hdBattousai
Topic Starter
hi everyone,
i run spyware terminator and avast antivirus home edition and it's kept me pretty clean but lately i've had a couple suspicious things try running on my pc that i didn't install or d/l first i was hit with a file called zsetup-128-Freeze-silent.exe witch started a hidden d/l and install over night my hips caught it and i stopped it next day and for 2 days afterward a file d/l'd itself and was called MPSigStub.exe i looked up the file and it says its a microsoft file but it caught my attention as suspicious because it installed itself on my second hard drive which i never use and have nothing stored on under the file H:\1b3b00f54712297a6b47e4c2 i tried to scan the file multiple times but i get an access denied for the file as my security rights are insufficient even as admin i proceded to try to zip the file with an "infected" password for further analysis but access was also denied i looked into the security details and system has full rights but owner and admin have none as well as its a hidden read-only file i noticed that each time i tried to access the file such as av and properties checks as well as when i tried to zip it the file changed it's directory path randomly on its own ever since i have denied these 2 files my computer has been acting up and running very slow can anyone help me. i have attached a log from gmer and hijackthis for convenience and i turned off most of my running processes that i initiated to make it shorter
also i contacted zumie support as the freeze-silent.exe registered as being from a vendor zumie somethin i contacted zumie privacy to see why this file of theres was uploaded onto my computer and running as it was trying to progressively scan the contents of my computer but the site refuses to answer any of my contact attempts and does anyone know where to find rku v 3.3 v3.31 wont work for me
**********************************************
HiJackThis Log
**********************************************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:55 AM, on 7/15/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Free Download Manager\FUM\fumoei.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Toshiba Registration\Registration.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Windows\explorer.exe
C:\Users\Owner\Documents\gmer\gmer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Free Uploader Oe Integration] C:\Program Files\Free Download Manager\FUM\fumoei.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [1040749826] C:\Program Files\Toshiba Registration\Registration.exe /r "C:\Program Files\Toshiba Registration\Registration.rpd"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Upload - {FD4E2FF8-973C-4A19-89BD-8E86B3CFCFE1} - C:\Program Files\Free Download Manager\FUM\fumiebtn.dll
O13 - Gopher Prefix:
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: pinger - Unknown owner - C:\Toshiba\IVP\ISM\pinger.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA HD DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
–
End of file - 10302 bytes
******************************************
GMER Log
******************************************
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-07-15 10:32:03
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.14 —-
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwClose [0x90EBE606]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0x90EBE05A]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0x90EBDD3C]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0x90EBF652]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0x90EBDE46]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0x90EBDF30]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0x90EBE8CC]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0x90EBE362]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0x90EBDBBA]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0x90EBE814]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0x90EBE494]
INT 0x51 ? 8BB25BF8
INT 0x62 ? 8BB25BF8
INT 0x72 ? 84656BF8
INT 0x82 ? 84656BF8
INT 0x92 ? 85418BF8
INT 0x92 ? 85419BF8
INT 0x92 ? 8BB25BF8
INT 0x92 ? 85418BF8
INT 0xA2 ? 8BB25BF8
INT 0xA2 ? 8BB25BF8
INT 0xA2 ? 8BB25BF8
INT 0xB3 ? 8BB25BF8
—- Kernel code sections - GMER 1.0.14 —-
.text ntkrnlpa.exe!KeSetTimerEx + 3DC 820F8A30 4 Bytes [ 06, E6, EB, 90 ]
.text ntkrnlpa.exe!KeSetTimerEx + 40C 820F8A60 4 Bytes [ 5A, E0, EB, 90 ]
.text ntkrnlpa.exe!KeSetTimerEx + 41C 820F8A70 4 Bytes [ 3C, DD, EB, 90 ]
.text ntkrnlpa.exe!KeSetTimerEx + 448 820F8A9C 4 Bytes [ 52, F6, EB, 90 ]
.text ntkrnlpa.exe!KeSetTimerEx + 508 820F8B5C 4 Bytes [ 46, DE, EB, 90 ]
.text …
? System32\Drivers\spyf.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload 8D1C146F 5 Bytes JMP 8BB251D8
.text andmnh6z.SYS 8D539000 22 Bytes [ 26, 42, 01, 82, 10, 41, 01, … ]
.text andmnh6z.SYS 8D539017 105 Bytes [ 00, 32, F7, 79, 80, 3D, F5, … ]
.text andmnh6z.SYS 8D539081 53 Bytes [ 28, 09, 82, 58, 39, 0F, 82, … ]
.text andmnh6z.SYS 8D5390B7 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text andmnh6z.SYS 8D5390CE 80 Bytes [ 00, 00, 27, 00, 00, 00, E0, … ]
.text …
—- Kernel IAT/EAT - GMER 1.0.14 —-
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [806996D2] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80699040] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [806997FC] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [806990BE] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8069913C] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806A8D92] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortNotification] F73BFF33
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortWritePortUchar] B85F0B75
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortWritePortUlong] FFFFFFFE
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 08C25D5E
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 5D8B5300
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortGetScatterGatherList] 74DF3B0C
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortReadPortUchar] 01FB8311
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortStallExecution] 5F5B0C74
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortGetParentBusType] FFFFFEB8
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortRequestCallback] C25D5EFF
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 7E390008
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortGetUnCachedExtension] C7077524
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortCompleteRequest] 71642446
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortMoveMemory] 7E398D54
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] C7077528
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 71902846
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 468B8D54
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortReadPortUshort] 244E8B2C
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 7468016A
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortInitialize] 500000FA
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortGetDeviceBase] C73BD1FF
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortDeviceStateChange] 5F5B0C75
—- User IAT/EAT - GMER 1.0.14 —-
IAT C:\Windows\system32\services.exe[768] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 001B0002
IAT C:\Windows\system32\services.exe[768] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 001B0000
IAT C:\Windows\system32\SearchProtocolHost.exe[3964] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW] [6D58DB6B] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Windows\system32\SearchProtocolHost.exe[3964] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DialogBoxParamW] [6D58DB6B] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Windows\system32\SearchProtocolHost.exe[3964] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DialogBoxParamW] [6D58DB6B] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
—- Devices - GMER 1.0.14 —-
Device \FileSystem\Ntfs \Ntfs 8541C1F8
Device \FileSystem\fastfat \FatCdrom 90B221F8
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\netbt \Device\NetBT_Tcpip_{153C23D4-E2C6-4466-BEB2-D5456A73077A} 903CC500
Device \Driver\volmgr \Device\VolMgrControl 846581F8
Device \Driver\usbuhci \Device\USBPDO-0 881D21F8
Device \Driver\usbuhci \Device\USBPDO-1 881D21F8
Device \Driver\usbehci \Device\USBPDO-2 881D31F8
Device \Driver\usbuhci \Device\USBPDO-3 881D21F8
Device \Driver\usbuhci \Device\USBPDO-4 881D21F8
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBPDO-5 881D21F8
Device \Driver\usbehci \Device\USBPDO-6 881D31F8
Device \Driver\volmgr \Device\HarddiskVolume1 846581F8
Device \Driver\volmgr \Device\HarddiskVolume2 846581F8
Device \Driver\cdrom \Device\CdRom0 881F62A0
Device \Driver\sptd \Device\3791051846 spyf.sys
Device \Driver\volmgr \Device\HarddiskVolume3 846581F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8541A1F8
Device \Driver\atapi \Device\Ide\IdePort0 8541A1F8
Device \Driver\iaNvStor \Device\Ide\IAACache0 854191F8
Device \Driver\atapi \Device\Ide\IdePort1 8541A1F8
Device \Driver\iaNvStor \Device\Ide\RobsonImd-0 854191F8
Device \Driver\cdrom \Device\CdRom1 881F62A0
Device \Driver\volmgr \Device\HarddiskVolume4 846581F8
Device \Driver\netbt \Device\NetBT_Tcpip_{2834E2BC-F460-4B8E-A197-F60CF653B3D4} 903CC500
Device \Driver\netbt \Device\NetBt_Wins_Export 903CC500
Device \Driver\PCI_PNP9829 \Device\0000004a spyf.sys
Device \Driver\Smb \Device\NetbiosSmb 90A92500
Device \Driver\iScsiPrt \Device\RaidPort0 882961F8
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBFDO-0 881D21F8
Device \Driver\usbuhci \Device\USBFDO-1 881D21F8
Device \Driver\usbehci \Device\USBFDO-2 881D31F8
Device \Driver\usbuhci \Device\USBFDO-3 881D21F8
Device \Driver\usbuhci \Device\USBFDO-4 881D21F8
Device \Driver\usbuhci \Device\USBFDO-5 881D21F8
Device \Driver\usbehci \Device\USBFDO-6 881D31F8
Device \Driver\andmnh6z \Device\Scsi\andmnh6z1Port4Path0Target0Lun0 882661F8
Device \Driver\andmnh6z \Device\Scsi\andmnh6z1 882661F8
Device \FileSystem\fastfat \Fat 90B221F8
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\cdfs \Cdfs 8833C500
—- Registry - GMER 1.0.14 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x22 0x7B 0x39 0xAA …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x9B 0x1A 0xFD 0x2B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xDB 0xAA 0x54 0x94 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x22 0x7B 0x39 0xAA …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x9B 0x1A 0xFD 0x2B …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xDB 0xAA 0x54 0x94 …
—- Files - GMER 1.0.14 —-
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0169E.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0169F.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A0.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A1.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A2.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A3.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A5.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A6.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A7.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A8.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A9.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AA.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AB.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AC.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AD.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AE.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AF.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B0.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B1.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B2.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B3.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B4.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B5.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B7.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B8.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B9.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BA.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BB.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BC.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BD.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BE.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BF.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016C0.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016C1.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016C2.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A4.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B6.log 131072 bytes
—- EOF - GMER 1.0.14 —-
Thanks and have a great day
note: ive talked to a couple programmer teachers of mine and they told me they have also gotten zsetup-128…. file and its horrid so that may be my problem although i didn't run it and my hips stopped it just thought i'd add that in i've already reported zumie.com to the FTC is malicious site if that helps at all
i run spyware terminator and avast antivirus home edition and it's kept me pretty clean but lately i've had a couple suspicious things try running on my pc that i didn't install or d/l first i was hit with a file called zsetup-128-Freeze-silent.exe witch started a hidden d/l and install over night my hips caught it and i stopped it next day and for 2 days afterward a file d/l'd itself and was called MPSigStub.exe i looked up the file and it says its a microsoft file but it caught my attention as suspicious because it installed itself on my second hard drive which i never use and have nothing stored on under the file H:\1b3b00f54712297a6b47e4c2 i tried to scan the file multiple times but i get an access denied for the file as my security rights are insufficient even as admin i proceded to try to zip the file with an "infected" password for further analysis but access was also denied i looked into the security details and system has full rights but owner and admin have none as well as its a hidden read-only file i noticed that each time i tried to access the file such as av and properties checks as well as when i tried to zip it the file changed it's directory path randomly on its own ever since i have denied these 2 files my computer has been acting up and running very slow can anyone help me. i have attached a log from gmer and hijackthis for convenience and i turned off most of my running processes that i initiated to make it shorter
also i contacted zumie support as the freeze-silent.exe registered as being from a vendor zumie somethin i contacted zumie privacy to see why this file of theres was uploaded onto my computer and running as it was trying to progressively scan the contents of my computer but the site refuses to answer any of my contact attempts and does anyone know where to find rku v 3.3 v3.31 wont work for me
**********************************************
HiJackThis Log
**********************************************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:55 AM, on 7/15/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Free Download Manager\FUM\fumoei.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Toshiba Registration\Registration.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Windows\explorer.exe
C:\Users\Owner\Documents\gmer\gmer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Free Uploader Oe Integration] C:\Program Files\Free Download Manager\FUM\fumoei.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [1040749826] C:\Program Files\Toshiba Registration\Registration.exe /r "C:\Program Files\Toshiba Registration\Registration.rpd"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Upload - {FD4E2FF8-973C-4A19-89BD-8E86B3CFCFE1} - C:\Program Files\Free Download Manager\FUM\fumiebtn.dll
O13 - Gopher Prefix:
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: pinger - Unknown owner - C:\Toshiba\IVP\ISM\pinger.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA HD DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
–
End of file - 10302 bytes
******************************************
GMER Log
******************************************
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-07-15 10:32:03
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.14 —-
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwClose [0x90EBE606]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0x90EBE05A]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0x90EBDD3C]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0x90EBF652]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0x90EBDE46]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0x90EBDF30]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0x90EBE8CC]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0x90EBE362]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0x90EBDBBA]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0x90EBE814]
SSDT \??\C:\Windows\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0x90EBE494]
INT 0x51 ? 8BB25BF8
INT 0x62 ? 8BB25BF8
INT 0x72 ? 84656BF8
INT 0x82 ? 84656BF8
INT 0x92 ? 85418BF8
INT 0x92 ? 85419BF8
INT 0x92 ? 8BB25BF8
INT 0x92 ? 85418BF8
INT 0xA2 ? 8BB25BF8
INT 0xA2 ? 8BB25BF8
INT 0xA2 ? 8BB25BF8
INT 0xB3 ? 8BB25BF8
—- Kernel code sections - GMER 1.0.14 —-
.text ntkrnlpa.exe!KeSetTimerEx + 3DC 820F8A30 4 Bytes [ 06, E6, EB, 90 ]
.text ntkrnlpa.exe!KeSetTimerEx + 40C 820F8A60 4 Bytes [ 5A, E0, EB, 90 ]
.text ntkrnlpa.exe!KeSetTimerEx + 41C 820F8A70 4 Bytes [ 3C, DD, EB, 90 ]
.text ntkrnlpa.exe!KeSetTimerEx + 448 820F8A9C 4 Bytes [ 52, F6, EB, 90 ]
.text ntkrnlpa.exe!KeSetTimerEx + 508 820F8B5C 4 Bytes [ 46, DE, EB, 90 ]
.text …
? System32\Drivers\spyf.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload 8D1C146F 5 Bytes JMP 8BB251D8
.text andmnh6z.SYS 8D539000 22 Bytes [ 26, 42, 01, 82, 10, 41, 01, … ]
.text andmnh6z.SYS 8D539017 105 Bytes [ 00, 32, F7, 79, 80, 3D, F5, … ]
.text andmnh6z.SYS 8D539081 53 Bytes [ 28, 09, 82, 58, 39, 0F, 82, … ]
.text andmnh6z.SYS 8D5390B7 22 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text andmnh6z.SYS 8D5390CE 80 Bytes [ 00, 00, 27, 00, 00, 00, E0, … ]
.text …
—- Kernel IAT/EAT - GMER 1.0.14 —-
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [806996D2] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80699040] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [806997FC] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [806990BE] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8069913C] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806A8D92] \SystemRoot\System32\Drivers\spyf.sys
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortNotification] F73BFF33
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortWritePortUchar] B85F0B75
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortWritePortUlong] FFFFFFFE
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortGetPhysicalAddress] 08C25D5E
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 5D8B5300
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortGetScatterGatherList] 74DF3B0C
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortReadPortUchar] 01FB8311
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortStallExecution] 5F5B0C74
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortGetParentBusType] FFFFFEB8
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortRequestCallback] C25D5EFF
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 7E390008
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortGetUnCachedExtension] C7077524
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortCompleteRequest] 71642446
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortMoveMemory] 7E398D54
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] C7077528
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 71902846
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 468B8D54
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortReadPortUshort] 244E8B2C
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortReadPortBufferUshort] 7468016A
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortInitialize] 500000FA
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortGetDeviceBase] C73BD1FF
IAT \SystemRoot\System32\Drivers\andmnh6z.SYS[ataport.SYS!AtaPortDeviceStateChange] 5F5B0C75
—- User IAT/EAT - GMER 1.0.14 —-
IAT C:\Windows\system32\services.exe[768] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 001B0002
IAT C:\Windows\system32\services.exe[768] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 001B0000
IAT C:\Windows\system32\SearchProtocolHost.exe[3964] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW] [6D58DB6B] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Windows\system32\SearchProtocolHost.exe[3964] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DialogBoxParamW] [6D58DB6B] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Windows\system32\SearchProtocolHost.exe[3964] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DialogBoxParamW] [6D58DB6B] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
—- Devices - GMER 1.0.14 —-
Device \FileSystem\Ntfs \Ntfs 8541C1F8
Device \FileSystem\fastfat \FatCdrom 90B221F8
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\netbt \Device\NetBT_Tcpip_{153C23D4-E2C6-4466-BEB2-D5456A73077A} 903CC500
Device \Driver\volmgr \Device\VolMgrControl 846581F8
Device \Driver\usbuhci \Device\USBPDO-0 881D21F8
Device \Driver\usbuhci \Device\USBPDO-1 881D21F8
Device \Driver\usbehci \Device\USBPDO-2 881D31F8
Device \Driver\usbuhci \Device\USBPDO-3 881D21F8
Device \Driver\usbuhci \Device\USBPDO-4 881D21F8
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBPDO-5 881D21F8
Device \Driver\usbehci \Device\USBPDO-6 881D31F8
Device \Driver\volmgr \Device\HarddiskVolume1 846581F8
Device \Driver\volmgr \Device\HarddiskVolume2 846581F8
Device \Driver\cdrom \Device\CdRom0 881F62A0
Device \Driver\sptd \Device\3791051846 spyf.sys
Device \Driver\volmgr \Device\HarddiskVolume3 846581F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8541A1F8
Device \Driver\atapi \Device\Ide\IdePort0 8541A1F8
Device \Driver\iaNvStor \Device\Ide\IAACache0 854191F8
Device \Driver\atapi \Device\Ide\IdePort1 8541A1F8
Device \Driver\iaNvStor \Device\Ide\RobsonImd-0 854191F8
Device \Driver\cdrom \Device\CdRom1 881F62A0
Device \Driver\volmgr \Device\HarddiskVolume4 846581F8
Device \Driver\netbt \Device\NetBT_Tcpip_{2834E2BC-F460-4B8E-A197-F60CF653B3D4} 903CC500
Device \Driver\netbt \Device\NetBt_Wins_Export 903CC500
Device \Driver\PCI_PNP9829 \Device\0000004a spyf.sys
Device \Driver\Smb \Device\NetbiosSmb 90A92500
Device \Driver\iScsiPrt \Device\RaidPort0 882961F8
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBFDO-0 881D21F8
Device \Driver\usbuhci \Device\USBFDO-1 881D21F8
Device \Driver\usbehci \Device\USBFDO-2 881D31F8
Device \Driver\usbuhci \Device\USBFDO-3 881D21F8
Device \Driver\usbuhci \Device\USBFDO-4 881D21F8
Device \Driver\usbuhci \Device\USBFDO-5 881D21F8
Device \Driver\usbehci \Device\USBFDO-6 881D31F8
Device \Driver\andmnh6z \Device\Scsi\andmnh6z1Port4Path0Target0Lun0 882661F8
Device \Driver\andmnh6z \Device\Scsi\andmnh6z1 882661F8
Device \FileSystem\fastfat \Fat 90B221F8
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\cdfs \Cdfs 8833C500
—- Registry - GMER 1.0.14 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x22 0x7B 0x39 0xAA …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x9B 0x1A 0xFD 0x2B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xDB 0xAA 0x54 0x94 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x22 0x7B 0x39 0xAA …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x9B 0x1A 0xFD 0x2B …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xDB 0xAA 0x54 0x94 …
—- Files - GMER 1.0.14 —-
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0169E.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0169F.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A0.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A1.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A2.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A3.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A5.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A6.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A7.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A8.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A9.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AA.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AB.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AC.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AD.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AE.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016AF.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B0.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B1.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B2.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B3.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B4.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B5.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B7.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B8.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B9.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BA.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BB.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BC.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BD.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BE.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016BF.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016C0.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016C1.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016C2.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016A4.log 131072 bytes
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS016B6.log 131072 bytes
—- EOF - GMER 1.0.14 —-
Thanks and have a great day
note: ive talked to a couple programmer teachers of mine and they told me they have also gotten zsetup-128…. file and its horrid so that may be my problem although i didn't run it and my hips stopped it just thought i'd add that in i've already reported zumie.com to the FTC is malicious site if that helps at all