Hi,
Please do the following:
Please download DDS from either of these links
LINK 1
LINK 2
and save it to your desktop.
- Disable any script blocking protection
- Double click dds.pif to run the tool.
- When done, two DDS.txt's will open.
- Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt.
NEXT
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image]
Click the image to enlarge it
- In the right panel, you will see several boxes that have been checked. Uncheck the following …
- Sections
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
This is the file Gmer.txt. Thank you for the help.
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-01-01 14:07:39
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\fglyafog.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\System32\drivers\8c607f38.sys ZwCreateEvent [0xEDC74595]
SSDT \SystemRoot\System32\drivers\8c607f38.sys ZwCreateKey [0xEDC72585]
SSDT \SystemRoot\System32\drivers\8c607f38.sys ZwOpenKey [0xEDC72645]
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 8c607f38.sys
AttachedDevice \FileSystem\Ntfs \Ntfs TmPreFlt.sys (Pre-Filter For XP/Trend Micro Inc.)
Device \Driver\Tcpip \Device\Ip 8c607f38.sys
Device \Driver\Tcpip \Device\Tcp 8c607f38.sys
Device \Driver\Tcpip \Device\Udp 8c607f38.sys
Device \Driver\Tcpip \Device\RawIp 8c607f38.sys
Device \Driver\Tcpip \Device\IPMULTICAST 8c607f38.sys
AttachedDevice \FileSystem\Fastfat \Fat TmPreFlt.sys (Pre-Filter For XP/Trend Micro Inc.)
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\System32\drivers\8c607f38.sys (*** hidden *** ) [SYSTEM] 8c607f38 <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@ImagePath \SystemRoot\System32\drivers\8c607f38.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@kadfmmqr 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\8c607f38@F96ZK6nPB YmF0dXJhbWViZWwuY29t
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@ImagePath \SystemRoot\System32\drivers\8c607f38.sys
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@Type 1
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@Start 1
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@kadfmmqr 1
Reg HKLM\SYSTEM\ControlSet002\Services\8c607f38@F96ZK6nPB YmF0dXJhbWViZWwuY29t
—- EOF - GMER 1.0.15 —-