This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Several Logs, RootKit? Oh noes!

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I had a problem with secure32.html, which after searching I have solved. However, In the process of doing so, ComboFix found a possible rootkit and recommends scanning.

Here are my logs:

Logfile of HijackThis v1.99.1
Scan saved at 7:43:37 PM, on 1/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Jordan\LOCALS~1\Temp\Rar$EX00.438\RootkitRevealer.exe
C:\Program Files\Winamp\winamp.exe
C:\Documents and Settings\Jordan\Application Data\Microsoft\Internet Explorer\Quick Launch\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [AutoSys] C:\WINDOWS\system32\autosys.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TYWHQ - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Jordan\LOCALS~1\Temp\TYWHQ.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE




BREAK



"Jordan" - 07-01-23 19:44:06 Service Pack 2
ComboFix 07-01-23.2 - Running from: "C:\Documents and Settings\Jordan\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-12-23 to 2007-01-23 ))))))))))))))))))))))))))))))))))


2007-01-23 16:23 d——– C:\Program Files\SUPERAntiSpyware
2007-01-23 16:23 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-01-23 16:23 d——– C:\DOCUME~1\Jordan\Application Data\SUPERAntiSpyware.com
2007-01-23 16:23 d——– C:\DOCUME~1\ALLUSE~1\Application Data\SUPERAntiSpyware.com
2007-01-23 16:20 d——– C:\VundoFix Backups
2007-01-23 13:20 d——– C:\WINDOWS\Performance
2007-01-23 13:20 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Microsoft Corporation
2007-01-22 20:32 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-01-19 18:03 d——– C:\Program Files\Microsoft Games
2007-01-19 18:00 96,768 –a—— C:\WINDOWS\system32\mqlluwj.dll
2007-01-19 16:27 d–hs—- C:\WINDOWS\ftpcache
2007-01-18 19:47 d——– C:\Program Files\Doyles Room Poker
2007-01-18 19:47 d——– C:\DOCUME~1\Jordan\Application Data\JL514
2007-01-02 20:07 d——– C:\WINDOWS\pss


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

Rootkit driver pe386 is present. A rootkit scan is required

2007-01-23 18:56 ——– d——– C:\Program Files\mozilla firefox
2007-01-23 15:39 ——– d——– C:\Program Files\warcraft iii
2007-01-20 00:03 ——– d——– C:\Program Files\mirc
2007-01-19 18:52 ——– d—s—- C:\DOCUME~1\Jordan\Application Data\microsoft
2007-01-19 18:10 ——– d–h—– C:\Program Files\installshield installation information
2007-01-16 06:58 ——– d——– C:\Program Files\poker tracker v2
2007-01-15 15:39 ——– d——– C:\Program Files\absolute poker
2007-01-15 12:32 689280 –a—— C:\WINDOWS\system32\aswboot.exe
2007-01-15 12:23 90112 –a—— C:\WINDOWS\system32\avastss.scr
2006-12-24 16:15 ——– d——– C:\DOCUME~1\Jordan\Application Data\aim
2006-12-24 12:46 ——– d——– C:\DOCUME~1\Jordan\Application Data\azureus
2006-12-21 07:17 ——– d——– C:\Program Files\ultimatebet
2006-12-21 00:01 ——– d——– C:\Program Files\full tilt poker
2006-12-20 22:57 ——– d——– C:\Program Files\bodog poker
2006-12-20 18:56 94424 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2006-12-20 18:56 85952 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2006-12-20 18:51 31560 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2006-12-17 00:21 ——– d——– C:\Program Files\registry mechanic
2006-12-16 17:25 ——– d——– C:\DOCUME~1\Jordan\Application Data\limewire
2006-12-12 18:35 98304 –a—— C:\WINDOWS\system32cmdlineext.dll
2006-12-09 14:05 ——– d——– C:\Program Files\Common Files\adobe
2006-12-09 14:05 ——– d——– C:\DOCUME~1\Jordan\Application Data\adobeum
2006-12-04 22:19 ——– d—s—- C:\Program Files\xfire
2006-12-04 21:43 ——– d——– C:\DOCUME~1\Jordan\Application Data\xfire
2006-12-04 19:07 ——– d——– C:\Program Files\smartftp client 2.0 setup files
2006-12-04 19:07 ——– d——– C:\Program Files\smartftp client 2.0
2006-12-03 22:56 ——– d——– C:\Program Files\musicmatch
2006-12-03 13:51 ——– d——– C:\Program Files\mansion
2006-11-24 00:16 ——– d——– C:\Program Files\Common Files\casinovegasshared
2006-11-08 00:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"RoboForm"="\"C:\\Program Files\\Siber Systems\\AI RoboForm\\RoboTaskBarIcon.exe\""
"SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"Broadcom Wireless Manager UI"="C:\\WINDOWS\\system32\\WLTRAY.exe"
"RegistryMechanic"=""
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"SigmatelSysTrayApp"="stsystra.exe"
"AutoSys"="C:\\WINDOWS\\system32\\autosys.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
"Flags"=dword:00000080
"Title"="UnHackMe Rootkit Check"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
QWAVE REG_MULTI_SZ QWAVE\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
Shell\AutoRun\command D:\autoplay.exe

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H]
Shell\AutoRun\command H:\OblivionLauncher.exe

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
Shell\AutoRun\command E:\setup.exe

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{747d6679-e522-11da-992f-806d6172696f}]
Shell\AutoRun\command D:\autoplay.exe
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_RKREVEAL150
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_TYWHQ


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

Completion time: 07-01-23 19:45:11


What do I do next? Microsoft malicious tool says im clean, SuperAntispyware, spybot, and ad-aware have been run and fixed all problems.

Thanks in advance,

Jordan
Hello JL514 and Welcome to TomCoyote,

Please do the following;

Please set your system to show all files; please see here if you're unsure how to do this.

Scan with HijackThis. Place a check against each of the following:
O4 - HKLM\..\Run: [AutoSys] C:\WINDOWS\system32\autosys.exe
Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\WINDOWS\system32\autosys.exe<=file
Exit Explorer, and reboot as normal afterwards.

Download
GMER and extract it to the C:\program files\GMER folder
http://www.gmer.net/gmer.zip
  • Disconnect from internet and close running programs.
  • There is a small chance this app may crash your computer so save any work you have open.
  • Double click gmer.exe
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say Ok.
  • If no warning….
  • Click "rootkit" tab and click "scan"
  • Once done click "copy"
  • Open Notepad and hit "ctrl+v" to paste log.
  • Reconnect to internet and post log please.
Download
http://www.uploads.ejvindh.net/rustbfix.exe
…and save it to your desktop.

Double click on rustbfix.exe to run the tool. If a Rustock.b-infection is found, you will shortly hereafter be asked to reboot the computer. The reboot will probably take quite a while, and perhaps 2 reboots will be needed. But this will happen automatically. After the reboot 2 logfiles will open (%root%\avenger.txt & %root%\rustbfix\pelog.txt). Post the content of these logfiles along with a new HijackThis log.
GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-23 20:52:11
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey

—- Kernel code sections - GMER 1.0.12 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2E51 80503B35 3 Bytes [ CF, ED, B9 ]

—- Devices - GMER 1.0.12 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 89E4FA40
Device \Driver\00000057 \Device\00000050 IRP_MJ_POWER [B9EE3EA8] sptd.sys
Device \Driver\00000057 \Device\00000050 IRP_MJ_SYSTEM_CONTROL [B9EF7A70] sptd.sys
Device \Driver\00000057 \Device\00000050 IRP_MJ_PNP [B9EF0728] sptd.sys
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 89E4F0E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 89E02550
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 89C06C60
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 89C06C60
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 89C06C60
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 89C06C60
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 89C06C60
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 89C06C60
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C06C60
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 89C06C60
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 89C06C60
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 89C06C60
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 89C06C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSE 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 89A6CC60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 89A6CC60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 89C06C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 89C06C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 89C06C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 89C06C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 89C06C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 89C06C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C06C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 89C06C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 89C06C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 89C06C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 89C06C60
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 89E02550
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 89C06C60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 89C06C60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 89C06C60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 89C06C60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 89C06C60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 89C06C60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C06C60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 89C06C60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 89C06C60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 89C06C60
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 89C06C60
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 899750E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 899750E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 899750E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 899750E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 899750E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 899750E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 899750E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 899750E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 899750E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 899750E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 899750E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 899750E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_CREATE 899750E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_CLOSE 899750E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_DEVICE_CONTROL 899750E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_INTERNAL_DEVICE_CONTROL 899750E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_CLEANUP 899750E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_PNP 899750E8
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CLOSE 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_READ 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_WRITE 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_FLUSH_BUFFERS 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_DEVICE_CONTROL 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SHUTDOWN 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_POWER 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SYSTEM_CONTROL 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_PNP 89E4FC78
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 89AC2580
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 89AC2580
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 89A6C2B8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 89A6C2B8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSE 89A6C2B8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 89A6C2B8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 89A6C2B8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 89A6C2B8
Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION
************************* Rustock.b-fix – By ejvindh ************************* Tue 01/23/2007 20:53:06.56 No Rustock.b-rootkits found ******************************* End of Logfile ********************************
Looks like GMER got cut off - I like to see the whole thing please. You did not post a hijackthis log. I am glad the rootkit is gone. :)
Argh. I don't know that the root kit is gone, I didn't do anything. If the GMER got cut off, it's because of a character limit on posting, I copy/pasted the entire thing. I guess I should run it again?

Logfile of HijackThis v1.99.1
Scan saved at 10:39:26 PM, on 1/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jordan\Application Data\Microsoft\Internet Explorer\Quick Launch\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TYWHQ - Unknown owner - C:\DOCUME~1\Jordan\LOCALS~1\Temp\TYWHQ.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
Glad the rootkit is gone! :)

STEP 1.
Note: (if the service does not exist proceed to next step)
======
Stop and Disable Service
  • Go to Start > Run and type in Services.msc then cllick OK
  • Click the Extended tab.
  • Scroll down until you find TYWHQ
  • Click once on the service to highlight it.
  • Click Stop
  • Right-Click on the service.
  • Click on 'Properties'
  • Select the 'General' tab
  • Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box
  • From the drop-down menu, click on ‘Disabled'
  • Click the 'Apply' tab, then click 'OK'
The service is now stopped and disabled.

Scan with HijackThis. Place a check against each of the following:
O23 - Service: TYWHQ - Unknown owner - C:\DOCUME~1\Jordan\LOCALS~1\Temp\TYWHQ.exe (file missing)
Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

* Turn off the real time scanner of any existing antivirus program while performing the online scan
Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information from Kapersky in your next post.

Also would you run GMER again. I know rootkit is gone but I want to check something else.

Please post:
  • Kapersky log.
  • A new HijackThis log
  • GMER log please
Your may need several replies to post the requested logs, otherwise they might get cut off.
——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Wednesday, January 24, 2007 4:14:38 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 24/01/2007 Kaspersky Anti-Virus database records: 247045 ——————————————————————————- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ F:\ Scan Statistics: Total number of scanned objects: 78235 Number of viruses found: 3 Number of infected objects: 5 / 0 Number of suspicious objects: 0 Duration of the scan process: 00:39:42 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_24adf822-76f7-4481-b30b-ff1b40f8687f Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\Jordan\Application Data\Aim\jordanlamberg\cert8.db Object is locked skipped C:\Documents and Settings\Jordan\Application Data\Aim\jordanlamberg\key3.db Object is locked skipped C:\Documents and Settings\Jordan\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\cert8.db Object is locked skipped C:\Documents and Settings\Jordan\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\formhistory.dat Object is locked skipped C:\Documents and Settings\Jordan\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\history.dat Object is locked skipped C:\Documents and Settings\Jordan\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\key3.db Object is locked skipped C:\Documents and Settings\Jordan\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\parent.lock Object is locked skipped C:\Documents and Settings\Jordan\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\search.sqlite Object is locked skipped C:\Documents and Settings\Jordan\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\Jordan\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped C:\Documents and Settings\Jordan\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Jordan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Jordan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Jordan\Local Settings\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Jordan\Local Settings\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Jordan\Local Settings\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Jordan\Local Settings\Application Data\Mozilla\Firefox\Profiles\nmdz5o07.Jordan\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Jordan\Local Settings\Application Data\mqlluwj.dll Infected: Trojan-Downloader.Win32.Busky.gen skipped C:\Documents and Settings\Jordan\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Jordan\Local Settings\Temp\wahtmltmp00.htm Object is locked skipped C:\Documents and Settings\Jordan\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Jordan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Jordan\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Jordan\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped C:\Program Files\Winamp\Plugins\AudioScrobbler.log.txt Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP279\A0038868.exe Infected: Trojan-Downloader.Win32.Small.edb skipped C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP279\A0038878.dll Infected: Trojan-Downloader.Win32.Busky.gen skipped C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP285\A0039115.exe Infected: Trojan-Downloader.Win32.Small.bpz skipped C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP285\A0039116.dll Infected: Trojan-Downloader.Win32.Busky.gen skipped C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP291\change.log Object is locked skipped C:\WINDOWS\CSC\00000001 Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_Conexant HDA D110 MDC V.92 Modem.txt Object is locked skipped C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{88A1B653-3881-4C43-901B-74C465F95162}.crmlog Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{2CBAD0A1-FB10-44E9-B908-BCD5DAB93435}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\drivers\sptd3949.sys Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_2a0.dat Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_5e4.dat Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-24 16:21:12
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey

—- Kernel code sections - GMER 1.0.12 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2E51 80503B35 3 Bytes [ CF, ED, B9 ]

—- User code sections - GMER 1.0.12 —-

.text C:\Program Files\Winamp\winamp.exe[2896] USER32.dll!SetScrollInfo 77D49056 7 Bytes JMP 03389B03 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2896] USER32.dll!GetScrollInfo 77D517F8 7 Bytes JMP 03389A8B C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2896] USER32.dll!ShowScrollBar 77D5F2CA 5 Bytes JMP 03389B87 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2896] USER32.dll!GetScrollPos 77D5F6DC 5 Bytes JMP 03389AB3 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2896] USER32.dll!SetScrollPos 77D5F728 5 Bytes JMP 03389B2E C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2896] USER32.dll!GetScrollRange 77D5F75F 5 Bytes JMP 03389AD8 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2896] USER32.dll!SetScrollRange 77D5F973 5 Bytes JMP 03389B59 C:\Program Files\Winamp\Plugins\gen_jumpex.dll
.text C:\Program Files\Winamp\winamp.exe[2896] USER32.dll!EnableScrollBar 77D97BC5 7 Bytes JMP 03389A63 C:\Program Files\Winamp\Plugins\gen_jumpex.dll

—- Devices - GMER 1.0.12 —-

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 89E4FA40
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 89E4FA40
Device \Driver\00000057 \Device\00000050 IRP_MJ_POWER [B9EE3EA8] sptd.sys
Device \Driver\00000057 \Device\00000050 IRP_MJ_SYSTEM_CONTROL [B9EF7A70] sptd.sys
Device \Driver\00000057 \Device\00000050 IRP_MJ_PNP [B9EF0728] sptd.sys
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 89E4F0E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 89E4F0E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 89E02550
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 89C686A8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 89C686A8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 89C686A8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 89C686A8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 89C686A8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 89C686A8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C686A8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 89C686A8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 89C686A8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 89C686A8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 89C686A8
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSE 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 89A61C60
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 89A61C60
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 89C686A8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 89C686A8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 89C686A8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 89C686A8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 89C686A8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 89C686A8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C686A8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 89C686A8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 89C686A8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 89C686A8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 89C686A8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 89E02550
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 89E02550
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 89C686A8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 89C686A8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 89C686A8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 89C686A8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 89C686A8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 89C686A8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C686A8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 89C686A8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 89C686A8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 89C686A8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 89C686A8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 89990830
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 89990830
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 89990830
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 89990830
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 89990830
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 89990830
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 89990830
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 89990830
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 89990830
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 89990830
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 89990830
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 89990830
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_CREATE 89990830
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_CLOSE 89990830
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_DEVICE_CONTROL 89990830
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_INTERNAL_DEVICE_CONTROL 89990830
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_CLEANUP 89990830
Device \Driver\NetBT \Device\NetBT_Tcpip_{B44825D3-F6C3-49A1-AEBE-8EFD57E20561} IRP_MJ_PNP 89990830
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CLOSE 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_READ 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_WRITE 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_FLUSH_BUFFERS 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_DEVICE_CONTROL 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SHUTDOWN 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_POWER 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SYSTEM_CONTROL 89E4FC78
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_PNP 89E4FC78
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 89AAF680
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 89AAF680 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 89AAF680 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 89AAF680 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 89AAF680 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 89AAF680 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CREATE_NAMED_PIPE 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLOSE 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_WRITE 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_INFORMATION 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_INFORMATION 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_FLUSH_BUFFERS 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_VOLUME_INFORMATION 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_DIRECTORY_CONTROL 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_FILE_SYSTEM_CONTROL 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_CLEANUP 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_QUERY_SECURITY 89A61A10 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_SET_SECURITY 89A61A10 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 89E02550 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 89E02550 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 89E02550 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 89E02550 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 89E02550 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 89E02550 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 89E02550 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 89E02550 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 89E02550 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 89E02550 Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 89E02550 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CLOSE 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_WRITE 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_INFORMATION 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_SET_INFORMATION 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_VOLUME_INFORMATION 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_DIRECTORY_CONTROL 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_FILE_SYSTEM_CONTROL 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CLEANUP 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_CREATE_MAILSLOT 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_QUERY_SECURITY 8998A708 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_SET_SECURITY 8998A708 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_CREATE 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_CLOSE 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_DEVICE_CONTROL 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_POWER 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_SYSTEM_CONTROL 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target1Lun0 IRP_MJ_PNP 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CREATE 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_CLOSE 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_POWER 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1Port2Path0Target0Lun0 IRP_MJ_PNP 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CREATE 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_CLOSE 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_DEVICE_CONTROL 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_POWER 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_SYSTEM_CONTROL 89C49AF8 Device \Driver\dtscsi \Device\Scsi\dtscsi1 IRP_MJ_PNP 89C49AF8 Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_READ 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 899536F8 Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 899536F8 Device \FileSystem\Fastfat \Fat FastIoCheckIfPossible B1E221F9 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 8990DA30 Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 8990DA30 —- Registry - GMER 1.0.12 —- Reg \Registry\USER\S-1-5-21-1716843091-2073203372-2930501873-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{70A33BF2-3802-F75E-3746-2CA4323BA20E}@abnpegedcbbfakmmofemkedpehhifibkfj 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-1716843091-2073203372-2930501873-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{70A33BF2-3802-F75E-3746-2CA4323BA20E}@bbnpegedcbbfakmmoffmjedfagekbnnlldhi 0x61 0x61 0x00 0x00 —- EOF - GMER 1.0.12 —-
Logfile of HijackThis v1.99.1
Scan saved at 4:23:37 PM, on 1/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jordan\Desktop\gmer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Jordan\Application Data\Microsoft\Internet Explorer\Quick Launch\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

Glad the rootkit is gone! :)

STEP 1.
Note: (if the service does not exist proceed to next step)
======
Stop and Disable Service

  • Go to Start > Run and type in Services.msc then cllick OK
  • Click the Extended tab.
  • Scroll down until you find TYWHQ
  • Click once on the service to highlight it.
  • Click Stop
  • Right-Click on the service.
  • Click on 'Properties'
  • Select the 'General' tab
  • Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box
  • From the drop-down menu, click on ‘Disabled'
  • Click the 'Apply' tab, then click 'OK'
The service is now stopped and disabled.

Scan with HijackThis. Place a check against each of the following:
O23 - Service: TYWHQ - Unknown owner - C:\DOCUME~1\Jordan\LOCALS~1\Temp\TYWHQ.exe (file missing)
Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.


The service was there and I disabled it. It did not, however, show up on hijackthis' scan.
Looks good! Your hijackthis log appears to be clean.

Please set your system to show all files; please see here if you're unsure how to do this.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\Documents and Settings\Jordan\Local Settings\Application Data\mqlluwj.dll<=file
Exit Explorer, and reboot as normal afterwards.

Please run Kapersky once more and post the results.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI