This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Pc Reboots Its Self

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I think my p/c maybe infected as it continues to reboot its self, this has happened around 10 times in the past hour.

Hijak log


Thanks so much for any help available

Logfile of HijackThis v1.99.1
Scan saved at 7:04:40 PM, on 16/05/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\smanager.7.exe
C:\WINDOWS\System32\avp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\CNAC1RPK.EXE
C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Administrator\My Documents\My Pictures\Athletics\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKLM\..\Run: [C-Media Mixer] "C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe" /MixerStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [WireLessMouse ] "C:\Program Files\Multimedia Combo Set\MouseDrv.exe"
O4 - HKLM\..\Run: [WireLessKeyboard ] "C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\System32\avp.exe
O4 - HKLM\..\Run: [sys0246098977] C:\WINDOWS\sys0246098977.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [sf2kcd9c52q1w] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\crasos.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: KODAK Picture Transfer Software.lnk = ?
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/229?87da74f6272745bfb5559fb001e11c0b
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/230?87da74f6272745bfb5559fb001e11c0b
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O20 - Winlogon Notify: Webvw32 - webvw32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WinCTL - {009541A0-3B00-1F1C-00F3-040224009C02} - C:\Program Files\Common Files\winctl.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe (file missing)
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi ginkara,

You should know that your computer has been infected by backdoor and keylogging trojans. These programs have the ability to steal passwords and other information from your system. If you are using your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.


The first step in the cleaning process is to apply Service Pack 1a for Windows XP. Without this update, you're wide open to re-infection, and we're both just wasting our time.
Click here to get WinXP SP1a: http://www.microsoft.com/windowsxp/downloa…p1/default.mspx

Apply the update, reboot, then go to Windows Update and install all the Critical Updates (Note: Except for WinXP SP2)
Click here for Windows Update: http://www.windowsupdate.com/
Be sure to reboot your machine after this process.

It appears that you are using Norton Antivirus. Please check to see if your Norton subscription is still current, if so please update it with the latest definitions. If it has expired, please renew it or remove the program and install another antivirus program. Two popular and free programs are:
AVG Antivirus: http://free.grisoft.com/doc/1
Antivir: http://www.free-av.com/

Then open HijackThis, select Open the Misc Tools section
Press the Open Uninstall Manager… button, then press Save list…
Save the Uninstall log to your deskop and include a copy in your next response.
Now press Back and Scan and then Save log to create and save a new HijackThis log.

Once complete, please post the uninstall log and a new HijackThis log; if you need any assistance doing this please let me know.
Hi Silver, Thanks for the info, have changed details & passwords etc. My P/C is now rebooting within 10 seconds of loading so Im unable to install anything at this stage. It will start in safe mode. I think the format would be the best option, however is it possible to get it back to the stage so I can burn some of the photos I have on there ? Thanks Again
Hi ginkara,

We can try cleaning some malware in Safe Mode and see if that resolves the rebooting problem. We will need to download a tool to do so, it's not big (760K) but then 10 seconds isn't very long either. If you cannot download this on your computer, do you have access to another computer which you can use to download this tool?

If you can manage to download the program, follow these instructions. If you cannot, then post back and let me know.

Download SDFix and save it to your Desktop (or, transfer it from another computer).

Then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
Once complete, please post the SDFix report and a new HijackThis log and let me know if you are now able to run your machine in normal mode.
Hi Silver,

Downloaded SDFix from another P/C & transfered, upon restarting the log was only there for a few seconds & then it rebooted. I managed to run another hijak log before it rebooted. I noticed a windows error that said something about a spooler sub system application but it rebooted to quick. I have also noticed that if I dont touch the P/C it doesn't reboot, but as soon as I open anything it reboots in around 10 seconds.

Copies of Logs

SDFix: Version 1.84

Run by [removed]
Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
wincom32

ImagePath:
\??\C:\WINDOWS\System32\wincom32.sys

wincom32 - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File
Resetting AppInit_DLLs value


Logfile of HijackThis v1.99.1
Scan saved at 8:05:56 PM, on 23/05/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\dwwin.exe
C:\Documents and Settings\Administrator\My Documents\My Pictures\Athletics\hijackthis\HijackThis.exe
C:\WINDOWS\System32\CNAC1RPK.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/229?87da74f6272745bfb5559fb001e11c0b
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/230?87da74f6272745bfb5559fb001e11c0b
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F9A2608-D639-423A-B107-D971B91A683C}: NameServer = 163.157.254.140
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O20 - Winlogon Notify: Webvw32 - webvw32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WinCTL - {009541A0-3B00-1F1C-00F3-040224009C02} - C:\Program Files\Common Files\winctl.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe (file missing)
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Hi ginkara,

Firstly, I note there has been some significant changes to your HijackThis log which I wouldn't have expected from the SDFix tool. Quite a number of O4 autostart entries have been removed, a new DNS server entry has appeared and so has Spy Sweeper. Do you know about these changes?

Please boot your machine in Safe Mode (I think you are familiar with this by now):
Restart your computer and as soon as it starts booting up again continuously tap F8
A menu should appear, use the arrow keys to select Safe Mode and press enter

Open HijackThis, select View the list of backups and place a checkmark next to any of the following that are present:
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKLM\..\Run: [C-Media Mixer] "C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe" /MixerStartup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [WireLessMouse ] "C:\Program Files\Multimedia Combo Set\MouseDrv.exe"
O4 - HKLM\..\Run: [WireLessKeyboard ] "C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: KODAK Picture Transfer Software.lnk = ?
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe


Then press the Restore button on the right-hand side.

Next, press Back then Scan and place a check-mark next to the following lines (if present):
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O20 - Winlogon Notify: Webvw32 - webvw32.dll (file missing)
O21 - SSODL: WinCTL - {009541A0-3B00-1F1C-00F3-040224009C02} - C:\Program Files\Common Files\winctl.dll


A new entry in your last log is this one:
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F9A2608-D639-423A-B107-D971B91A683C}: NameServer = 163.157.254.140
Did you configure your machine to use the IP address 163.157.254.140 as a DNS server? If not then you can check this line also.

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Next, press Start->Run, type services.msc in the box and press OK
Look down the list for Net Agent - double-click this entry to bring up the properties sheet
Change the Startup type to Disabled, press the Stop button if possible, then press OK
Close the services console

Make hidden/system files and folders visible:
Click Start -> My Computer
Select the Tools menu, click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Show hidden files and folders
UNCHECK the Hide protected operating system files (recommended) option
Click Yes to confirm and press OK

Use Windows Explorer to find and delete the following files (if present):

C:\Documents and Settings\Administrator\Local Settings\Temp\crasos.exe
C:\Program Files\Common Files\winctl.dll
C:\Windows\smanager.7.exe
C:\Windows\sys0246098977.exe
C:\Windows\dls0523pmw.exe
C:\Windows\system32\avp.exe
C:\Windows\system32\ldcore.dll
C:\Windows\system32\webvw32.dll

If one or more of these files are present, but you find you cannot delete it, please make a note of it and tell me in your next response.

Once complete, please reboot your machine normally, post a new HijackThis log and let me know if the rebooting problem recurs.
Hi Silver,

The only change I knew of was Spy Sweeper.

Have followed instructions & rebooting problem seems to have been fixed, I continue to get the error message that The system has recovered from a serious error, it won't go away.

Is it safe to try & burn the pics I wanted.

New Log

Logfile of HijackThis v1.99.1
Scan saved at 10:57:34 PM, on 24/05/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\dumprep.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\CNAC1RPK.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\dwwin.exe
C:\Documents and Settings\Administrator\My Documents\My Pictures\Athletics\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/229?87da74f6272745bfb5559fb001e11c0b
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/230?87da74f6272745bfb5559fb001e11c0b
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Hi ginkara,

Your machine won't be safe until it has been fully cleaned of malware. However, if your machine is now stable enough to do what you want to do, and you intend to reformat after burning your data to CDs, then it's your choice whether to do it or continue cleaning. It's quite likely that your machine is still infected so please keep these things in mind:
  • Disconnect your computer from the internet - if you are just getting your data off, then there is no need to risk either your machine becoming further infected, or your machine infecting others.
  • Do you have other machines on your LAN? If you have more than one computer and they are sharing the same internet connection, plugged into the same router, or connected in any way, then the other computers may have been infected by this one. Please perform full antivirus and antispyware scans and check for any symptoms of infection.
  • Any files taken from this machine are potentially dangerous - malware can attach itself to legitimate files so please do not open or use any files taken from this machine until checked with an up to date antivirus program. I recommend you use Kaspersky's online scanner for this purpose.
Some helpful information on reformatting can be found here:
http://www.dslreports.com/faq/10063

I recommend you take the time to read the article through, particularly the advice about protecting your unpatched computer until it is secured. I suggest you have offline copies of your protection software ready to install, and do not use the computer for anything until it is fully patched and protected.

Some more recommendations to help keep your machine clean once you have reformatted:

Windows XP Service Pack 2, and all the important and critical updates since then are crucial for the security of your system. A major contributing factor to the problems you are now experiencing is the lack of security and feature updates to your OS. Once you have reformatted, please take the time to get it up to date immediately using Windows Update.

Antivirus protection is essential, please ensure you have one operating at all times, do not however install more than one as they can conflict and cause system problems. Two popular and free packages are:

AVG Antivirus: http://free.grisoft.com/doc/1
Antivir: http://www.free-av.com/

Antispyware protection is also essential, there are a variety of programs available, however using one with real-time protection is important.
Windows Defender is free and offers real-time protection.

Firewall protection: XP's in-built firewall helps you by blocking inbound connections to your computer, but adding a software firewall will allow you to monitor and control outbound connections as well. I recommend these programs:
Sunbelt Personal Firewall
Zone Alarm

IESPYADS helps protect you from malicious websites by placing a list of known bad websites in Internet Explorer's Restricted Zone. This Zone limits the capabilities of these websites including preventing them from installing software. This will compliment your security software and I recommend you install it:
http://www.spywarewarrior.com/uiuc/resource.htm

Find out how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know whether you wish to continue cleaning, or you are happy taking your data off and reformatting at this stage.
Hi Silver, No Luck in burning data, machine rebooted itself after about 3 minutes. Best I continue to keep trying to clean. Any further help would be greatly appreciated Thanks
Hi ginkara,

OK we'll see if further cleaning can restore some stability.

Download Dr.WEB CureIt to your desktop from here:
ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe
  • Double-click cureit.exe to start the program.
  • Press Start and then OK to start the Express scan
  • The Express scan takes just a few moments to finish, if something is found, click Yes to cure it
  • Once the short scan has finished, Click Options->Change settings
  • Choose the Scan tab and remove the check mark from Heuristic analysis
  • Choose the Actions tab and next to Infected objects select Move, then press OK to close the settings box.
  • Select all hard drives to be scanned by clicking on them - choose all drives - a red dot confirms they will be scanned
  • Click the green arrow on the right to start the scan
  • Click Yes to all if it asks if you want to move a file
  • Click File-> Save report list and save the report to your desktop
  • Close Dr.Web Cureit and reboot your computer (this is important as files may be moved/deleted during reboot)
Download Gmer to your Desktop from here:
http://www.gmer.net/gmer.zip
  • Unzip the program onto your Desktop
  • Disconnect from internet and close all running programs
  • Double click gmer.exe, let the gmer.sys driver load if asked
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say OK
  • If no warning….Check that the Rootkit tab is selected and click the Scan button - don't change any settings before you do so
  • Once the scan is complete, click the Copy button
  • Open Notepad and hit Ctrl+V to paste the log and then save the log to your desktop
Once complete, please post the Dr Web log and the GMER log along with a new HijackThis log.
Hi ginkara, OK do the Dr Web scan in Safe Mode and see what that turns up, once the Dr Web scan is complete, then try the GMER scan in normal mode, if it doesn't work don't worry, just stop and post the logs.
Hey Silver,

Logs as required

Dr Webb & Hijak, will post GMER shortly

Thanks

sams[1].exe;C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\4DUB0P63;Trojan.Packed.131;Moved.;
Movies.exe;C:\Program Files\Lionhead Studios Ltd\The Movies;Win95.SK;Moved.;
00393260.SYS;C:\RECYCLER\NPROTECT;Trojan.Packed.115;Moved.;
Process.exe;C:\SDFix\apps;Tool.Prockill;;
avp.exe;C:\SDFix\backups;Trojan.DownLoader.22755;Moved.;
ldcore.dll;C:\SDFix\backups;Trojan.DownLoader.18468;Moved.;
movedfile.ren;C:\SDFix\backups;Trojan.DownLoader.18468;Moved.;
pee.exe.exe;C:\SDFix\backups;Trojan.Packed.131;Moved.;
sams.exe.exe;C:\SDFix\backups;Trojan.Packed.131;Moved.;
stdrun2.exe\data001;C:\SDFix\backups\stdrun2.exe;Adware.Bagon;;
stdrun2.exe\data002;C:\SDFix\backups\stdrun2.exe;Trojan.MulDrop.4522;;
stdrun2.exe;C:\SDFix\backups;Archive contains infected objects;Moved.;
wincom32.sys;C:\SDFix\backups;Trojan.Packed.115;Moved.;
A0079688.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP195;Tool.ShutDown.11;;
A0090361.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP226;BackDoor.Generic.1372;Moved.;
A0090362.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP226;BackDoor.Generic.1372;Moved.;
A0096370.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP227;Adware.Bagon;;
A0096372.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP227;Trojan.Click.1166;Moved.;
A0096376.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP227;Trojan.DownLoader.22755;Moved.;
A0096379.sys;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP227;Trojan.Packed.115;Moved.;
A0096380.sys;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP227;Trojan.Packed.115;Moved.;
A0096381.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP227;Trojan.Packed.131;Moved.;
A0096382.dll;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP227;Trojan.DownLoader.22200;Moved.;
A0096384.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP227;Trojan.Packed.131;Moved.;
A0096410.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP228;Adware.Bagon;;
A0096412.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP228;Trojan.Click.1166;Moved.;
A0096416.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP228;Trojan.DownLoader.22755;Moved.;
A0096419.sys;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP228;Trojan.Packed.115;Moved.;
A0096420.sys;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP228;Trojan.Packed.115;Moved.;
A0096421.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP228;Trojan.Packed.131;Moved.;
A0096422.dll;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP228;Trojan.DownLoader.22200;Moved.;
A0096424.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP228;Trojan.Packed.131;Moved.;
A0098457.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP229;Adware.Bagon;;
A0098459.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP229;Trojan.Click.1166;Moved.;
A0098463.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP229;Trojan.DownLoader.22755;Moved.;
A0098466.sys;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP229;Trojan.Packed.115;Moved.;
A0098467.sys;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP229;Trojan.Packed.115;Moved.;
A0098468.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP229;Trojan.Packed.131;Moved.;
A0098469.dll;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP229;Trojan.DownLoader.22200;Moved.;
A0098471.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP229;Trojan.Packed.131;Moved.;
A0109490.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP229;Adware.Bagon;;
A0109493.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP229;Trojan.Click.1166;Moved.;
A0215583.EXE;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP230;Trojan.AVKill.252;Moved.;
A0215587.EXE;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP230;Trojan.DownLoader.4995;Moved.;
A0215588.dll;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP230;Trojan.DownLoader.22200;Moved.;
A0215589.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP230;Trojan.Packed.131;Moved.;
A0219576.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP230;Trojan.Packed.131;Moved.;
A0219577.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP230;Trojan.Packed.131;Moved.;
A0219579.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP230;Trojan.DownLoader.22755;Moved.;
A0219581.sys;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP230;Trojan.Packed.115;Moved.;
A0219582.dll;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP230;Trojan.DownLoader.18468;Moved.;
A0241616.dll;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP232;Trojan.DownLoader.22200;Moved.;
A0249609.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP233;Win95.SK;Moved.;
A0249610.SYS;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP233;Trojan.Packed.115;Moved.;
A0249611.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP233;Trojan.DownLoader.22755;Moved.;
A0249612.dll;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP233;Trojan.DownLoader.18468;Moved.;
A0249613.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP233;Trojan.Packed.131;Moved.;
A0249614.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP233;Trojan.Packed.131;Moved.;
A0249615.exe\data001;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP233\A0249615.exe;Adware.Bagon;;
A0249615.exe\data002;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP233\A0249615.exe;Trojan.MulDrop.4522;;
A0249615.exe;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP233;Archive contains infected objects;Moved.;
A0249616.sys;C:\System Volume Information\_restore{B4CEC110-7980-4F5B-B0C9-F912DC8727C1}\RP233;Trojan.Packed.115;Moved.;
SB1083.exe;C:\Temp;Trojan.DownLoader.21890;Moved.;
ldcore(3).dll;C:\WINDOWS\system32;Trojan.DownLoader.18468;Moved.;
restart.exe;C:\WINDOWS\system32;Tool.ShutDown.11;;
hex.exe;C:\WINDOWS\system32\spool\PRINTERS;Tool.HideApp;;



Logfile of HijackThis v1.99.1
Scan saved at 10:23:40 PM, on 31/05/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\dwwin.exe
C:\WINDOWS\System32\CNAC1RPK.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Administrator\My Documents\My Pictures\Athletics\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/229?87da74f6272745bfb5559fb001e11c0b
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-au\msntabres.dll.mui/230?87da74f6272745bfb5559fb001e11c0b
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F9A2608-D639-423A-B107-D971B91A683C}: NameServer = 194.129.59.35
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
GMER Post is too long so I have cut in half


Thanks

GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-05-31 22:32:45
Windows 5.1.2600


—- System - GMER 1.0.12 —-

SSDT 83372968 ZwAllocateVirtualMemory
SSDT 82B1AD80 ZwConnectPort
SSDT 833EB420 ZwCreateKey
SSDT 8331A020 ZwCreateProcess
SSDT 8339F238 ZwCreateProcessEx
SSDT 833B49F0 ZwCreateThread
SSDT 833E21E8 ZwDeleteKey
SSDT 833D30B8 ZwDeleteValueKey
SSDT \??\C:\WINDOWS\system32\windev-127e-3bfd.sys ZwEnumerateKey <– ROOTKIT !!!
SSDT \??\C:\WINDOWS\system32\windev-127e-3bfd.sys ZwEnumerateValueKey <– ROOTKIT !!!
SSDT \??\C:\Program Files\ewido anti-spyware 4.0\guard.sys ZwOpenProcess
SSDT \??\C:\WINDOWS\system32\windev-127e-3bfd.sys ZwQueryDirectoryFile <– ROOTKIT !!!
SSDT 833CA8B8 ZwQueueApcThread
SSDT 83318FA8 ZwReadVirtualMemory
SSDT 833B1090 ZwRenameKey
SSDT 833899F0 ZwSetContextThread
SSDT 8333DB90 ZwSetInformationKey
SSDT 833E0458 ZwSetInformationProcess
SSDT 833CFB58 ZwSetInformationThread
SSDT 8338A020 ZwSetValueKey
SSDT 833EA538 ZwSuspendProcess
SSDT 8338D238 ZwSuspendThread
SSDT \??\C:\Program Files\ewido anti-spyware 4.0\guard.sys ZwTerminateProcess
SSDT 833EB500 ZwTerminateThread
SSDT 833728F0 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.12 —-

.text ntoskrnl.exe!KeInitializeInterrupt + B79 804D4F8E 1 Byte [ 06 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 150 804FC668 4 Bytes [ 68, 29, 37, 83 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 188 804FC6A0 4 Bytes [ 80, AD, B1, 82 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 1B0 804FC6C8 4 Bytes [ 20, B4, 3E, 83 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 1C8 804FC6E0 8 Bytes [ 20, A0, 31, 83, 38, F2, 39, … ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 1E0 804FC6F8 4 Bytes [ F0, 49, 3B, 83 ]
.text …

—- User code sections - GMER 1.0.12 —-

.text C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe[1916] kernel32.dll!CreateThread + 18 77E7AC4F 4 Bytes [ DD, 41, 5D, 88 ]

—- Devices - GMER 1.0.12 —-

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE 830247C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE 83024748
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE 82F47E10
Device \Driver\Tcpip \Device\Ip IRP_MJ_READ 82F47D98
Device \Driver\Tcpip \Device\Ip IRP_MJ_WRITE 82F47D20
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION 82D71D18
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION 82D71CA0
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA 82D71C28
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA 82F30530
Device \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS 82F304B8
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION 82F30440
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION 82E8F950
Device \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL 82E8F8D8
Device \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL 82E8F860
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL 82D71438
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL 82D713C0
Device \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN 82D71348
Device \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL 82E1D9A0
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP 82E1D928
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT 82E1D8B0
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY 82E79530
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY 82E794B8
Device \Driver\Tcpip \Device\Ip IRP_MJ_POWER 82E79440
Device \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL 82FE9FA8
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE 82FE9F30
Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA 82FE9EB8
Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA 82F42FA8
Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP 82F42F30
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE 830247C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE 83024748
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE 82F47E10
Device \Driver\Tcpip \Device\Tcp IRP_MJ_READ 82F47D98
Device \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE 82F47D20
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION 82D71D18
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION 82D71CA0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA 82D71C28
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA 82F30530
Device \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS 82F304B8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION 82F30440
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION 82E8F950
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL 82E8F8D8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL 82E8F860
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL 82D71438
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL 82D713C0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN 82D71348
Device \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL 82E1D9A0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP 82E1D928
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT 82E1D8B0
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY 82E79530
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY 82E794B8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_POWER 82E79440
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL 82FE9FA8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE 82FE9F30
Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA 82FE9EB8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA 82F42FA8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP 82F42F30
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE 830247C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE 83024748
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE 82F47E10
Device \Driver\Tcpip \Device\Udp IRP_MJ_READ 82F47D98
Device \Driver\Tcpip \Device\Udp IRP_MJ_WRITE 82F47D20
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION 82D71D18
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION 82D71CA0
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA 82D71C28
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA 82F30530
Device \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS 82F304B8
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION 82F30440
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION 82E8F950
Device \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL 82E8F8D8
Device \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL 82E8F860
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL 82D71438
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL 82D713C0
Device \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN 82D71348
Device \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL 82E1D9A0
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP 82E1D928
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT 82E1D8B0
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY 82E79530
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY 82E794B8
Device \Driver\Tcpip \Device\Udp IRP_MJ_POWER 82E79440
Device \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL 82FE9FA8
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE 82FE9F30
Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA 82FE9EB8
Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA 82F42FA8
Device \Driver\Tcpip \Device\Udp IRP_MJ_PNP 82F42F30
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE 830247C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE 83024748
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE 82F47E10
Device \Driver\Tcpip \Device\RawIp IRP_MJ_READ 82F47D98
Device \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE 82F47D20
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION 82D71D18
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION 82D71CA0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA 82D71C28
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA 82F30530
Device \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS 82F304B8
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION 82F30440
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION 82E8F950
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL 82E8F8D8
Device \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL 82E8F860
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL 82D71438
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL 82D713C0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN 82D71348
Device \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL 82E1D9A0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP 82E1D928
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT 82E1D8B0
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY 82E79530
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY 82E794B8
Device \Driver\Tcpip \Device\RawIp IRP_MJ_POWER 82E79440
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL 82FE9FA8
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE 82FE9F30
Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA 82FE9EB8
Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA 82F42FA8
Device \Driver\Tcpip \Device\RawIp IRP_MJ_PNP 82F42F30
Device \Driver\SYMTDI \Device\SymTDI IRP_MJ_DEVICE_CONTROL [BA5927A0] windev-127e-3bfd.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE 830247C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_NAMED_PIPE 83024748
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE 82F47E10
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_READ 82F47D98
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_WRITE 82F47D20
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_INFORMATION 82D71D18
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_INFORMATION 82D71CA0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_EA 82D71C28
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_EA 82F30530
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FLUSH_BUFFERS 82F304B8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_VOLUME_INFORMATION 82F30440
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_VOLUME_INFORMATION 82E8F950
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DIRECTORY_CONTROL 82E8F8D8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FILE_SYSTEM_CONTROL 82E8F860
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL 82D71438
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL 82D713C0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SHUTDOWN 82D71348
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_LOCK_CONTROL 82E1D9A0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP 82E1D928
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_MAILSLOT 82E1D8B0
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_SECURITY 82E79530
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_SECURITY 82E794B8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_POWER 82E79440
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SYSTEM_CONTROL 82FE9FA8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CHANGE 82FE9F30
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_QUOTA 82FE9EB8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_QUOTA 82F42FA8
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_PNP
—- Services - GMER 1.0.12 —- Service C:\WINDOWS\system32\windev-127e-3bfd.sys (*** hidden *** ) [AUTO] windev-127e-3bfd <– ROOTKIT !!! —- Registry - GMER 1.0.12 —- Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-127E-3BFD Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-127E-3BFD@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@Service windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@DeviceDesc windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@Service windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@DeviceDesc windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-127E-3BFD\00\Control@ActiveService windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@Service windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@DeviceDesc windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-127E-3BFD@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-1456-419E Reg \Registry\MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEV-1456-419E@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@Type 1 Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@Start 2 Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@ErrorControl 1 Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd\Enum@0 Root\LEGACY_WINDEV-127E-3BFD\00 Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@Type 1 Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-127E-3BFD Reg \Registry\MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-127E-3BFD@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@Service windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@DeviceDesc windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@Service windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@DeviceDesc windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-127E-3BFD@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-1456-419E Reg \Registry\MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINDEV-1456-419E@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\windev-127e-3bfd@Type 1 Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\windev-127e-3bfd@Start 2 Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\windev-127e-3bfd@ErrorControl 1 Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_WINDEV-1456-419E Reg \Registry\MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_WINDEV-1456-419E@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_WINDEV-1456-419E\00@Service windev-1456-419e Reg \Registry\MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_WINDEV-1456-419E\00@DeviceDesc windev-1456-419e Reg \Registry\MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_WINDEV-1456-419E@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\ControlSet004\Services\windev-1456-419e Reg \Registry\MACHINE\SYSTEM\ControlSet004\Services\windev-1456-419e@Type 1 Reg \Registry\MACHINE\SYSTEM\ControlSet004\Services\windev-1456-419e@Start 2 Reg \Registry\MACHINE\SYSTEM\ControlSet004\Services\windev-1456-419e@ErrorControl 1 Reg \Registry\MACHINE\SYSTEM\ControlSet004\Services\windev-1456-419e@ImagePath \??\C:\WINDOWS\System32\windev-1456-419e.sys Reg \Registry\MACHINE\SYSTEM\ControlSet004\Services\windev-1456-419e@DisplayName windev-1456-419e Reg \Registry\MACHINE\SYSTEM\ControlSet004\Services\windev-1456-419e@ImagePath \??\C:\WINDOWS\System32\windev-1456-419e.sys Reg \Registry\MACHINE\SYSTEM\ControlSet004\Services\windev-1456-419e@DisplayName windev-1456-419e Reg \Registry\MACHINE\SYSTEM\ControlSet004\Services\windev-1456-419e@ImagePath \??\C:\WINDOWS\System32\windev-1456-419e.sys Reg \Registry\MACHINE\SYSTEM\ControlSet004\Services\windev-1456-419e@DisplayName windev-1456-419e Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-127E-3BFD Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-127E-3BFD@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@Service windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@DeviceDesc windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@Service windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@DeviceDesc windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-127E-3BFD\00\Control@ActiveService windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@Service windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-127E-3BFD\00@DeviceDesc windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-127E-3BFD@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-1456-419E Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEV-1456-419E@NextInstance 1 Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@Type 1 Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@Start 2 Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@ErrorControl 1 Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd\Enum@0 Root\LEGACY_WINDEV-127E-3BFD\00 Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@Type 1 Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@ImagePath \??\C:\WINDOWS\system32\windev-127e-3bfd.sys Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\windev-127e-3bfd@DisplayName windev-127e-3bfd —- Files - GMER 1.0.12 —- ADS C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{69718663-3D4C-1AEE-C987-B087C1311515}1\10-{69718663-3D4C-1AEE-C987-B087C1311515}-v1-{7E41B912-E6AA-4DAA-BB4E-E30D346E8E7B}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{69718663-3D4C-1AEE-C987-B087C1311515}\11\11-{AE47FC8B-54AC-4E9A-85DC-982F29F2C01D}-v11-{AE47FC8B-54AC-4E9A-85DC-982F29F2C01D}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS ADS C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{69718663-3D4C-1AEE-C987-B087C1311515}\12\12-{AE47FC8B-54AC-4E9A-85DC-982F29F2C01D}-v12-{AE47FC8B-54AC-4E9A-85DC-982F29F2C01D}-v12-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS File C:\WINDOWS\system32\windev-127e-3bfd.sys <– ROOTKIT !!! File C:\WINDOWS\system32\windev-peers.ini —- EOF - GMER 1.0.12 —-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI