PaulIsInfected
Topic Starter
I have tried a couple Malwarebytes antimalware and ad-aware which seemed to clean my system out quite a bit. I originally had a dpmodemx32.dll (along with some others) that were really bogging down my system. It is now running quickly again, but I keep getting redirected to wierd sites when I am doing google searches. I cannot seem to get rid of this! Any help sure would be appreciated!
Here are the logs:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/12/16 17:30
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAC28A000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA64E000 Size: 8192 File Visible: No Signed: -
Status: -
Name: nwfilter.sys
Image Path: nwfilter.sys
Address: 0xBA4BC000 Size: 15808 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA863F000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
——————-
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04b2f
#: 034 Function Name: NtCreateDirectoryObject
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04b5b
#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04b8f
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04be3
#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04c27
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04c53
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04c93
#: 079 Function Name: NtFlushKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04cd3
#: 105 Function Name: NtMakeTemporaryObject
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04cff
#: 108 Function Name: NtMapViewOfSection
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04d2b
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04d7b
#: 125 Function Name: NtOpenSection
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04daf
#: 151 Function Name: NtQueryInformationFile
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04de3
#: 160 Function Name: NtQueryKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04e1f
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04e5b
#: 183 Function Name: NtReadFile
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04e9b
#: 224 Function Name: NtSetInformationFile
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04ee7
#: 229 Function Name: NtSetInformationThread
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04f23
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04f5b
#: 267 Function Name: NtUnmapViewOfSection
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04f9b
#: 274 Function Name: NtWriteFile
Status: Hooked by "C:\WINDOWS\system32\Drivers\Crypto.sys" at address 0xa9e04fcb
==EOF==