This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Loads of Malware equals Lots of Frustration/Problems

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, I had a whole long post written up here explaining it, and being charming and what not, but then it got closed, so I will just be to the point- Problems: -I have the "Your System is Infected" desktop image, and I cannot change my dekstop. -I cannot click on any link in Internet Explorer without being redirected to misc. websites. -I keep getting the bogus "Internet Security 2010" virus pop-ups incessantly. -I cannot access my Task Manager. -I cannot run a System Restore. I was at the point of saying "forget it, it's done", but then I found your site. It took quite a while to get all the logs I needed thanks to this virus, but I have them now. I actually had to run EXEHelper, DDS, and RootRepeal, so I will post those/attach the one that you have to attach below. I really appreciate the help you can offer me in nixing this virus! exeHelper by Raktor Build 20091204 Run at 00:33:52 on 12/15/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Killed process winupdate86.exe Checking for bad files… Deleting file C:\WINDOWS\system32\41.exe Deleting file C:\WINDOWS\system32\critical_warning.html Deleting file C:\WINDOWS\system32\winupdate86.exe Deleting file C:\Documents and Settings\Owner\Start Menu\Programs\Startup\scandisk.dll Deleting file C:\Documents and Settings\Owner\Start Menu\Programs\Startup\scandisk.lnk Checking for bad registry entries… Removing HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate86.exe Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 0:41:57.15 on Tue 12/15/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.419 [GMT -5:00] AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\acs.exe C:\WINDOWS\system32\Ati2evxx.exe svchost.exe svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\libusbd-nt.exe C:\WINDOWS\runservice.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\ehome\RMSvc.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\system32\dllhost.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\zHotkey.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe C:\Program Files\DNA\btdna.exe C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\NETGEAR\WG311T\wlancfg5.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\InternetSecurity2010\IS2010.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\JTWF29XA\exeHelper[1].com c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe C:\WINDOWS\system32\notepad.exe C:\Documents and Settings\Owner\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.gamefaqs.com/ uDefault_Search_URL = hxxp://searchbar.findthewebsiteyouneed.com uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mURLSearchHooks: H - No File mURLSearchHooks: H - No File BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - No File TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [igndlm.exe] c:\program files\download manager\DLM.exe /windowsstart /startifwork uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount uRun: [jsh87r3huiehf89esiudgd] c:\docume~1\owner\locals~1\temp\lzd97.exe uRun: [asg984jgkfmgasi8ug98jgkfgfb] c:\docume~1\owner\locals~1\temp\install.exe uRun: [bopilsnh] c:\documents and settings\owner\local settings\application data\cksgrn\cqfosysguard.exe uRun: [bcrdgjfd] c:\documents and settings\owner\local settings\application data\bhfane\wkbosysguard.exe uRun: [dwdwaepl] c:\documents and settings\owner\local settings\application data\kstxdf\xkwrsysguard.exe uRun: [notepad] rundll32.exe c:\docume~1\owner\ntload.dll,_IWMPEvents@0 uRun: [Internet Security 2010] c:\program files\internetsecurity2010\IS2010.exe uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10b.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [CHotkey] zHotkey.exe mRun: [ShowWnd] ShowWnd.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [SoundMan] SOUNDMAN.EXE mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe" mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [bopilsnh] c:\documents and settings\owner\local settings\application data\cksgrn\cqfosysguard.exe mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [bcrdgjfd] c:\documents and settings\owner\local settings\application data\bhfane\wkbosysguard.exe mRun: [notepad] rundll32.exe c:\windows\system32\notepad.dll,_IWMPEvents@0 mRun: [dwdwaepl] c:\documents and settings\owner\local settings\application data\kstxdf\xkwrsysguard.exe mRun: [hezazilum] Rundll32.exe "c:\windows\system32\gomukamu.dll",a uPolicies-system: EnableProfileQuota = 1 (0x1) mPolicies-system: EnableLUA = 0 (0x0) dPolicies-explorer: NoSetActiveDesktop = 1 (0x1) dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) dPolicies-system: DisableTaskMgr = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll Trusted Zone: getmirar.com\click Trusted Zone: mirarsearch.com\click Trusted Zone: mirarsearch.com\redirect Trusted Zone: net-nucleus.com\awbeta DPF: Justin.tv Publisher - hxxp://www.justin.tv/plugins/justintv_publisher.CAB DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.systemrequirementslab.com/sysreqlab2.cab DPF: {8ad9c840-044e-11d1-b3e9-00805f499d93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {cafeefac-0016-0000-0015-abcdeffedcba} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {cafeefac-ffff-ffff-ffff-abcdeffedcba} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab TCP: {CD449724-C1DB-4923-AFD0-B304115535C3} = 193.104.110.38,4.2.2.1,192.168.2.1 192.168.2.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\hmelyofflabs\vhtoolkit\Skype4COM.dll Notify: AtiExtEvent - Ati2evxx.dll AppInit_DLLs: nunuluna.dll c:\windows\system32\gomukamu.dll c:\windows\system32\ratifuya.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SSODL: patineyud - {79930fd8-0df1-49e6-8474-154639a543da} - c:\windows\system32\ratifuya.dll SSODL: sitehunej - {0af0ba1f-cabe-413e-b5de-4366767b4908} - c:\windows\system32\ratifuya.dll STS: tokatiluy: {79930fd8-0df1-49e6-8474-154639a543da} - c:\windows\system32\ratifuya.dll STS: gahurihor: {0af0ba1f-cabe-413e-b5de-4366767b4908} - c:\windows\system32\ratifuya.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll LSA: Notification Packages = scecli odbavcet.dll niyihifi.dll ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2007-9-28 214664] R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe –> system32\libusbd-nt.exe [?] R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2006-3-17 2560] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-7-6 359952] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\McrdSvc.exe [2005-10-20 96256] R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2007-9-28 144704] R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-4-3 24652] R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2009-3-5 33792] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2007-9-28 79816] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2007-9-28 35272] S1 70fe0aa2;70fe0aa2;c:\windows\system32\drivers\70fe0aa2.sys –> c:\windows\system32\drivers\70fe0aa2.sys [?] S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] S3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [2005-10-19 16194] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2007-9-28 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2007-9-28 40552] S3 SUSTUCAM;Susteen USB Cable Modem Driver;c:\windows\system32\drivers\sustucam.sys [2006-4-12 38016] S3 U6000ALL;HDTV110 TV Box(ALL);c:\windows\system32\drivers\dmdcap.sys [2009-6-13 230784] S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\drivers\xusb20.sys [2006-10-13 50048] S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2007-9-28 606736] =============== Created Last 30 ================ 2009-12-15 05:28:08 0 —-a-w- c:\windows\system32\26500.exe 2009-12-15 05:08:08 0 —-a-w- c:\windows\system32\6334.exe 2009-12-15 05:01:52 440 –sha-r- c:\documents and settings\owner\ntuser.pol 2009-12-15 04:48:07 0 —-a-w- c:\windows\system32\18467.exe 2009-12-15 04:37:38 0 d—–w- c:\program files\InternetSecurity2010 2009-12-13 18:13:43 39424 –sh–w- c:\windows\system32\kipiheba.dll 2009-12-13 18:13:42 92672 –sh–w- c:\windows\system32\ratifuya.dll 2009-12-13 18:13:01 35328 –sha-w- c:\windows\system32\winlogon86.exe 2009-12-13 03:59:39 0 —-a-w- c:\documents and settings\owner\üµüµ 2009-12-13 03:59:02 18944 —-a-w- c:\windows\system32\winhelper86.dll ==================== Find3M ==================== 2009-12-15 04:26:20 2489 –sha-w- c:\windows\system32\mmf.sys 2009-11-14 00:34:10 4 —-a-w- c:\docume~1\owner\applic~1\avdrn.dat 2009-03-20 16:55:06 349 —-a-w- c:\program files\INSTALL.LOG 2004-12-14 22:47:18 400096 -c–a-w- c:\windows\inf\wg311t\WG311T13.sys 2004-10-20 00:58:28 35232 -c–a-w- c:\windows\inf\wg311t\ME_INST.EXE 2004-10-20 00:58:28 26112 -c–a-w- c:\windows\inf\wg311t\install.exe 2003-12-18 15:33:46 20102 —-a-w- c:\program files\Readme.txt 2003-09-03 11:46:54 10960 —-a-w- c:\program files\EULA.txt 2005-07-08 17:22:58 0 -csha-w- c:\windows\sminst\HPCD.sys 2009-09-13 03:58:55 39424 –sha-w- c:\windows\system32\fuhiheje.dll 2009-09-13 03:58:56 92672 –sha-w- c:\windows\system32\gomukamu.dll 2009-09-13 18:12:56 45568 –sha-w- c:\windows\system32\gotujumu.dll 2009-09-13 18:12:56 33792 –sha-w- c:\windows\system32\lejorude.dll 2009-09-13 03:58:55 45568 –sha-w- c:\windows\system32\nagefipi.dll 2009-09-13 03:49:29 53248 –sha-w- c:\windows\system32\niyihifi.dll 2009-03-21 14:06:58 29696 –sha-w- c:\windows\system32\notepad.dll 2009-09-13 03:49:29 53248 –sha-w- c:\windows\system32\nunuluna.dll 2009-09-13 18:12:56 35328 –sha-w- c:\windows\system32\sokazoya.exe 2009-09-13 03:49:29 53248 –sha-w- c:\windows\system32\sonuleme.dll 2009-09-13 18:12:56 35328 –sha-w- c:\windows\system32\winlogon86.exe 2009-04-09 03:29:56 245760 –sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat 2008-09-04 15:31:24 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090420080905\index.dat ============= FINISH: 0:42:54.87 =============== ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/12/15 00:46 Program Version: Version 1.3.5.0 Windows Version: Windows XP Media Center Edition SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xAE346000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7AEA000 Size: 8192 File Visible: No Signed: - Status: - Name: PCI_PNP5200 Image Path: \Driver\PCI_PNP5200 Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA9FAD000 Size: 49152 File Visible: No Signed: - Status: - Name: spfv.sys Image Path: spfv.sys Address: 0xF73CE000 Size: 1052672 File Visible: No Signed: - Status: - Name: sptd Image Path: \Driver\sptd Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: C:\hiberfil.sys Status: Locked to the Windows API! Path: C:\Documents and Settings\Owner\PRIVATE-Stream of Conciousness-PRIVATE.txt:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Owner\ntload.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\$hf_mig$\{29F8DDC1-9487-49b8-B27E-3E0C3C1298FF} Status: Locked to the Windows API! Path: c:\windows\temp\mcmsc_poxlhpepodotzl4 Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\~df9388.tmp Status: Allocation size mismatch (API: 16384, Raw: 0) Path: c:\windows\temp\mcafee_zomhfqezwfzxswp Status: Allocation size mismatch (API: 4096, Raw: 0) Path: c:\windows\temp\mcmsc_y1dddlnxdfmncwu Status: Allocation size mismatch (API: 4096, Raw: 0) Path: C:\WINDOWS\system32\notepad.dll Status: Invisible to the Windows API! Path: C:\Documents and Settings\Owner\Local Settings\Temp\ntload.dll Status: Invisible to the Windows API! Path: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\scandisk.dll Status: Invisible to the Windows API! Path: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\scandisk.lnk Status: Invisible to the Windows API! SSDT ——————- #: 041 Function Name: NtCreateKey Status: Hooked by "spfv.sys" at address 0xf73cf0e0 #: 071 Function Name: NtEnumerateKey Status: Hooked by "spfv.sys" at address 0xf73edca4 #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "spfv.sys" at address 0xf73ee032 #: 119 Function Name: NtOpenKey Status: Hooked by "spfv.sys" at address 0xf73cf0c0 #: 160 Function Name: NtQueryKey Status: Hooked by "spfv.sys" at address 0xf73ee10a #: 177 Function Name: NtQueryValueKey Status: Hooked by "spfv.sys" at address 0xf73edf8a #: 247 Function Name: NtSetValueKey Status: Hooked by "spfv.sys" at address 0xf73ee19c Stealth Objects ——————- Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP] Process: System Address: 0x873521f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP] Process: System Address: 0x871171f8 Size: 121 Object: Hidden Code [Driver: iviVD, IRP_MJ_CREATE] Process: System Address: 0x873d41f8 Size: 121 Object: Hidden Code [Driver: iviVD, IRP_MJ_CLOSE] Process: System Address: 0x873d41f8 Size: 121 Object: Hidden Code [Driver: iviVD, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873d41f8 Size: 121 Object: Hidden Code [Driver: iviVD, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873d41f8 Size: 121 Object: Hidden Code [Driver: iviVD, IRP_MJ_POWER] Process: System Address: 0x873d41f8 Size: 121 Object: Hidden Code [Driver: iviVD, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873d41f8 Size: 121 Object: Hidden Code [Driver: iviVD, IRP_MJ_PNP] Process: System Address: 0x873d41f8 Size: 121 Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_CREATE] Process: System Address: 0x873d01f8 Size: 121 Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_CLOSE] Process: System Address: 0x873d01f8 Size: 121 Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873d01f8 Size: 121 Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873d01f8 Size: 121 Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_POWER] Process: System Address: 0x873d01f8 Size: 121 Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873d01f8 Size: 121 Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_PNP] Process: System Address: 0x873d01f8 Size: 121 Object: Hidden Code [Driver: perc2, IRP_MJ_CREATE] Process: System Address: 0x873581f8 Size: 121 Object: Hidden Code [Driver: perc2, IRP_MJ_CLOSE] Process: System Address: 0x873581f8 Size: 121 Object: Hidden Code [Driver: perc2, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873581f8 Size: 121 Object: Hidden Code [Driver: perc2, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873581f8 Size: 121 Object: Hidden Code [Driver: perc2, IRP_MJ_POWER] Process: System Address: 0x873581f8 Size: 121 Object: Hidden Code [Driver: perc2, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873581f8 Size: 121 Object: Hidden Code [Driver: perc2, IRP_MJ_PNP] Process: System Address: 0x873581f8 Size: 121 Object: Hidden Code [Driver: cbidf, IRP_MJ_CREATE] Process: System Address: 0x873551f8 Size: 121 Object: Hidden Code [Driver: cbidf, IRP_MJ_CLOSE] Process: System Address: 0x873551f8 Size: 121 Object: Hidden Code [Driver: cbidf, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873551f8 Size: 121 Object: Hidden Code [Driver: cbidf, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873551f8 Size: 121 Object: Hidden Code [Driver: cbidf, IRP_MJ_POWER] Process: System Address: 0x873551f8 Size: 121 Object: Hidden Code [Driver: cbidf, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873551f8 Size: 121 Object: Hidden Code [Driver: cbidf, IRP_MJ_PNP] Process: System Address: 0x873551f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP] Process: System Address: 0x86fcd1f8 Size: 121 Object: Hidden