This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

here is my log, please help

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi again…. I was waiting for your instructions and did not get a reply topic notice until just now, i apologize….. so, i just did what you said and the combofix runs and gets to the point where it says it will close and return in no more than 10 seconds, it says "surfsidekick found!", but never returns….just closes…so i cant even get a logfile on that…..i did it twice with same results…. also, for about a week there things were running pretty good, but now pictures will load very slowly again and a couple of programs take about a minute to open…… any ideas…?
Download Brute Force Uninstaller to your desktop.
  • Right click the file on your Desktop, and choose Extract All.
  • Click Next.
  • In the box to choose where to extract the files to:
  • Click Browse.
  • Click on the + sign next to My Computer
  • Click on Local Disk (C:) or whatever your primary drive is.
  • Click Make New Folder
  • Type in BFU
  • Click Next, and uncheck the Show Extracted Files box and then click Finish.
Download sidekickFix.bat (rightclick on that link and choose save as)
  • Place sidekickFix.bat in your C:\BFU - folder. (Important!)
  • Close all browsers and explorer folders.
  • Double-click on sidekickFix.bat
  • Click Yes and follow the prompts, when prompted to restart the PC please do so.
On your next reply, please post a fresh HijackThis log and please tell us how your machine is running.
ok, did all that and here it is but still not running right, a couple programs and all pictures take extremely long to load…..also i noticed last line on my log says america online, which i dont even use or have so can that be deleted?


Logfile of HijackThis v1.99.1
Scan saved at 13:27, on 06-12-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\hijack this\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sports.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04e\BrStDvPt.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB003" /M "Stylus CX4800"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /M "Stylus CX4800" /EF "HKCU"
O4 - Global Startup: Media Card Companion Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O8 - Extra context menu item: Open with &ZipScan - C:\PROGRA~1\ZIPSCA~1\zs_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

also i noticed last line on my log says america online, which i dont even use or have so can that be deleted?


Isn't AOL your ISP? If so, deleting that file could hinder you from connecting to the internet again.

Run Panda Active Scan
  • Once you are on the Panda site click the Scan Your PC button.
  • A new window will open…click the Check Now button.
  • Enter your Country.
  • Enter your State/Province.
  • Enter your E-mail Address and click Send.
  • Select either Home User or Company.
  • Click the big Scan Now button.
  • If it wants to install an ActiveX component allow it.
  • It will start downloading the files it requires for the scan. (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan.
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
__________________________________-

Download Gmer from here:
http://www.gmer.net/gmer.zip
  • Disconnect from internet and close running programs.
  • There is a small chance this application may crash your computer so save any work you have open.
  • Double click gmer.exe
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say Ok.
  • If no warning….
  • Click "Rootkit" tab and click "Scan"
  • Once donem click "Copy"
  • Open Notepad and hit "ctrl+v" to paste the log.
  • Reconnect to the internet and post the log back to this thread please.
___________________________________

Download, unzip and run 'RootkitRevealer' from Sysinternals:
http://www.sysinternals.com/Utilities/RootkitRevealer.html

Once the program has started, press Scan and let it run.
When the scan is done, use 'File' > 'Save' to place the logfile in a convenient location (such as the desktop). The default file name will be 'RootkitReveal.txt'.

Save your Log File.
Copy/Paste the contents of that logfile into your next reply.

DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc. !

On your next reply, please post a fresh HijackThis log, Panda ActiveScan log, RootkitRevealer log and the Gmer log.
ok, here we go…..

hijack log…

Logfile of HijackThis v1.99.1
Scan saved at 23:51, on 06-12-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\hijack this\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sports.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04e\BrStDvPt.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB003" /M "Stylus CX4800"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /M "Stylus CX4800" /EF "HKCU"
O4 - Global Startup: Media Card Companion Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O8 - Extra context menu item: Open with &ZipScan - C:\PROGRA~1\ZIPSCA~1\zs_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

———————————————————————————————————————–

panda activescan log….

Incident Status Location

Adware:adware program Not disinfected c:\windows\system32\data.~
Spyware:spyware/iehelp Not disinfected c:\windows\downloaded program files\ipreg32.inf
Adware:adware/topconvert Not disinfected c:\windows\downloaded program files\loader2.ocx
Adware:adware/elitebar Not disinfected c:\windows\downloaded program files\OSD149F.OSD
Adware:adware/sbsoft Not disinfected c:\windows\downloaded program files\webdlg32.inf
Adware:adware/statblaster Not disinfected c:\windows\downloaded program files\WildApp.inf
Adware:adware/ist.yoursitebar Not disinfected c:\windows\downloaded program files\ysbactivex.inf
Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Ssk.log
Adware:adware/bravesentry Not disinfected c:\windows\desktop.html
Spyware:spyware/adclicker Not disinfected c:\windows\usta32.ini
Adware:adware/powerscan Not disinfected Windows Registry
Adware:adware/cws Not disinfected Windows Registry
Adware:adware/ncase Not disinfected Windows Registry
Adware:adware/ist.sidefind Not disinfected Windows Registry
Adware:adware/toolbarsimbar Not disinfected Windows Registry
Dialer:dialer.ok Not disinfected HKEY_CLASSES_ROOT\Interface\{66BD1BD0-3655-42E4-8CE9-16D3613B0B25}
Adware:adware/dyfuca Not disinfected Windows Registry
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Owner\Cookies\owner@apmebf[1].txt
Potentially unwanted tool:Application/HideWindow.A Not disinfected C:\hp\bin\FondleWindow.exe
Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
Potentially unwanted tool:Application/KillApp.A Not disinfected C:\hp\bin\Terminator.exe
Possible Virus. Not disinfected C:\sUBs\TSF\swreg.exe
Adware:Adware/EliteBar Not disinfected C:\WINDOWS\blocklist.reg
Adware:Adware/SBSoft Not disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\webdlg32.inf
Adware:Adware/SBSoft Not disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.2\webdlg32.inf
Adware:Adware/SBSoft Not disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.3\webdlg32.inf
Adware:Adware/SBSoft Not disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.4\webdlg32.inf
Adware:Adware/SBSoft Not disinfected C:\WINDOWS\webdlg32.inf
Adware:Adware/Popup.pop Not disinfected C:\WINDOWS\winsx.inf


———————————————————————————————————————–

rootkit log…..

HKLM\SECURITY\Policy\Secrets\SAC* 03-08-23 01:06 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 03-08-23 01:06 0 bytes Key name contains embedded nulls (*)
HKLM\SYSTEM\ControlSet001\Control\Motorola\PST\USBDriverVersionNumber 05-10-11 14:01 3 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet002\Control\Motorola\PST\USBDriverVersionNumber 05-10-11 14:01 3 bytes Data mismatch between Windows API and raw hive data.
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb 06-12-01 23:38 64.00 KB Hidden from Windows API.
D: 0 bytes Error mounting volume

———————————————————————————————————————–


GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2006-12-01 23:26:38
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT a347bus.sys ZwClose
SSDT a347bus.sys ZwCreateKey
SSDT a347bus.sys ZwCreatePagingFile
SSDT a347bus.sys ZwEnumerateKey
SSDT a347bus.sys ZwEnumerateValueKey
SSDT a347bus.sys ZwOpenFile
SSDT a347bus.sys ZwOpenKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT a347bus.sys ZwQueryKey
SSDT a347bus.sys ZwQueryValueKey
SSDT a347bus.sys ZwSetSystemPowerState
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

—- Devices - GMER 1.0.12 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82A89960
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 829A5198
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 829AAD20
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 829AAD20
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 827EF738
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 829AAD20
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 829AAD20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_NAMED_PIPE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_READ 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_WRITE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FLUSH_BUFFERS 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DIRECTORY_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FILE_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SHUTDOWN 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_LOCK_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLEANUP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_MAILSLOT 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CHANGE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE_NAMED_PIPE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLOSE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_READ 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_WRITE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_FLUSH_BUFFERS 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DIRECTORY_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_FILE_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_INTERNAL_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SHUTDOWN 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_LOCK_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLEANUP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE_MAILSLOT 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_POWER 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CHANGE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_PNP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE_NAMED_PIPE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CLOSE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_READ 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_WRITE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_FLUSH_BUFFERS 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DIRECTORY_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_FILE_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_INTERNAL_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SHUTDOWN 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_LOCK_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CLEANUP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE_MAILSLOT 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_POWER 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DEVICE_CHANGE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_PNP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_CREATE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_CREATE_NAMED_PIPE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_CLOSE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_READ 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_WRITE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_QUERY_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SET_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_QUERY_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SET_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_FLUSH_BUFFERS 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_QUERY_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SET_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_DIRECTORY_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_FILE_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_INTERNAL_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SHUTDOWN 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_LOCK_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_CLEANUP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_CREATE_MAILSLOT 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_QUERY_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SET_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_POWER 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_DEVICE_CHANGE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_QUERY_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SET_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_PNP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_CREATE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_CREATE_NAMED_PIPE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_CLOSE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_READ 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_WRITE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_QUERY_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SET_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_QUERY_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SET_EA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_FLUSH_BUFFERS 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_QUERY_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SET_VOLUME_INFORMATION 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_DIRECTORY_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_FILE_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_INTERNAL_DEVICE_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SHUTDOWN 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_LOCK_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_CLEANUP 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_CREATE_MAILSLOT 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_QUERY_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SET_SECURITY 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_POWER 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SYSTEM_CONTROL 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_DEVICE_CHANGE 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_QUERY_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SET_QUOTA 82A8F9C8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_PNP 82A8F9C8
Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 82486FB0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 827E8188
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 827E8188
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 8284EB58
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 827EFC48
Device \FileSystem\Fastfat \Fat IRP_MJ_READ 829A5198
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 827EFE88
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 827EFE88
Device &

dude, this can't be good……..?


The logs are not that bad but we need to see the full Gmer log.

Your Gmer log got cut off.. Please include the full Gmer log in your next post, use separate posts if necessary.

Since AOL is not your ISP, I don't see why it should be there but it is not malware so the uninstall is an optional.

Go to Control Panel > Add or Remove Programs > uninstall the items in bold if found.

AOL
America Online
All entries with AOL in them


Reboot
__________________________________

You may want to print these instructions here or save them in notepad since you'll work offline.

Reboot into Safe Mode.

To enter Safe Mode..

Click Start > Turn Off Computer > Restart > Tap F8 key just before Windows starts to load, > This will bring up a Menu > Use your keyboard to scroll to Safe Mode> Hit enter.


*Configure your machine to view hidden files:

Windows XP
  • Click Start.
  • Open My Computer..
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the "Hidden files and folders" heading select Show hidden files and folders.
  • Uncheck the Hide Protected Operating System Files Option.
  • Click Yes to confirm.
  • Click OK.
*Using Windows Explorer, find and delete these files:

c:\windows\system32\data.~
c:\windows\downloaded program files\ipreg32.inf
c:\windows\downloaded program files\loader2.ocx
c:\windows\downloaded program files\OSD149F.OSD
c:\windows\downloaded program files\webdlg32.inf
c:\windows\downloaded program files\WildApp.inf
c:\windows\downloaded program files\ysbactivex.inf
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Ssk.log
c:\windows\desktop.html
c:\windows\usta32.ini
C:\WINDOWS\blocklist.reg
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\webdlg32.inf
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\webdlg32.inf
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\webdlg32.inf
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\webdlg32.inf
C:\WINDOWS\webdlg32.inf
C:\WINDOWS\winsx.inf

*Delete this folder:

C:\sUBs

Empty your Recycle Bin.

_____________________________________
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


*Please run AVG AntiSpyware again and this time please make sure that you save the logfile and include it in your next post.

Reboot to normal mode after the scan.

______________________________________

Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

IMPORTANT: Do NOT run any other options except for Option # 1.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm

On your next reply, please include a fresh HijackThis log, AVG Antispyware log, smitfraudfix log, full Gmer log and please tell us how's your machine running.
ok im in process now..( i have 2 computers side by side)….anyway, you should know that…. #1 i did post the full gmr log so i dont know what got cut off as im not familiar with that…i will do it again though….and #2..all those files you want me to delete do not exist, i did everything you said and i double checked and they are not there……i will proceed with everything else
ok, here it all is again, but still system not right some programs files and things extremely slow….outlook also….






Scan done at 22:39:39.59, 06-12-02
Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

C:\WINDOWS\desktop.html FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

smitfraudfix log….

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

—————————————————————————————————————————


here is hijack log…………….

Logfile of HijackThis v1.99.1
Scan saved at 22:42, on 06-12-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\hijack this\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sports.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04e\BrStDvPt.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB003" /M "Stylus CX4800"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /M "Stylus CX4800" /EF "HKCU"
O4 - Global Startup: Media Card Companion Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O8 - Extra context menu item: Open with &ZipScan - C:\PROGRA~1\ZIPSCA~1\zs_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


——————————————————————————————————————————



GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2006-12-03 03:46:04
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT a347bus.sys ZwClose
SSDT a347bus.sys ZwCreateKey
SSDT a347bus.sys ZwCreatePagingFile
SSDT a347bus.sys ZwEnumerateKey
SSDT a347bus.sys ZwEnumerateValueKey
SSDT a347bus.sys ZwOpenFile
SSDT a347bus.sys ZwOpenKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT a347bus.sys ZwQueryKey
SSDT a347bus.sys ZwQueryValueKey
SSDT a347bus.sys ZwSetSystemPowerState
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

—- Devices - GMER 1.0.12 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82A3C330
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 827FC5C0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 829A7008
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 829A7008
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 827E6E80
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 829A7008
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 829A7008
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_NAMED_PIPE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_READ 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_WRITE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FLUSH_BUFFERS 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DIRECTORY_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_FILE_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SHUTDOWN 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_LOCK_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLEANUP 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE_MAILSLOT 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CHANGE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_QUERY_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SET_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE_NAMED_PIPE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLOSE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_READ 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_WRITE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_FLUSH_BUFFERS 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DIRECTORY_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_FILE_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_INTERNAL_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SHUTDOWN 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_LOCK_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CLEANUP 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_CREATE_MAILSLOT 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_POWER 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_DEVICE_CHANGE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_QUERY_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_SET_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort2 IRP_MJ_PNP 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE_NAMED_PIPE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CLOSE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_READ 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_WRITE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_FLUSH_BUFFERS 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DIRECTORY_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_FILE_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_INTERNAL_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SHUTDOWN 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_LOCK_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CLEANUP 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_CREATE_MAILSLOT 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_POWER 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_DEVICE_CHANGE 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_QUERY_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_SET_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdePort3 IRP_MJ_PNP 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_CREATE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_CREATE_NAMED_PIPE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_CLOSE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_READ 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_WRITE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_QUERY_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SET_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_QUERY_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SET_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_FLUSH_BUFFERS 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_QUERY_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SET_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_DIRECTORY_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_FILE_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_INTERNAL_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SHUTDOWN 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_LOCK_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_CLEANUP 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_CREATE_MAILSLOT 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_QUERY_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SET_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_POWER 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_DEVICE_CHANGE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_QUERY_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_SET_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-1b IRP_MJ_PNP 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_CREATE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_CREATE_NAMED_PIPE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_CLOSE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_READ 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_WRITE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_QUERY_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SET_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_QUERY_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SET_EA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_FLUSH_BUFFERS 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_QUERY_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SET_VOLUME_INFORMATION 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_DIRECTORY_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_FILE_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_INTERNAL_DEVICE_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SHUTDOWN 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_LOCK_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_CLEANUP 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_CREATE_MAILSLOT 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_QUERY_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SET_SECURITY 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_POWER 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SYSTEM_CONTROL 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_DEVICE_CHANGE 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_QUERY_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_SET_QUOTA 829A7D20
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-13 IRP_MJ_PNP 829A7D20
Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 8262A370
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 827C7230
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 827C7230
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 82803B50
Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 827FD200
Device \FileSystem\Fastfat \Fat IRP_MJ_READ 827FC5C0
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 827EC260
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 827EC260
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_READ 827EC260
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_READ 827EC260
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_READ 827EC260
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 824B1B08

—- Modules - GMER 1.0.12 —-

Module _________ F83E0000

—- Files - GMER 1.0.12 —-

ADS C:\Documents and Settings\Owner\Desktop\SprinklerKing\CIA version 2005.exe:SummaryInformation
ADS C:\Documents and Settings\Owner\Desktop\SprinklerKing\CIA version 2005.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS C:\Program Files\SprinklerKing\CIA version 2005.exe:SummaryInformation
ADS C:\Program Files\SprinklerKing\CIA version 2005.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}

—- EOF - GMER 1.0.12 —-


—————————————————————————————————————————

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 04:01 06-12-03

+ Scan result:



Nothing found.



::Report end
1.) You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

2.) Reboot into Safe Mode.

To enter Safe Mode..

Click Start > Turn Off Computer > Restart > Tap F8 key just before Windows starts to load, > This will bring up a Menu > Use your keyboard to scroll to Safe Mode> Hit enter.

3.) Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".


The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.

_______________________________________________

Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe



I recommend you download RegSeeker. Extract it to it's own folder, open and double click RegSeeker.exe to start the program. Maximize the window and click clean registry. Check all sections and click OK. When the scan is complete, verify the backup box in lower left corner is checked and click the select all button, then select all again. Then right click within the search results and select delete. Run it again and again, deleting everything it finds until it finds nothing. Reboot and make sure your programs are working properly, control panel and add/remove programs windows open, etc (basically just do a quick check of everything). In the event anything was 'broken', you can open RegSeeker, click backups and double click any/all files to put the information back. A reboot may be required for the effects to be seen. Reboot When done.

NOTE: To be extra safe you can choose to only remove the items in RED.

_______________________________________________

Click here to use the F-Secure Online Scanner
It's explained there with images how to allow the ActiveX to start the scan, so read that first.
  • Then click the F-Secure Online Scanner Next Generation Beta link.
  • Once the ActiveX is installed, you should accept the License terms by clicking OK below to start the scan.
  • Click the Full System Scan button.
  • It will start to download scanner components and databases. This can take a while.
  • The main scan will start.
  • Once the scan finished scanning, click the Automatic cleaning (recommended) button
  • It could be possible that your firewall gives an alert - allow it, because that's a connection you establish to submit infected files to F-Secure.
  • The cleaning can take a while, so please be patient.
  • Then click the Show report button and copy and paste what's present under results in your next reply.
________________________________________________

On your next reply please include a fresh HijackThis log, smitfraudfix log and the results of the F-secure online scan.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI