.0\OpwareSE2.exe"
mRun: [OPSE reminder] "c:\program files\scansoft\omnipagese2.0\eregeng\ereg.exe" -r "c:\program files\scansoft\omnipagese2.0\eregeng\ereg.ini"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\users\merkku\appdata\roaming\micros~1\windows\startm~1\programs\startup\nikonm~1.lnk - c:\program files\common files\nikon\monitor\NkMonitor.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cleana~1.lnk - c:\program files\cisco systems\clean access agent\CCAAgentLauncher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
mPolicies-explorer: UseDefaultTile = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 0 (0x0)
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html
IE: Vie Microsoft E&xceliin - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {38E51477-DDB4-4aed-9D61-D0C193E10749} - {38E51477-DDB4-4aed-9D61-D0C193E10749} - c:\program files\allmusicconverter\YouTubeRipper.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\program files\saunalahti turvapaketti\fsps\program\fslsp.dll
DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://ezproxy.utu.fi:2191/lib/uniturku/support/plugins/ebraryRdr.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
AppInit_DLLs: c:\progra~1\google\google~3\GOEC62~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\merkku\appdata\roaming\mozilla\firefox\profiles\vy1rdj0l.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fi/
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.visited_color", "#551A8B");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.videoFeeds.handler", "ask");
============= SERVICES / DRIVERS ===============
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2007-7-28 33920]
R1 F-Secure HIPS;F-Secure HIPS;c:\program files\saunalahti turvapaketti\hips\drivers\fshs.sys [2007-7-28 67808]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\system32\drivers\fses.sys [2007-9-11 35552]
R1 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2007-9-11 70944]
R1 fsvista;F-Secure Vista Support Driver;c:\program files\saunalahti turvapaketti\anti-virus\minifilter\fsvista.sys [2007-9-11 12384]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\saunalahti turvapaketti\anti-virus\minifilter\fsgk.sys [2007-9-11 100984]
R3 MusCAudio;MusCAudio;c:\windows\system32\drivers\MusCAudio.sys [2009-8-18 23096]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]
S3 FSORSPClient;F-Secure ORSP Client;c:\program files\saunalahti turvapaketti\orsp client\fsorsp.exe [2007-7-28 55904]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-6-23 29744]
S3 SMServer;SMServer;c:\windows\system32\snmvtsvc.exe [2009-8-18 245760]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\saunalahti turvapaketti\anti-virus\win2k\fsfilter.sys [2007-9-11 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\saunalahti turvapaketti\anti-virus\win2k\fsrec.sys [2007-9-11 25184]
=============== Created Last 30 ================
2009-10-03 01:44 195,440 ——– c:\windows\system32\MpSigStub.exe
2009-10-02 14:25 230,916 a——- c:\windows\system32\msxml71.dll
2009-09-08 22:13 897,608 a——- c:\windows\system32\drivers\tcpip.sys
2009-09-08 22:13 104,960 a——- c:\windows\system32\netiohlp.dll
2009-09-08 22:13 27,136 a——- c:\windows\system32\NETSTAT.EXE
2009-09-08 22:12 19,968 a——- c:\windows\system32\ARP.EXE
2009-09-08 22:12 9,728 a——- c:\windows\system32\TCPSVCS.EXE
2009-09-08 22:12 10,240 a——- c:\windows\system32\finger.exe
2009-09-08 22:12 8,704 a——- c:\windows\system32\HOSTNAME.EXE
2009-09-08 22:12 11,264 a——- c:\windows\system32\MRINFO.EXE
2009-09-08 22:12 17,920 a——- c:\windows\system32\ROUTE.EXE
2009-09-08 22:12 17,920 a——- c:\windows\system32\netevent.dll
2009-09-08 22:10 2,501,921 a——- c:\windows\system32\wlan.tmf
2009-09-08 22:10 293,376 a——- c:\windows\system32\wlanmsm.dll
2009-09-08 22:10 127,488 a——- c:\windows\system32\L2SecHC.dll
2009-09-08 22:10 302,592 a——- c:\windows\system32\wlansec.dll
2009-09-08 22:10 513,024 a——- c:\windows\system32\wlansvc.dll
2009-09-08 22:09 2,868,224 a——- c:\windows\system32\mf.dll
==================== Find3M ====================
2009-10-04 19:30 450,820 a——- c:\windows\system32\perfh00B.dat
2009-10-04 19:30 88,430 a——- c:\windows\system32\perfc00B.dat
2009-09-16 18:09 20 —-h— c:\programdata\PKP_DLdu.DAT
2009-09-16 18:09 20 —-h— c:\progra~2\PKP_DLdu.DAT
2009-08-28 15:39 28,672 a——- c:\windows\system32\Apphlpdm.dll
2009-08-28 15:39 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 15:38 2,153,984 a——- c:\windows\apppatch\AcGenral.dll
2009-08-28 15:38 541,696 a——- c:\windows\apppatch\AcLayers.dll
2009-08-28 15:38 459,776 a——- c:\windows\apppatch\AcSpecfc.dll
2009-08-28 13:15 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-18 03:57 86,016 a——- c:\windows\inf\infstrng.dat
2009-08-18 03:57 51,200 a——- c:\windows\inf\infpub.dat
2009-08-18 03:57 86,016 a——- c:\windows\inf\infstor.dat
2009-08-14 11:35 10,936 a——- c:\windows\system32\MusCVideo.dll
2009-08-14 11:35 3,768 a——- c:\windows\system32\MusCVideo.sys
2009-08-14 11:35 23,096 a——- c:\windows\system32\MusCAudio.sys
2009-08-14 11:35 23,096 a——- c:\windows\system32\drivers\MusCAudio.sys
2009-08-13 18:03 245,760 a——- c:\windows\system32\snmvtsvc.exe
2009-07-25 05:23 411,368 a——- c:\windows\system32\deploytk.dll
2009-07-18 19:06 827,904 a——- c:\windows\system32\wininet.dll
2009-07-18 19:01 78,336 a——- c:\windows\system32\ieencode.dll
2009-07-18 12:46 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-07-17 17:35 71,680 a——- c:\windows\system32\atl.dll
2009-07-14 16:00 313,344 a——- c:\windows\system32\wmpdxm.dll
2009-07-14 15:59 4,096 a——- c:\windows\system32\dxmasf.dll
2009-07-14 15:58 7,680 a——- c:\windows\system32\spwmp.dll
2009-07-14 13:59 8,147,456 a——- c:\windows\system32\wmploc.DLL
2008-07-03 19:19 174 a–sh— c:\program files\desktop.ini
2008-07-03 19:02 665,600 a——- c:\windows\inf\drvindex.dat
2007-06-24 00:35 274,158 a——- c:\windows\inf\perflib\040b\perfi.dat
2007-06-24 00:35 274,158 a——- c:\windows\inf\perflib\040b\perfh.dat
2007-06-24 00:35 36,790 a——- c:\windows\inf\perflib\040b\perfd.dat
2007-06-24 00:35 36,790 a——- c:\windows\inf\perflib\040b\perfc.dat
2006-11-02 12:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 12:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 12:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 12:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2007-07-28 00:01 262,144 a–sh— c:\windows\serviceprofiles\localservice\NTUSER.DAT
2007-07-28 00:00 2,048 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\lastalive0.dat
2007-07-28 00:00 2,048 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\lastalive1.dat
2007-07-28 10:03 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2007-07-28 10:03 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2007-07-28 10:03 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2007-07-28 00:01 262,144 a–sh— c:\windows\serviceprofiles\networkservice\NTUSER.DAT
2007-12-04 02:07 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2007-12-04 02:07 32,768 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2007-12-04 02:07 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
============= FINISH: 12:57:20,14 ===============
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/07 12:59
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x8F445000 Size: 32768 File Visible: No Signed: -
Status: -
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8F43A000 Size: 45056 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x99D3B000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1220 Status: Locked to the Windows API!
SSDT
——————-
#: 078 Function Name: NtCreateThread
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f408e02
#: 165 Function Name: NtLoadDriver
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f40912a
#: 177 Function Name: NtMapViewOfSection
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f408b4e
#: 197 Function Name: NtOpenSection
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f40955c
#: 267 Function Name: NtRenameKey
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f40a7fa
#: 317 Function Name: NtSetSystemInformation
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f4093ac
#: 330 Function Name: NtSuspendProcess
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f4089d4
#: 331 Function Name: NtSuspendThread
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f408e36
#: 332 Function Name: NtSystemDebugControl
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f408fb0
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f408934
#: 335 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f408a8a
#: 358 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f408efa
#: 382 Function Name: NtCreateThreadEx
Status: Hooked by "C:\Program Files\Saunalahti Turvapaketti\HIPS\drivers\fshs.sys" at address 0x8f408e1c
==EOF==