Code [Driver: ini910u, IRP_MJ_CREATE] Process: System Address: 0x873cd1f8 Size: 121 Object: Hidden Code [Driver: ini910u, IRP_MJ_CLOSE] Process: System Address: 0x873cd1f8 Size: 121 Object: Hidden Code [Driver: ini910u, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873cd1f8 Size: 121 Object: Hidden Code [Driver: ini910u, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873cd1f8 Size: 121 Object: Hidden Code [Driver: ini910u, IRP_MJ_POWER] Process: System Address: 0x873cd1f8 Size: 121 Object: Hidden Code [Driver: ini910u, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873cd1f8 Size: 121 Object: Hidden Code [Driver: ini910u, IRP_MJ_PNP] Process: System Address: 0x873cd1f8 Size: 121 Object: Hidden Code [Driver: asc, IRP_MJ_CREATE] Process: System Address: 0x873cf1f8 Size: 121 Object: Hidden Code [Driver: asc, IRP_MJ_CLOSE] Process: System Address: 0x873cf1f8 Size: 121 Object: Hidden Code [Driver: asc, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873cf1f8 Size: 121 Object: Hidden Code [Driver: asc, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873cf1f8 Size: 121 Object: Hidden Code [Driver: asc, IRP_MJ_POWER] Process: System Address: 0x873cf1f8 Size: 121 Object: Hidden Code [Driver: asc, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873cf1f8 Size: 121 Object: Hidden Code [Driver: asc, IRP_MJ_PNP] Process: System Address: 0x873cf1f8 Size: 121 Object: Hidden Code [Driver: ql1280, IRP_MJ_CREATE] Process: System Address: 0x8735a1f8 Size: 121 Object: Hidden Code [Driver: ql1280, IRP_MJ_CLOSE] Process: System Address: 0x8735a1f8 Size: 121 Object: Hidden Code [Driver: ql1280, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8735a1f8 Size: 121 Object: Hidden Code [Driver: ql1280, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8735a1f8 Size: 121 Object: Hidden Code [Driver: ql1280, IRP_MJ_POWER] Process: System Address: 0x8735a1f8 Size: 121 Object: Hidden Code [Driver: ql1280, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8735a1f8 Size: 121 Object: Hidden Code [Driver: ql1280, IRP_MJ_PNP] Process: System Address: 0x8735a1f8 Size: 121 Object: Hidden Code [Driver: asc3350p, IRP_MJ_CREATE] Process: System Address: 0x8735c1f8 Size: 121 Object: Hidden Code [Driver: asc3350p, IRP_MJ_CLOSE] Process: System Address: 0x8735c1f8 Size: 121 Object: Hidden Code [Driver: asc3350p, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8735c1f8 Size: 121 Object: Hidden Code [Driver: asc3350p, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8735c1f8 Size: 121 Object: Hidden Code [Driver: asc3350p, IRP_MJ_POWER] Process: System Address: 0x8735c1f8 Size: 121 Object: Hidden Code [Driver: asc3350p, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8735c1f8 Size: 121 Object: Hidden Code [Driver: asc3350p, IRP_MJ_PNP] Process: System Address: 0x8735c1f8 Size: 121 Object: Hidden Code [Driver: mraid35x, IRP_MJ_CREATE] Process: System Address: 0x873ce1f8 Size: 121 Object: Hidden Code [Driver: mraid35x, IRP_MJ_CLOSE] Process: System Address: 0x873ce1f8 Size: 121 Object: Hidden Code [Driver: mraid35x, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873ce1f8 Size: 121 Object: Hidden Code [Driver: mraid35x, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873ce1f8 Size: 121 Object: Hidden Code [Driver: mraid35x, IRP_MJ_POWER] Process: System Address: 0x873ce1f8 Size: 121 Object: Hidden Code [Driver: mraid35x, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873ce1f8 Size: 121 Object: Hidden Code [Driver: mraid35x, IRP_MJ_PNP] Process: System Address: 0x873ce1f8 Size: 121 Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_CREATE] Process: System Address: 0x873c91f8 Size: 121 Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_CLOSE] Process: System Address: 0x873c91f8 Size: 121 Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873c91f8 Size: 121 Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873c91f8 Size: 121 Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_POWER] Process: System Address: 0x873c91f8 Size: 121 Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873c91f8 Size: 121 Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_PNP] Process: System Address: 0x873c91f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_READ] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_POWER] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: dmio, IRP_MJ_PNP] Process: System Address: 0x873671f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CREATE] Process: System Address: 0x871b81f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CLOSE] Process: System Address: 0x871b81f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_READ] Process: System Address: 0x871b81f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_WRITE] Process: System Address: 0x871b81f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x871b81f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x871b81f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_POWER] Process: System Address: 0x871b81f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x871b81f8 Size: 121 Object: Hidden Code [Driver: USBSTOR, IRP_MJ_PNP] Process: System Address: 0x871b81f8 Size: 121 Object: Hidden Code [Driver: symc8xx, IRP_MJ_CREATE] Process: System Address: 0x8735e1f8 Size: 121 Object: Hidden Code [Driver: symc8xx, IRP_MJ_CLOSE] Process: System Address: 0x8735e1f8 Size: 121 Object: Hidden Code [Driver: symc8xx, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8735e1f8 Size: 121 Object: Hidden Code [Driver: symc8xx, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8735e1f8 Size: 121 Object: Hidden Code [Driver: symc8xx, IRP_MJ_POWER] Process: System Address: 0x8735e1f8 Size: 121 Object: Hidden Code [Driver: symc8xx, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8735e1f8 Size: 121 Object: Hidden Code [Driver: symc8xx, IRP_MJ_PNP] Process: System Address: 0x8735e1f8 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE] Process: System Address: 0x870401f8 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE] Process: System Address: 0x870401f8 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x870401f8 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x870401f8 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER] Process: System Address: 0x870401f8 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x870401f8 Size: 121 Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP] Process: System Address: 0x870401f8 Size: 121 Object: Hidden Code [Driver: ultra, IRP_MJ_CREATE] Process: System Address: 0x873c81f8 Size: 121 Object: Hidden Code [Driver: ultra, IRP_MJ_CLOSE] Process: System Address: 0x873c81f8 Size: 121 Object: Hidden Code [Driver: ultra, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873c81f8 Size: 121 Object: Hidden Code [Driver: ultra, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873c81f8 Size: 121 Object: Hidden Code [Driver: ultra, IRP_MJ_POWER] Process: System Address: 0x873c81f8 Size: 121 Object: Hidden Code [Driver: ultra, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873c81f8 Size: 121 Object: Hidden Code [Driver: ultra, IRP_MJ_PNP] Process: System Address: 0x873c81f8 Size: 121 Object: Hidden Code [Driver: dac960nt, IRP_MJ_CREATE] Process: System Address: 0x873631f8 Size: 121 Object: Hidden Code [Driver: dac960nt, IRP_MJ_CLOSE] Process: System Address: 0x873631f8 Size: 121 Object: Hidden Code [Driver: dac960nt, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873631f8 Size: 121 Object: Hidden Code [Driver: dac960nt, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873631f8 Size: 121 Object: Hidden Code [Driver: dac960nt, IRP_MJ_POWER] Process: System Address: 0x873631f8 Size: 121 Object: Hidden Code [Driver: dac960nt, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873631f8 Size: 121 Object: Hidden Code [Driver: dac960nt, IRP_MJ_PNP] Process: System Address: 0x873631f8 Size: 121 Object: Hidden Code [Driver: aic78u2, IRP_MJ_CREATE] Process: System Address: 0x873cc1f8 Size: 121 Object: Hidden Code [Driver: aic78u2, IRP_MJ_CLOSE] Process: System Address: 0x873cc1f8 Size: 121 Object: Hidden Code [Driver: aic78u2, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873cc1f8 Size: 121 Object: Hidden Code [Driver: aic78u2, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873cc1f8 Size: 121 Object: Hidden Code [Driver: aic78u2, IRP_MJ_POWER] Process: System Address: 0x873cc1f8 Size: 121 Object: Hidden Code [Driver: aic78u2, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873cc1f8 Size: 121 Object: Hidden Code [Driver: aic78u2, IRP_MJ_PNP] Process: System Address: 0x873cc1f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP] Process: System Address: 0x873d51f8 Size: 121 Object: Hidden Code [Driver: adpu160m, IRP_MJ_CREATE] Process: System Address: 0x873c71f8 Size: 121 Object: Hidden Code [Driver: adpu160m, IRP_MJ_CLOSE] Process: System Address: 0x873c71f8 Size: 121 Object: Hidden Code [Driver: adpu160m, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873c71f8 Size: 121 Object: Hidden Code [Driver: adpu160m, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873c71f8 Size: 121 Object: Hidden Code [Driver: adpu160m, IRP_MJ_POWER] Process: System Address: 0x873c71f8 Size: 121 Object: Hidden Code [Driver: adpu160m, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873c71f8 Size: 121 Object: Hidden Code [Driver: adpu160m, IRP_MJ_PNP] Process: System Address: 0x873c71f8 Size: 121 Object: Hidden Code [Driver: sym_u3, IRP_MJ_CREATE] Process: System Address: 0x8735d1f8 Size: 121 Object: Hidden Code [Driver: sym_u3, IRP_MJ_CLOSE] Process: System Address: 0x8735d1f8 Size: 121 Object: Hidden Code [Driver: sym_u3, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8735d1f8 Size: 121 Object: Hidden Code [Driver: sym_u3, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8735d1f8 Size: 121 Object: Hidden Code [Driver: sym_u3, IRP_MJ_POWER] Process: System Address: 0x8735d1f8 Size: 121 Object: Hidden Code [Driver: sym_u3, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8735d1f8 Size: 121 Object: Hidden Code [Driver: sym_u3, IRP_MJ_PNP] Process: System Address: 0x8735d1f8 Size: 121 Object: Hidden Code [Driver: abp480n5, IRP_MJ_CREATE] Process: System Address: 0x873ca1f8 Size: 121 Object: Hidden Code [Driver: abp480n5, IRP_MJ_CLOSE] Process: System Address: 0x873ca1f8 Size: 121 Object: Hidden Code [Driver: abp480n5, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873ca1f8 Size: 121 Object: Hidden Code [Driver: abp480n5, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873ca1f8 Size: 121 Object: Hidden Code [Driver: abp480n5, IRP_MJ_POWER] Process: System Address: 0x873ca1f8 Size: 121 Object: Hidden Code [Driver: abp480n5, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873ca1f8 Size: 121 Object: Hidden Code [Driver: abp480n5, IRP_MJ_PNP] Process: System Address: 0x873ca1f8 Size: 121 Object: Hidden Code [Driver: ql1080, IRP_MJ_CREATE] Process: System Address: 0x8735b1f8 Size: 121 Object: Hidden Code [Driver: ql1080, IRP_MJ_CLOSE] Process: System Address: 0x8735b1f8 Size: 121 Object: Hidden Code [Driver: ql1080, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x8735b1f8 Size: 121 Object: Hidden Code [Driver: ql1080, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x8735b1f8 Size: 121 Object: Hidden Code [Driver: ql1080, IRP_MJ_POWER] Process: System Address: 0x8735b1f8 Size: 121 Object: Hidden Code [Driver: ql1080, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x8735b1f8 Size: 121 Object: Hidden Code [Driver: ql1080, IRP_MJ_PNP] Process: System Address: 0x8735b1f8 Size: 121 Object: Hidden Code [Driver: symc810, IRP_MJ_CREATE] Process: System Address: 0x873641f8 Size: 121 Object: Hidden Code [Driver: symc810, IRP_MJ_CLOSE] Process: System Address: 0x873641f8 Size: 121 Object: Hidden Code [Driver: symc810, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873641f8 Size: 121 Object: Hidden Code [Driver: symc810, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873641f8 Size: 121 Object: Hidden Code [Driver: symc810, IRP_MJ_POWER] Process: System Address: 0x873641f8 Size: 121 Object: Hidden Code [Driver: symc810, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873641f8 Size: 121 Object: Hidden Code [Driver: symc810, IRP_MJ_PNP] Process: System Address: 0x873641f8 Size: 121 Object: Hidden Code [Driver: hpn, IRP_MJ_CREATE] Process: System Address: 0x873561f8 Size: 121 Object: Hidden Code [Driver: hpn, IRP_MJ_CLOSE] Process: System Address: 0x873561f8 Size: 121 Object: Hidden Code [Driver: hpn, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873561f8 Size: 121 Object: Hidden Code [Driver: hpn, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873561f8 Size: 121 Object: Hidden Code [Driver: hpn, IRP_MJ_POWER] Process: System Address: 0x873561f8 Size: 121 Object: Hidden Code [Driver: hpn, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873561f8 Size: 121 Object: Hidden Code [Driver: hpn, IRP_MJ_PNP] Process: System Address: 0x873561f8 Size: 121 Object: Hidden Code [Driver: acmdleenЅఇ牄歭, IRP_MJ_CREATE] Process: System Address: 0x86fba1f8 Size: 121 Object: Hidden Code [Driver: acmdleenЅఇ牄歭, IRP_MJ_CLOSE] Process: System Address: 0x86fba1f8 Size: 121 Object: Hidden Code [Driver: acmdleenЅఇ牄歭, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x86fba1f8 Size: 121 Object: Hidden Code [Driver: acmdleenЅఇ牄歭, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x86fba1f8 Size: 121 Object: Hidden Code [Driver: acmdleenЅఇ牄歭, IRP_MJ_POWER] Process: System Address: 0x86fba1f8 Size: 121 Object: Hidden Code [Driver: acmdleenЅఇ牄歭, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x86fba1f8 Size: 121 Object: Hidden Code [Driver: acmdleenЅఇ牄歭, IRP_MJ_PNP] Process: System Address: 0x86fba1f8 Size: 121 Object: Hidden Code [Driver: ql12160, IRP_MJ_CREATE] Process: System Address: 0x873591f8 Size: 121 Object: Hidden Code [Driver: ql12160, IRP_MJ_CLOSE] Process: System Address: 0x873591f8 Size: 121 Object: Hidden Code [Driver: ql12160, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873591f8 Size: 121 Object: Hidden Code [Driver: ql12160, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873591f8 Size: 121 Object: Hidden Code [Driver: ql12160, IRP_MJ_POWER] Process: System Address: 0x873591f8 Size: 121 Object: Hidden Code [Driver: ql12160, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x873591f8 Size: 121 Object: Hidden Code [Driver: ql12160, IRP_MJ_PNP] Process: System Address: 0x873591f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE] Process: System Address: 0x868fc1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE] Process: System Address: 0x868fc1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x868fc1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x868fc1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP] Process: System Address: 0x868fc1f8 Size: 121 Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP] Process: System Address: 0x868fc1f8 Size: 121 Object: Hidden Code [Driver: aic78xx, IRP_MJ_CREATE] Process: System Address: 0x873d11f8 Size: 121 Object: Hidden Code [Driver: aic78xx, IRP_MJ_CLOSE] Process: System Address: 0x873d11f8 Size: 121 Object: Hidden Code [Driver: aic78xx, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x873d11f8 Size: 121 Object: Hidden Code [Driver: aic78xx, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x873d11f8 Size: 121 Object==EOF== ———- Alright, that is everything. Thanks again for the time you guys take for us! Have a great night. ~Psymin

Attachments:

[external image: Posted Image]

Stay with this topic until I give you the all clean post.

You might want to print these instructions out.


Restart your computer in Safe Mode.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.
This can take several miniutes to load.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.

If you run into one you can't delete just move on.

Delete these Files if listed:
C:\Program Files\InternetSecurity2010\IS2010.exe
c:\documents and settings\owner\local settings\temp\lzd97.exe
c:\documents and settings\owner\local settings\temp\install.exe
c:\documents and settings\owner\local settings\application data\cksgrn\cqfosysguard.exe
c:\documents and settings\owner\local settings\application data\bhfane\wkbosysguard.exe
c:\documents and settings\owner\local settings\application data\kstxdf\xkwrsysguard.exe
c:\windows\system32\gomukamu.dll
c:\windows\system32\ratifuya.dll
c:\windows\system32\drivers\70fe0aa2.sys
c:\windows\system32\26500.exe
c:\windows\system32\6334.exe
c:\windows\system32\18467.exe
c:\windows\system32\kipiheba.dll
c:\windows\system32\winlogon86.exe
c:\documents and settings\owner\üµüµ
c:\windows\system32\winhelper86.dll
c:\windows\system32\fuhiheje.dll
c:\windows\system32\gomukamu.dll
c:\windows\system32\lejorude.dll
c:\windows\system32\nagefipi.dll
c:\windows\system32\niyihifi.dll
c:\windows\system32\notepad.dll <—–Make sure you only delete notepad.dll
c:\windows\system32\nunuluna.dll
c:\windows\system32\sokazoya.exe
c:\windows\system32\sonuleme.dll


Delete these Folders if listed:
C:\Program Files\InternetSecurity2010
c:\documents and settings\owner\local settings\application data\cksgrn
c:\documents and settings\owner\local settings\application data\bhfane
c:\documents and settings\owner\local settings\application data\kstxdf


Reboot and please describe how your computer behaves at the moment.
Awesome! So glad to hear back from you. First off, thank you very much for helping! Now, onto the computer: (I am typing from my Mac Notebook and working on the computer next to me) When I try to start in Safe Mode as you describe, it doesn't load. It takes me to another screen that says "sorry, Windows couldn't up correctly", and gives me options that are "Safe Mode" "Safe Mode with Networking", etc. I tried clicking Safe Mode, and it just rebooted back to the same screen after a couple seconds. At this point, I think it is starting normally because I let it go too long. I will try once more and let you know. Just to note, I had this problem before where I couldn't load in Safe Mode. I think it started happening after I got the first AntiVirus System PRO virus (which I thought I had cured, but evidently not). Anyway, I just restarted and clicked Safe Mode. It jumps back like I mentioned before to the "sorry, Windows did not start successfully"screen. I tried clicking Safe Mode three times now, and it just keeps going back there. So, with that, I am already stuck again. :wacko: So, where should I go from here? The other options are as follows (which you probably know already): Safe Mode Safe Mode with Networking Safe Mode with Command Prompt Last Known Good Configuration (your most recent settings that worked) Start Windows Normally
You don't have much choice then. Boot normal and see if you can open My Computer before you start getting all the pop-ups. You could also try Taskmanager (Atl/Ctrl/Del) before the pop-ups. You're going to have to be quick to do this. If in taskmanager, end the process on any of those files I listed, then delete them from the C drive.
Files that Could not be Found:
c:\documents and settings\owner\local settings\temp\lzd97.exe
c:\documents and settings\owner\local settings\temp\install.exe
c:\documents and settings\owner\local settings\application data\cksgrn\cqfosysguard.exe
c:\documents and settings\owner\local settings\application data\bhfane\wkbosysguard.exe
c:\documents and settings\owner\local settings\application data\kstxdf\xkwrsysguard.exe
c:\windows\system32\gomukamu.dll
c:\windows\system32\ratifuya.dll
c:\windows\system32\drivers\70fe0aa2.sys
c:\windows\system32\26500.exe - Present, but could not be deleted.
c:\windows\system32\6334.exe - Present, but could not be deleted.
c:\windows\system32\18467.exe - Present, but could not be deleted.
c:\windows\system32\kipiheba.dll
c:\windows\system32\winlogon86.exe
c:\documents and settings\owner\üµüµ - Present, but could not be deleted.
c:\windows\system32\fuhiheje.dll
c:\windows\system32\gomukamu.dll
c:\windows\system32\lejorude.dll
c:\windows\system32\nagefipi.dll
c:\windows\system32\niyihifi.dll
c:\windows\system32\notepad.dll <—–Make sure you only delete notepad.dll
c:\windows\system32\nunuluna.dll
c:\windows\system32\sokazoya.exe
c:\windows\system32\sonuleme.dll


Folders that Could not be Found:
c:\documents and settings\owner\local settings\application data\cksgrn


Alright, I have just deleted the ones that I could find, and will now restart.

On startup, the following pops up:
"rundll32.exe - Bad Image"
Inside, it reads- "The application or DLL C:\DOCUME~1\NETWOR~1\ntload.dll is not a valid Windows image. Please check this against your installation diskette."

Once I click "OK" in that box, this box pop up:
"RUNDLL"
"Error loading: C:\DOCUME~1\NETWOR~1\ntload.dll
%1 is not a valid Win32 application."

When I click "OK" on that, it just goes away.

My background does not read "YOU HAVE A VIRUS" or similar anymore, it is just a blank blue background.

I deleted the Internet Security 2010 desktop shortcut icon.

I can only change the color of my desktop image, I cannot change it to a picture, or even scroll through the pictures that are background options.

I can access my task manager again.

There are no more pop ups at all.

When I went on IE, I tried going to a site linked from google search, and another thing popped up that said I was still infected and it looked the Internet Security 2010 logo in the corner.

I am still unable to start up Malwarebytes' Anti-Malware program.

Anything else you need specifically? If not, I'll just wait for the next step. Thanks again!
It is the one that had the same image as the desktop icon, correct? Not "mbamservice.exe"? I renamed the one with the same image as the desktop icon to mbam.com and it still isn't working. Have a good night, I look forward to hearing from you tomorrow. EDIT- Hmmm…is it a problem that I don't have a file named "mbam.exe"? I think I renamed the wrong one; it was called "mbamgui.exe". I only have that and "mbamservice.exe" and "unins000.exe" in terms of exe files. Which of those is the one I am to rename?
Delete whatever MBAM folders / files you have now.

After downloading you should see a MBAM Icon shortcut on your desktop. Run that.
If it still won't run, rename that one to MBAM.com.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.
Good morning. I am unable to delete the Malwarebytes folder, so I clicked the uninstall option inside the folder and that is running now. Well, everything is breaking apart- After I uninstalled that, it said I had to restart to completely remove it. So, I did. When it comes back- Internet Security 2010 is back on the desktop and popping up everywhere! I again cannot access the task manager. So, I haven't yet been able to download MBAM again. I am restarting to do what I did last time to make the popups disappear (the steps you gave me about being quick with ctrl+alt+del at startup). I will post again once I get MBAM installed. Also, there is a McAfee popup that says it detected a "Vundo.gen.bw" virus and will when I click close this message, it continues to pop up. I tried restarting, but the same results occur. EDIT- Oh boy…now I can't even do that. Right when it loads my desktop, an error message appears and I think that is what is stopping me from accessing my task manager unlike last time. I am trying again. EDIT 2- Well, I am stuck. I have tried three time to restart and quickly access the task manager, but I am unable to. It keeps saying it has been disabled by the admin. I will await your help.
I tried installing MBAM to my C:\ drive using the .exe on my thumb drive and it won't load. So, I tried installing it directly on my thumb drive and it wont load either. I changed "mbamgui.exe" to "mbamgui.com" on my thumb driver after and that will not work either. I'm sorry this is being so troublesome, but thank you again for you help.
The only file that would need to be changed would be MBAM.exe the others are fine. Sop at this time you can't get to the desktop at all? Can you see the start button? Do you have your Windows OS CD?
I don't see a file that is just named "mbam.exe". Is there a way I could have that hidden or something? No, I can get to my desktop, it is just filled with pop-ups all the time. And it is a blank white desktop, not my original image pre-virus. I don't think I have my XP cd's anymore. I know I don't have them with me (I moved a few months ago), but they might be at my parents home (which I wouldn't be able to get until after the new year).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI