This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Rootkit Infection - Norton does not find anything but detects behavior

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Re-Run aswMBR 

Click Scan

On completion of the scan

Click the   Fix for TDL4 or FIXMBR for Whistler   Button Select as appropriate

[external image: Posted Image]

[external image: Posted Image]



Save the log as before and post in your next reply
Here you go: aswMBR version 0.9.4 Copyright© 2011 AVAST Software Run date: 2011-04-22 00:14:30 —————————– 00:14:30.046 OS Version: Windows 5.1.2600 Service Pack 3 00:14:30.062 Number of processors: 2 586 0x209 00:14:30.062 ComputerName: S0031784443 UserName: 00:14:32.296 Initialize success 00:14:35.953 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 00:14:35.953 Disk 0 Vendor: Maxtor_6Y160P0 YAR41BW0 Size: 156334MB BusType: 3 00:14:35.953 Device \Driver\atapi -> DriverStartIo 8a30a33b 00:14:35.953 Disk 0 MBR read error 00:14:35.953 Disk 0 MBR scan 00:14:35.953 MBR BIOS signature not found 0 00:14:35.953 Disk 0 scanning sectors +320143320 00:14:35.968 Disk 0 scanning C:\WINDOWS\system32\drivers 00:14:49.609 Service scanning 00:14:50.687 Disk 0 trace - called modules: 00:14:50.687 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8a30a4f0]<< 00:14:50.687 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a35aab8] 00:14:50.687 3 CLASSPNP.SYS[f7657fd7] -> nt!IofCallDriver -> \Device\00000077[0x8a35bf18] 00:14:50.687 5 ACPI.sys[f75ae620] -> nt!IofCallDriver -> [0x8a37ad98] 00:14:50.687 \Driver\atapi[0x8a330b08] -> IRP_MJ_CREATE -> 0x8a30a4f0 00:14:50.687 Scan finished successfully 00:15:13.406 Disk 0 MBR fix error
Hmm… This one is a stubborn one.


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
I've tried twice to get GMER to complete its scan. The first time, it ran for a few hours, and when it was done, a message popped up basically saying there were no system resources left to complete the required actions. I did run MBR. Here's the log: MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000003d Kernel Drivers (total 158): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x80700000 \WINDOWS\system32\hal.dll 0x8A2B7000 \WINDOWS\system32\KDCOM.DLL 0xF789B000 \WINDOWS\system32\BOOTVID.dll 0xF75A8000 ACPI.sys 0xF7987000 \WINDOWS\System32\DRIVERS\WMILIB.SYS 0xF7597000 pci.sys 0xF75F7000 isapnp.sys 0xF7607000 ohci1394.sys 0xF7617000 \WINDOWS\System32\DRIVERS\1394BUS.SYS 0xF7A4F000 pciide.sys 0xF7707000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS 0xF7627000 MountMgr.sys 0xF74D8000 ftdisk.sys 0xF770F000 PartMgr.sys 0xF7637000 VolSnap.sys 0xF74C0000 atapi.sys 0xF7647000 disk.sys 0xF7657000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS 0xF74A0000 fltmgr.sys 0xF7449000 SYMDS.SYS 0xF7437000 sr.sys 0xF7B3B000 SYMEFA.SYS 0xF7667000 PxHelp20.sys 0xBA7E9000 KSecDD.sys 0xBA75C000 Ntfs.sys 0xBA72F000 NDIS.sys 0xBA715000 Mup.sys 0xF7677000 agp440.sys 0xF76A7000 \SystemRoot\System32\DRIVERS\nic1394.sys 0xF7507000 \SystemRoot\System32\DRIVERS\intelppm.sys 0xB519D000 \SystemRoot\System32\DRIVERS\ati2mtag.sys 0xB5189000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS 0xF774F000 \SystemRoot\System32\DRIVERS\usbuhci.sys 0xB5165000 \SystemRoot\System32\DRIVERS\USBPORT.SYS 0xF7757000 \SystemRoot\System32\DRIVERS\usbehci.sys 0xB50F6000 \SystemRoot\system32\drivers\ctaud2k.sys 0xB50D2000 \SystemRoot\system32\drivers\portcls.sys 0xF74F7000 \SystemRoot\system32\drivers\drmk.sys 0xB50AF000 \SystemRoot\system32\drivers\ks.sys 0xB5084000 \SystemRoot\system32\drivers\ctoss2k.sys 0xF799D000 \SystemRoot\system32\drivers\ctprxy2k.sys 0xB4FAF000 \SystemRoot\System32\DRIVERS\BCMDM.sys 0xF7767000 \SystemRoot\System32\Drivers\Modem.SYS 0xB4F8B000 \SystemRoot\System32\DRIVERS\e100b325.sys 0xBA705000 \SystemRoot\System32\DRIVERS\i8042prt.sys 0xF776F000 \SystemRoot\System32\DRIVERS\kbdclass.sys 0xF7777000 \SystemRoot\System32\DRIVERS\fdc.sys 0xBA40F000 \SystemRoot\System32\DRIVERS\serial.sys 0xB94D3000 \SystemRoot\System32\DRIVERS\serenum.sys 0xB4F77000 \SystemRoot\System32\DRIVERS\parport.sys 0xBA3FF000 \SystemRoot\System32\DRIVERS\imapi.sys 0xB559B000 \SystemRoot\system32\drivers\ASAPIW2k.sys 0xB94CF000 \SystemRoot\system32\drivers\pfc.sys 0xBA3EF000 \SystemRoot\System32\DRIVERS\cdrom.sys 0xBA3DF000 \SystemRoot\System32\DRIVERS\redbook.sys 0xB5593000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys 0xB4EF2000 \SystemRoot\system32\drivers\smwdm.sys 0xF79A1000 \SystemRoot\system32\drivers\aeaudio.sys 0xB4E01000 \SystemRoot\system32\DRIVERS\btkrnl.sys 0xF79A3000 \SystemRoot\system32\DRIVERS\serscan.sys 0xBA238000 \SystemRoot\System32\DRIVERS\audstub.sys 0xBA3CF000 \SystemRoot\System32\DRIVERS\rasl2tp.sys 0xBA609000 \SystemRoot\System32\DRIVERS\ndistapi.sys 0xB4DEA000 \SystemRoot\System32\DRIVERS\ndiswan.sys 0xBA3BF000 \SystemRoot\System32\DRIVERS\raspppoe.sys 0xBA3AF000 \SystemRoot\System32\DRIVERS\raspptp.sys 0xB558B000 \SystemRoot\System32\DRIVERS\TDI.SYS 0xB4DD9000 \SystemRoot\System32\DRIVERS\psched.sys 0xBA39F000 \SystemRoot\System32\DRIVERS\msgpc.sys 0xB5583000 \SystemRoot\System32\DRIVERS\ptilink.sys 0xB557B000 \SystemRoot\System32\DRIVERS\raspti.sys 0xBA38F000 \SystemRoot\system32\DRIVERS\NetDirect.sys 0xBA37F000 \SystemRoot\System32\DRIVERS\termdd.sys 0xB5573000 \SystemRoot\System32\DRIVERS\mouclass.sys 0xF79A5000 \SystemRoot\System32\DRIVERS\swenum.sys 0xB4D7B000 \SystemRoot\System32\DRIVERS\update.sys 0xBA261000 \SystemRoot\System32\DRIVERS\mssmbios.sys 0xB556B000 \SystemRoot\system32\DRIVERS\btport.sys 0xB9EAD000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xBA6C5000 \SystemRoot\System32\DRIVERS\usbhub.sys 0xF79B1000 \SystemRoot\System32\DRIVERS\USBD.SYS 0xA38FF000 \SystemRoot\system32\drivers\ha10kx2k.sys 0xA38DF000 \SystemRoot\system32\drivers\ctac32k.sys 0xA38C4000 \SystemRoot\system32\drivers\emupia2k.sys 0xA38A5000 \SystemRoot\system32\drivers\ctsfm2k.sys 0xA3885000 \SystemRoot\system32\drivers\hap16v2k.sys 0xF7947000 \SystemRoot\system32\drivers\MODEMCSA.sys 0xF77BF000 \SystemRoot\System32\DRIVERS\flpydisk.sys 0xA22BB000 \SystemRoot\System32\Drivers\NAV\1205000.07D\SRTSP.SYS 0xA2297000 \SystemRoot\system32\drivers\NAV\1205000.07D\Ironx86.SYS 0xF7587000 \SystemRoot\system32\drivers\NAV\1205000.07D\SRTSPX.SYS 0xA2271000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xB94EB000 \SystemRoot\System32\DRIVERS\hidusb.sys 0xF7547000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS 0xF7807000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS 0xA0568000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0xF79E5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7A83000 \SystemRoot\System32\Drivers\Null.SYS 0xF79E7000 \SystemRoot\System32\Drivers\Beep.SYS 0xA3B6D000 \SystemRoot\System32\DRIVERS\mouhid.sys 0xA0560000 \SystemRoot\System32\drivers\vga.sys 0xF79E9000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF79F9000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xA0558000 \SystemRoot\System32\Drivers\Msfs.SYS 0xA0550000 \SystemRoot\System32\Drivers\Npfs.SYS 0xB94E3000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x9F507000 \SystemRoot\System32\DRIVERS\ipsec.sys 0x9F4AE000 \SystemRoot\System32\DRIVERS\tcpip.sys 0x9F488000 \SystemRoot\System32\DRIVERS\ipnat.sys 0x9F42F000 \SystemRoot\System32\Drivers\NAV\1205000.07D\SYMTDI.SYS 0xA4707000 \SystemRoot\System32\DRIVERS\wanarp.sys 0x9F3D7000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110421.001\IDSxpx86.sys 0xA46F7000 \SystemRoot\System32\DRIVERS\arp1394.sys 0x9F3AF000 \SystemRoot\System32\DRIVERS\netbt.sys 0xA46E7000 \SystemRoot\System32\Drivers\btwusb.sys 0xA0719000 \SystemRoot\System32\drivers\ws2ifsl.sys 0x9F38D000 \SystemRoot\System32\drivers\afd.sys 0xA46D7000 \SystemRoot\System32\DRIVERS\netbios.sys 0xA0711000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x9F362000 \SystemRoot\System32\DRIVERS\rdbss.sys 0x9F2F2000 \SystemRoot\System32\DRIVERS\mrxsmb.sys 0xA36C5000 \SystemRoot\System32\Drivers\Fips.SYS 0x9F294000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0x9F1CC000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110419.001\BHDrvx86.sys 0x9F1AE000 \SystemRoot\system32\DRIVERS\btwdndis.sys 0x9F12D000 \SystemRoot\system32\drivers\btaudio.sys 0x9FE6D000 \SystemRoot\system32\DRIVERS\btwhid.sys 0x98FFE000 \SystemRoot\System32\Drivers\Cdfs.SYS 0x98554000 \SystemRoot\System32\Drivers\dump_atapi.sys 0x9A511000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0x98592000 \SystemRoot\System32\drivers\Dxapi.sys 0x99148000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0x9856D000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\ati2dvag.dll 0xBF065000 \SystemRoot\System32\ati2cqag.dll 0xBF0FE000 \SystemRoot\System32\atikvmag.dll 0xBF182000 \SystemRoot\System32\atiok3x2.dll 0xBF1CD000 \SystemRoot\System32\ati3duag.dll 0xBF572000 \SystemRoot\System32\ativvaxx.dll 0xBA615000 \SystemRoot\System32\DRIVERS\ndisuio.sys 0xBF9C6000 \SystemRoot\System32\ATMFD.DLL 0x962D7000 \SystemRoot\System32\DRIVERS\mrxdav.sys 0x98C3B000 \SystemRoot\System32\Drivers\ParVdm.SYS 0x961D2000 \SystemRoot\system32\drivers\wdmaud.sys 0x98A2D000 \SystemRoot\system32\drivers\sysaudio.sys 0x960DC000 \SystemRoot\System32\DRIVERS\srv.sys 0xA18F6000 \SystemRoot\system32\drivers\npf.sys 0x96173000 \??\C:\WINDOWS\System32\PfModNT.sys 0xA085D000 \SystemRoot\System32\DRIVERS\secdrv.sys 0x9570B000 \SystemRoot\System32\Drivers\HTTP.sys 0x95316000 \SystemRoot\System32\Drivers\Fastfat.SYS 0x952C3000 \SystemRoot\system32\drivers\kmixer.sys 0x95030000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110421.020\NAVEX15.SYS 0x9501C000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110421.020\NAVENG.SYS 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 57): 0 System Idle Process 4 System 880 C:\WINDOWS\system32\smss.exe 1004 csrss.exe 1044 C:\WINDOWS\system32\winlogon.exe 1096 C:\WINDOWS\system32\services.exe 1108 C:\WINDOWS\system32\lsass.exe 1268 C:\WINDOWS\system32\ati2evxx.exe 1292 C:\WINDOWS\system32\svchost.exe 1408 svchost.exe 1556 C:\WINDOWS\system32\svchost.exe 1596 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe 1740 svchost.exe 1840 C:\WINDOWS\system32\ati2evxx.exe 1916 svchost.exe 128 C:\WINDOWS\system32\spoolsv.exe 668 svchost.exe 708 C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe 768 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 816 C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe 872 C:\Program Files\Bonjour\mDNSResponder.exe 1064 C:\WINDOWS\system32\CTSVCCDA.EXE 1528 C:\Program Files\Google\Update\GoogleUpdate.exe 1700 C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe 264 C:\Program Files\Java\jre6\bin\jqs.exe 376 C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe 544 C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\18.5.0.125\ccsvchst.exe 636 C:\WINDOWS\explorer.exe 836 C:\WINDOWS\system32\PnkBstrA.exe 924 C:\WINDOWS\system32\PnkBstrB.exe 1668 C:\WINDOWS\system32\svchost.exe 1324 C:\WINDOWS\system32\MsPMSPSv.exe 2196 C:\WINDOWS\system32\svchost.exe 3212 C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe 3396 C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe 3412 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe 3472 C:\WINDOWS\system32\cthelper.exe 3492 C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDET.exe 3512 C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE 3540 C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE 3696 C:\Program Files\iTunes\iTunesHelper.exe 3716 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe 3748 C:\Program Files\Common Files\Java\Java Update\jusched.exe 3920 C:\Program Files\Creative\Shared Files\CamTray.exe 3944 C:\WINDOWS\system32\ctfmon.exe 1852 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe 280 C:\Program Files\FinePixViewerS\QuickDCF2.exe 344 C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe 828 C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\18.5.0.125\ccsvchst.exe 2664 C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE 3680 alg.exe 496 C:\Program Files\iPod\bin\iPodService.exe 2836 wmiprvse.exe 2912 C:\Program Files\Internet Explorer\iexplore.exe 2740 C:\Program Files\Internet Explorer\iexplore.exe 980 C:\WINDOWS\system32\wscntfy.exe 4052 C:\Documents and Settings\Robert and Tess\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\F: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: Maxtor6Y160P0, Rev: YAR41BW0 PhysicalDrive1 Model Number: SeagateFA GoFlex Desk, Rev: 0155 Size Device Name MBR Status ——————————————– 152 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A 1863 GB \\.\PhysicalDrive1 RE: Unknown MBR code SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98F Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
Thanks for the log. Since GMER won't run, let's give Rootkit Unhooker a run.

Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.
    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
Here's the RootKit report: RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #2 ============================================== >Drivers ============================================== 0xB519D000 C:\WINDOWS\System32\DRIVERS\ati2mtag.sys 3891200 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver) 0xBF1CD000 C:\WINDOWS\System32\ati3duag.dll 3821568 bytes (ATI Technologies Inc. , ati3duag.dll) 0xBF572000 C:\WINDOWS\System32\ativvaxx.dll 2670592 bytes (ATI Technologies Inc. , Radeon Video Acceleration Universal Driver) 0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2265088 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2265088 bytes 0x804D7000 RAW 2265088 bytes 0x804D7000 WMIxWDM 2265088 bytes 0xBF800000 Win32k 1859584 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1859584 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0x94CCC000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110422.003\NAVEX15.SYS 1388544 bytes (Symantec Corporation, AV Engine) 0xB4E01000 C:\WINDOWS\system32\DRIVERS\btkrnl.sys 987136 bytes (Broadcom Corporation., Bluetooth Bus Enumerator) 0xB4FAF000 C:\WINDOWS\System32\DRIVERS\BCMDM.sys 872448 bytes (BCM, Modem Device Driver) 0x9F1CC000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110419.001\BHDrvx86.sys 819200 bytes (Symantec Corporation, BASH Driver) 0xA38FF000 C:\WINDOWS\system32\drivers\ha10kx2k.sys 770048 bytes (Creative Technology Ltd, Creative EMU10KX HAL (WDM)) 0xF7B3B000 SYMEFA.SYS 671744 bytes 0xBF065000 C:\WINDOWS\System32\ati2cqag.dll 626688 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module) 0xBA75C000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xB4EF2000 C:\WINDOWS\system32\drivers\smwdm.sys 544768 bytes (Analog Devices, Inc., SoundMAX Integrated Digital Audio ) 0xA22BB000 C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SRTSP.SYS 544768 bytes (Symantec Corporation, Symantec AutoProtect) 0xBF0FE000 C:\WINDOWS\System32\atikvmag.dll 540672 bytes (ATI Technologies Inc., Virtual Command And Memory Manager) 0x9F12D000 C:\WINDOWS\system32\drivers\btaudio.sys 528384 bytes (Broadcom Corporation., Bluetooth Audio Device) 0x9F2F2000 C:\WINDOWS\System32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xB50F6000 C:\WINDOWS\system32\drivers\ctaud2k.sys 454656 bytes (Creative Technology Ltd, Creative WDM Audio Device Driver) 0x9F294000 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 385024 bytes (Symantec Corporation, Symantec Eraser Control Driver) 0xB4D7B000 C:\WINDOWS\System32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0x9F42F000 C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SYMTDI.SYS 364544 bytes (Symantec Corporation, Network Dispatch Driver) 0x9F4AE000 C:\WINDOWS\System32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0x9F3D7000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110421.001\IDSxpx86.sys 360448 bytes (Symantec Corporation, IDS Core Driver) 0x960DC000 C:\WINDOWS\System32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver) 0xF7449000 SYMDS.SYS 356352 bytes 0xBF012000 C:\WINDOWS\System32\ati2dvag.dll 339968 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver) 0xBF182000 C:\WINDOWS\System32\atiok3x2.dll 307200 bytes (ATI Technologies Inc., Ring 0 x2 component) 0xBF9C6000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0x9570B000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xF75A8000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0x962D7000 C:\WINDOWS\System32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xBA72F000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xB5084000 C:\WINDOWS\system32\drivers\ctoss2k.sys 176128 bytes (Creative Technology Ltd., Creative OS Services Driver (WDM)) 0x94C8D000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0x9F362000 C:\WINDOWS\System32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0x9F3AF000 C:\WINDOWS\System32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0x9F488000 C:\WINDOWS\System32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xA2271000 C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 155648 bytes (Symantec Corporation, Symantec Event Library) 0xB4F8B000 C:\WINDOWS\System32\DRIVERS\e100b325.sys 147456 bytes (Intel Corporation, Intel® PRO/100 Adapter NDIS 5.1 driver) 0x95316000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xA2297000 C:\WINDOWS\system32\drivers\NAV\1205000.07D\Ironx86.SYS 147456 bytes (Symantec Corporation, Iron Driver) 0xB50D2000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xB5165000 C:\WINDOWS\System32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xB50AF000 C:\WINDOWS\system32\drivers\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0x9F38D000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x80700000 ACPI_HAL 134400 bytes 0x80700000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xA38DF000 C:\WINDOWS\system32\drivers\ctac32k.sys 131072 bytes (Creative Technology Ltd, Creative AC3 SW Decoder Device Driver (WDM)) 0xF74A0000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xA3885000 C:\WINDOWS\system32\drivers\hap16v2k.sys 131072 bytes (Creative Technology Ltd, Creative EMU10KX-P16v HAL (WDM)) 0xA38A5000 C:\WINDOWS\system32\drivers\ctsfm2k.sys 126976 bytes (Creative Technology Ltd, SoundFont® Manager (WDM)) 0xF74D8000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0x9F1AE000 C:\WINDOWS\system32\DRIVERS\btwdndis.sys 122880 bytes (Broadcom Corporation., Bluetooth LAN Access Server Driver) 0x94E1F000 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI10.sys 118784 bytes (Symantec Corporation, Symantec Eraser Utility Driver) 0xA38C4000 C:\WINDOWS\system32\drivers\emupia2k.sys 110592 bytes (Creative Technology Ltd, E-mu Plug-in Architecture Driver (WDM)) 0xBA715000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xF74C0000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0x98554000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xBA7E9000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xB4DEA000 C:\WINDOWS\System32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x961D2000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0x94CB8000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110422.003\NAVENG.SYS 81920 bytes (Symantec Corporation, AV Engine) 0xB4F77000 C:\WINDOWS\System32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xB5189000 C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0x9F507000 C:\WINDOWS\System32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xF7437000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xF7597000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xB4DD9000 C:\WINDOWS\System32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0x98FFE000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xBA3EF000 C:\WINDOWS\System32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xF76A7000 C:\WINDOWS\System32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager) 0xF7607000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0xBA40F000 C:\WINDOWS\System32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xA46F7000 C:\WINDOWS\System32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client) 0xF74F7000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xBA3DF000 C:\WINDOWS\System32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0x98A2D000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xBA6C5000 C:\WINDOWS\System32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xF7617000 C:\WINDOWS\System32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0x9FE6D000 C:\WINDOWS\system32\DRIVERS\btwhid.sys 53248 bytes (Broadcom Corporation., Bluetooth Virtual HID Minidriver) 0xF7657000 C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xBA705000 C:\WINDOWS\System32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xBA3CF000 C:\WINDOWS\System32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xF7637000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xBA3AF000 C:\WINDOWS\System32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xF7677000 agp440.sys 45056 bytes (Microsoft Corporation, 440 NT AGP Filter) 0xA36C5000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xBA3FF000 C:\WINDOWS\System32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xF7627000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xBA38F000 C:\WINDOWS\system32\DRIVERS\NetDirect.sys 45056 bytes (The OpenVPN Project, TAP-Win32 Virtual Network Driver) 0xBA3BF000 C:\WINDOWS\System32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xF7587000 C:\WINDOWS\system32\drivers\NAV\1205000.07D\SRTSPX.SYS 45056 bytes (Symantec Corporation, Symantec AutoProtect) 0xA46E7000 C:\WINDOWS\System32\Drivers\btwusb.sys 40960 bytes (Broadcom Corporation., Driver for Bluetooth USB Devices) 0xF75F7000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xB9EAD000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xF7667000 PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0xA085D000 C:\WINDOWS\System32\DRIVERS\secdrv.sys 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0xBA37F000 C:\WINDOWS\System32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xF7647000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xF7547000 C:\WINDOWS\System32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xF7507000 C:\WINDOWS\System32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xBA39F000 C:\WINDOWS\System32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xA46D7000 C:\WINDOWS\System32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0x98A7D000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xA4707000 C:\WINDOWS\System32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xB559B000 C:\WINDOWS\system32\drivers\ASAPIW2k.sys 32768 bytes (Pinnacle Systems GmbH, ASAPI) 0xB556B000 C:\WINDOWS\system32\DRIVERS\btport.sys 32768 bytes (Broadcom Corporation., Bluetooth BTPORT Driver for Windows 2000) 0xF7767000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver) 0xA0550000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xF7757000 C:\WINDOWS\System32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xF7777000 C:\WINDOWS\System32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xF7807000 C:\WINDOWS\System32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xA18F6000 C:\WINDOWS\system32\drivers\npf.sys 28672 bytes (CACE Technologies, Inc., npf.sys (NT5/6 x86) Kernel Driver) 0xF7707000 C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xA0568000 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 28672 bytes (Microsoft Corporation, USB Mass Storage Class Driver) 0xB5593000 C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter) 0xF776F000 C:\WINDOWS\System32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xB5573000 C:\WINDOWS\System32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xF774F000 C:\WINDOWS\System32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xA0560000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xF77BF000 C:\WINDOWS\System32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xA0558000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xF770F000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xB5583000 C:\WINDOWS\System32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xB557B000 C:\WINDOWS\System32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xB558B000 C:\WINDOWS\System32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0x99148000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xA0711000 C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xF7947000 C:\WINDOWS\system32\drivers\MODEMCSA.sys 16384 bytes (Microsoft Corporation, Unimodem CSA Filter) 0xBA261000 C:\WINDOWS\System32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xBA615000 C:\WINDOWS\System32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0x96173000 C:\WINDOWS\System32\PfModNT.sys 16384 bytes (Creative Technology Ltd., PCI/ISA Device Info. Service) 0xB94D3000 C:\WINDOWS\System32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xF789B000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0x98592000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xB94EB000 C:\WINDOWS\System32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0x8A2B7000 C:\WINDOWS\system32\KDCOM.DLL 12288 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xA3B6D000 C:\WINDOWS\System32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xBA609000 C:\WINDOWS\System32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xB94CF000 C:\WINDOWS\system32\drivers\pfc.sys 12288 bytes (Padus, Inc., Padus® ASPI Shell) 0xB94E3000 C:\WINDOWS\System32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xA0719000 C:\WINDOWS\System32\drivers\ws2ifsl.sys 12288 bytes (Microsoft Corporation, Winsock2 IFS Layer) 0xF79A1000 C:\WINDOWS\system32\drivers\aeaudio.sys 8192 bytes (Andrea Electronics Corporation, Andrea Audio Stub Driver) 0xF79E7000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xF799D000 C:\WINDOWS\system32\drivers\ctprxy2k.sys 8192 bytes (Creative Technology Ltd, Creative Proxy Device Driver (WDM)) 0x9A511000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xF79E5000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xF79E9000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0x98C3B000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xF79F9000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xF79A3000 C:\WINDOWS\system32\DRIVERS\serscan.sys 8192 bytes (Microsoft Corporation, Serial Imaging Device Driver) 0xF79A5000 C:\WINDOWS\System32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xF79B1000 C:\WINDOWS\System32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xF7987000 C:\WINDOWS\System32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xBA238000 C:\WINDOWS\System32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0x9856D000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xF7A83000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xF7A4F000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) !!!!!!!!!!!Hidden driver: 0x8A31233B ?_empty_? 3269 bytes ============================================== >Stealth ============================================== 0xF74C0000 WARNING: suspicious driver modification [atapi.sys::0x8A31233B] 0x059F0000 Hidden Image–>Intuit.Spc.Map.WindowsFirewallUtilities.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 1077248 bytes 0x05B60000 Hidden Image–>System.ServiceProcess.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 126976 bytes 0x036C0000 Hidden Image–>System.XML.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 2060288 bytes 0x04A90000 Hidden Image–>System.EnterpriseServices.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 266240 bytes 0x047E0000 Hidden Image–>System.Transactions.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 270336 bytes 0x05D50000 Hidden Image–>log4net.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 282624 bytes 0x04470000 Hidden Image–>System.Data.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 2961408 bytes 0x05010000 Hidden Image–>System.Runtime.Remoting.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 307200 bytes 0x038F0000 Hidden Image–>System.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 3190784 bytes 0x06780000 Hidden Image–>Intuit.Spc.Map.WindowsFirewallUtilities.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 421888 bytes 0x03640000 Hidden Image–>System.configuration.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 438272 bytes 0x013D0000 Hidden Image–>Intuit.Spc.Foundations.Portability.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 471040 bytes 0x048D0000 Hidden Image–>Intuit.Spc.Map.Reporter.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 479232 bytes 0x063A0000 Hidden Image–>Intuit.Spc.Map.Reporter.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 479232 bytes 0x05270000 Hidden Image–>System.Windows.Forms.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 5033984 bytes 0x01340000 Hidden Image–>Intuit.Spc.Foundations.Primary.Logging.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 53248 bytes 0x05840000 Hidden Image–>System.Drawing.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 634880 bytes 0x035E0000 Hidden Image–>Intuit.Spc.Foundations.Primary.ExceptionHandling.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 77824 bytes 0x043B0000 Hidden Image–>System.Data.SQLite.DLL [ EPROCESS 0x87C2C590 ] PID: 1700, 778240 bytes 0x03620000 Hidden Image–>Intuit.Spc.Foundations.Primary.Config.dll [ EPROCESS 0x87C2C590 ] PID: 1700, 86016 bytes 0x06200000 Hidden Image–>System.Data.SQLite.DLL [ EPROCESS 0x87C2C590 ] PID: 1700, 872448 bytes
Hi RBG,

Finally found that bad boy!

  • I need you to restart your computer, then use your arrow keys to select Microsoft Windows Recovery Console when prompted. Hit enter.

    [external image: Posted Image]
  • When Recovery Console starts, it will prompt you to enter a number corresponding to the Windows XP installation that you need to repair. In most cases, you'll enter "1" (which will be the only choice). If you press ENTER without typing a number, Recovery Console will quit and restart your computer.
  • Enter your Administrator password. If there is no password, simply press Enter.
  • At the Recovery Console command prompt, type fixmbr and then verify that you want to proceed.
Restart your computer, then run another scan with Rootkit Unhooker. Post its results.
Here's the new log: RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #2 ============================================== >Drivers ============================================== 0xB9146000 C:\WINDOWS\System32\DRIVERS\ati2mtag.sys 3891200 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver) 0xBF1CD000 C:\WINDOWS\System32\ati3duag.dll 3821568 bytes (ATI Technologies Inc. , ati3duag.dll) 0xBF572000 C:\WINDOWS\System32\ativvaxx.dll 2670592 bytes (ATI Technologies Inc. , Radeon Video Acceleration Universal Driver) 0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2265088 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2265088 bytes 0x804D7000 RAW 2265088 bytes 0x804D7000 WMIxWDM 2265088 bytes 0xBF800000 Win32k 1859584 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1859584 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xA7FDC000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110422.003\NAVEX15.SYS 1388544 bytes (Symantec Corporation, AV Engine) 0xB8DAA000 C:\WINDOWS\system32\DRIVERS\btkrnl.sys 987136 bytes (Broadcom Corporation., Bluetooth Bus Enumerator) 0xB8F58000 C:\WINDOWS\System32\DRIVERS\BCMDM.sys 872448 bytes (BCM, Modem Device Driver) 0xA7B4D000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110419.001\BHDrvx86.sys 819200 bytes (Symantec Corporation, BASH Driver) 0xA8BAF000 C:\WINDOWS\system32\drivers\ha10kx2k.sys 770048 bytes (Creative Technology Ltd, Creative EMU10KX HAL (WDM)) 0xF7B3B000 SYMEFA.SYS 671744 bytes 0xBF065000 C:\WINDOWS\System32\ati2cqag.dll 626688 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module) 0xBA75C000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xB8E9B000 C:\WINDOWS\system32\drivers\smwdm.sys 544768 bytes (Analog Devices, Inc., SoundMAX Integrated Digital Audio ) 0xA8240000 C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SRTSP.SYS 544768 bytes (Symantec Corporation, Symantec AutoProtect) 0xBF0FE000 C:\WINDOWS\System32\atikvmag.dll 540672 bytes (ATI Technologies Inc., Virtual Command And Memory Manager) 0xA812F000 C:\WINDOWS\system32\drivers\btaudio.sys 528384 bytes (Broadcom Corporation., Bluetooth Audio Device) 0xA7C90000 C:\WINDOWS\System32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xB909F000 C:\WINDOWS\system32\drivers\ctaud2k.sys 454656 bytes (Creative Technology Ltd, Creative WDM Audio Device Driver) 0xA7C32000 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 385024 bytes (Symantec Corporation, Symantec Eraser Control Driver) 0xB8D24000 C:\WINDOWS\System32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xA7EBD000 C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SYMTDI.SYS 364544 bytes (Symantec Corporation, Network Dispatch Driver) 0xA7F3C000 C:\WINDOWS\System32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xA7E15000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110421.001\IDSxpx86.sys 360448 bytes (Symantec Corporation, IDS Core Driver) 0xA5075000 C:\WINDOWS\System32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver) 0xF7449000 SYMDS.SYS 356352 bytes 0xBF012000 C:\WINDOWS\System32\ati2dvag.dll 339968 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver) 0xBF182000 C:\WINDOWS\System32\atiok3x2.dll 307200 bytes (ATI Technologies Inc., Ring 0 x2 component) 0xBF9C6000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xA4788000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xF75A8000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xA54A8000 C:\WINDOWS\System32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xBA72F000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xB902D000 C:\WINDOWS\system32\drivers\ctoss2k.sys 176128 bytes (Creative Technology Ltd., Creative OS Services Driver (WDM)) 0xA7D00000 C:\WINDOWS\System32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xA7DED000 C:\WINDOWS\System32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xA7F16000 C:\WINDOWS\System32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xA81F6000 C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 155648 bytes (Symantec Corporation, Symantec Event Library) 0xB8F34000 C:\WINDOWS\System32\DRIVERS\e100b325.sys 147456 bytes (Intel Corporation, Intel® PRO/100 Adapter NDIS 5.1 driver) 0xA441C000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xA821C000 C:\WINDOWS\system32\drivers\NAV\1205000.07D\Ironx86.SYS 147456 bytes (Symantec Corporation, Iron Driver) 0xB907B000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xB910E000 C:\WINDOWS\System32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xB9058000 C:\WINDOWS\system32\drivers\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xA7DCB000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x80700000 ACPI_HAL 134400 bytes 0x80700000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xA8B8F000 C:\WINDOWS\system32\drivers\ctac32k.sys 131072 bytes (Creative Technology Ltd, Creative AC3 SW Decoder Device Driver (WDM)) 0xF74A0000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xA8B35000 C:\WINDOWS\system32\drivers\hap16v2k.sys 131072 bytes (Creative Technology Ltd, Creative EMU10KX-P16v HAL (WDM)) 0xA8B55000 C:\WINDOWS\system32\drivers\ctsfm2k.sys 126976 bytes (Creative Technology Ltd, SoundFont® Manager (WDM)) 0xF74D8000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xA81B0000 C:\WINDOWS\system32\DRIVERS\btwdndis.sys 122880 bytes (Broadcom Corporation., Bluetooth LAN Access Server Driver) 0xA7C15000 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 118784 bytes (Symantec Corporation, Symantec Eraser Utility Driver) 0xA8B74000 C:\WINDOWS\system32\drivers\emupia2k.sys 110592 bytes (Creative Technology Ltd, E-mu Plug-in Architecture Driver (WDM)) 0xBA715000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xF74C0000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xA7B0D000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xBA7E9000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xB8D93000 C:\WINDOWS\System32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xA52B3000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xA7FC8000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110422.003\NAVENG.SYS 81920 bytes (Symantec Corporation, AV Engine) 0xB8F20000 C:\WINDOWS\System32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xB9132000 C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xA7F95000 C:\WINDOWS\System32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xF7437000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xF7597000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xB8D82000 C:\WINDOWS\System32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xBA2EC000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xB9E70000 C:\WINDOWS\System32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xF76A7000 C:\WINDOWS\System32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager) 0xF7607000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0xB9E90000 C:\WINDOWS\System32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xF76B7000 C:\WINDOWS\System32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client) 0xB9EB0000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xB9E60000 C:\WINDOWS\System32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xA558D000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xF7517000 C:\WINDOWS\System32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xF7617000 C:\WINDOWS\System32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0xBA6B5000 C:\WINDOWS\system32\DRIVERS\btwhid.sys 53248 bytes (Broadcom Corporation., Bluetooth Virtual HID Minidriver) 0xF7657000 C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xB9EA0000 C:\WINDOWS\System32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xF76C7000 C:\WINDOWS\System32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xF7637000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xF76E7000 C:\WINDOWS\System32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xF7677000 agp440.sys 45056 bytes (Microsoft Corporation, 440 NT AGP Filter) 0xBA34C000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xB9E80000 C:\WINDOWS\System32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xF7627000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xF7587000 C:\WINDOWS\system32\DRIVERS\NetDirect.sys 45056 bytes (The OpenVPN Project, TAP-Win32 Virtual Network Driver) 0xF76D7000 C:\WINDOWS\System32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xBA6F5000 C:\WINDOWS\system32\drivers\NAV\1205000.07D\SRTSPX.SYS 45056 bytes (Symantec Corporation, Symantec AutoProtect) 0xBA6E5000 C:\WINDOWS\System32\Drivers\btwusb.sys 40960 bytes (Broadcom Corporation., Driver for Bluetooth USB Devices) 0xF75F7000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xF7567000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xF7667000 PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0xA5015000 C:\WINDOWS\System32\DRIVERS\secdrv.sys 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0xF7577000 C:\WINDOWS\System32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xF7647000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xBA705000 C:\WINDOWS\System32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xB9EC0000 C:\WINDOWS\System32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xF76F7000 C:\WINDOWS\System32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xBA36C000 C:\WINDOWS\System32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xA4550000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xBA675000 C:\WINDOWS\System32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xF77FF000 C:\WINDOWS\system32\drivers\ASAPIW2k.sys 32768 bytes (Pinnacle Systems GmbH, ASAPI) 0xF774F000 C:\WINDOWS\system32\DRIVERS\btport.sys 32768 bytes (Broadcom Corporation., Bluetooth BTPORT Driver for Windows 2000) 0xF77E7000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver) 0xF776F000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xF77DF000 C:\WINDOWS\System32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xF77F7000 C:\WINDOWS\System32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xB9AC8000 C:\WINDOWS\System32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xF77AF000 C:\WINDOWS\system32\drivers\npf.sys 28672 bytes (CACE Technologies, Inc., npf.sys (NT5/6 x86) Kernel Driver) 0xF7707000 C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xB9AB8000 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 28672 bytes (Microsoft Corporation, USB Mass Storage Class Driver) 0xF7807000 C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter) 0xF77EF000 C:\WINDOWS\System32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xF771F000 C:\WINDOWS\System32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xF77D7000 C:\WINDOWS\System32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xB9A80000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xF7757000 C:\WINDOWS\System32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xF7767000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xF770F000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xF7817000 C:\WINDOWS\System32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xF781F000 C:\WINDOWS\System32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xF780F000 C:\WINDOWS\System32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xF77CF000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xBA619000 C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xB9518000 C:\WINDOWS\system32\drivers\MODEMCSA.sys 16384 bytes (Microsoft Corporation, Unimodem CSA Filter) 0xBA641000 C:\WINDOWS\System32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xA57B9000 C:\WINDOWS\System32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xA50E5000 C:\WINDOWS\System32\PfModNT.sys 16384 bytes (Creative Technology Ltd., PCI/ISA Device Info. Service) 0xF7943000 C:\WINDOWS\System32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xF7897000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xA7B3D000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xB9508000 C:\WINDOWS\System32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xB94FC000 C:\WINDOWS\System32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xBA64D000 C:\WINDOWS\System32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xF7947000 C:\WINDOWS\system32\drivers\pfc.sys 12288 bytes (Padus, Inc., Padus® ASPI Shell) 0xBA226000 C:\WINDOWS\System32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xBA20E000 C:\WINDOWS\System32\drivers\ws2ifsl.sys 12288 bytes (Microsoft Corporation, Winsock2 IFS Layer) 0xF7A05000 C:\WINDOWS\system32\drivers\aeaudio.sys 8192 bytes (Andrea Electronics Corporation, Andrea Audio Stub Driver) 0xF79AB000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xF7A03000 C:\WINDOWS\system32\drivers\ctprxy2k.sys 8192 bytes (Creative Technology Ltd, Creative Proxy Device Driver (WDM)) 0xF7997000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xF79A9000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xF7987000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xF79AD000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xF79D5000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xF79AF000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xF7A07000 C:\WINDOWS\system32\DRIVERS\serscan.sys 8192 bytes (Microsoft Corporation, Serial Imaging Device Driver) 0xF7A09000 C:\WINDOWS\System32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xF798B000 C:\WINDOWS\System32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xF7989000 C:\WINDOWS\System32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xF7A85000 C:\WINDOWS\System32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xBA2CB000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xB9F5A000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xF7A4F000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ============================================== 0x05610000 Hidden Image–>Intuit.Spc.Map.WindowsFirewallUtilities.dll [ EPROCESS 0x87813788 ] PID: 1344, 1077248 bytes 0x05780000 Hidden Image–>System.ServiceProcess.dll [ EPROCESS 0x87813788 ] PID: 1344, 126976 bytes 0x032E0000 Hidden Image–>System.XML.dll [ EPROCESS 0x87813788 ] PID: 1344, 2060288 bytes 0x046A0000 Hidden Image–>System.EnterpriseServices.dll [ EPROCESS 0x87813788 ] PID: 1344, 266240 bytes 0x043F0000 Hidden Image–>System.Transactions.dll [ EPROCESS 0x87813788 ] PID: 1344, 270336 bytes 0x05970000 Hidden Image–>log4net.dll [ EPROCESS 0x87813788 ] PID: 1344, 282624 bytes 0x04080000 Hidden Image–>System.Data.dll [ EPROCESS 0x87813788 ] PID: 1344, 2961408 bytes 0x04C30000 Hidden Image–>System.Runtime.Remoting.dll [ EPROCESS 0x87813788 ] PID: 1344, 307200 bytes 0x03500000 Hidden Image–>System.dll [ EPROCESS 0x87813788 ] PID: 1344, 3190784 bytes 0x063A0000 Hidden Image–>Intuit.Spc.Map.WindowsFirewallUtilities.dll [ EPROCESS 0x87813788 ] PID: 1344, 421888 bytes 0x03270000 Hidden Image–>System.configuration.dll [ EPROCESS 0x87813788 ] PID: 1344, 438272 bytes 0x03070000 Hidden Image–>Intuit.Spc.Foundations.Portability.dll [ EPROCESS 0x87813788 ] PID: 1344, 471040 bytes 0x04500000 Hidden Image–>Intuit.Spc.Map.Reporter.dll [ EPROCESS 0x87813788 ] PID: 1344, 479232 bytes 0x05FC0000 Hidden Image–>Intuit.Spc.Map.Reporter.dll [ EPROCESS 0x87813788 ] PID: 1344, 479232 bytes 0x04E90000 Hidden Image–>System.Windows.Forms.dll [ EPROCESS 0x87813788 ] PID: 1344, 5033984 bytes 0x00F60000 Hidden Image–>Intuit.Spc.Foundations.Primary.Logging.dll [ EPROCESS 0x87813788 ] PID: 1344, 53248 bytes 0x05460000 Hidden Image–>System.Drawing.dll [ EPROCESS 0x87813788 ] PID: 1344, 634880 bytes 0x03210000 Hidden Image–>Intuit.Spc.Foundations.Primary.ExceptionHandling.dll [ EPROCESS 0x87813788 ] PID: 1344, 77824 bytes 0x03FC0000 Hidden Image–>System.Data.SQLite.DLL [ EPROCESS 0x87813788 ] PID: 1344, 778240 bytes 0x03250000 Hidden Image–>Intuit.Spc.Foundations.Primary.Config.dll [ EPROCESS 0x87813788 ] PID: 1344, 86016 bytes 0x05E40000 Hidden Image–>System.Data.SQLite.DLL [ EPROCESS 0x87813788 ] PID: 1344, 872448 bytes
I'm searching on Google and there are no warnings or popups. You are a lifesaver! Thank you so much. So, I have a couple more questions. First, I and my family generally practice safe computing (as safe as we can). Any ideas what this virus was or where it came from or what its endgame was? We have gone through and changed passwords (using a different machine) on all of our online accounts, because I'm assuming that kind of tracking was going on. Also, I've seen where we can donate. Is there a standard amount? Does it benefit you directly, or the site as a whole? Again, thank you for your help.
Hi RBG, no problem! Sorry it took some time to find out what was actually causing those problems.

This rootkit was some form of the TDL4 rootkit. It's hard to say where the rootkit came from, but today's malware can strike even the safest and most savvy computer users. You probably already know this, but you can prevent being infected by keeping Windows and your antivirus software up to date. Also take caution when browsing the web or opening email attachments. Good call on changing your passwords; that is standard procedure after being infected by a rootkit or backdoor trojan.

If you haven't already done so, proceed with the cleanup process for ComboFix, update Java, and update Adobe Reader. I also need you to delete GMER, aswMBR, Rootkit Unhooker, and MBRCheck from your desktop.

Finally, to answer your question regarding donations, the donate link in my signature will go directly to me. If you would like to help the site out, you can use the donate link here.

Any further questions or outstanding issues?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI