Just like what jeff said, try going for LiveXP from Winbuilder (http://winbuilder.net/dow
Main Topics
Browse All TopicsI have a rootkit that I can't remove. I ran sdfix, combofix and gmer. I ran gmer and ran a scan but it disappears before finishing. If I stop it when I see typing in red I can delete or disable the service. Here's a log file from gmer. See line with
" \\?\globalroot\Device\__ma
I put the combofix log below gmer too.
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-08-19 14:21:58
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT 89AE8420 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Dr
SSDT \??\C:\WINDOWS\system32\Dr
---- Kernel code sections - GMER 1.0.15 ----
? win32k.sys:1 The system cannot find the file specified. !
? win32k.sys:2 The system cannot find the file specified. !
? C:\WINDOWS\system32\Driver
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[61
.text C:\WINDOWS\system32\winlog
.text C:\WINDOWS\system32\winlog
.text C:\WINDOWS\system32\winlog
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\winlog
IAT C:\WINDOWS\system32\winlog
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\Device\__ma
Library \\?\globalroot\Device\__ma
Library \\?\globalroot\Device\__ma
Library \\?\globalroot\Device\__ma
Library \\?\globalroot\Device\__ma
Library \\?\globalroot\Device\__ma
Library \\?\globalroot\Device\__ma
Library \\?\globalroot\Device\__ma
Library \\?\globalroot\Device\__ma
---- Files - GMER 1.0.15 ----
ADS C:\System Volume Information\_restore{0ED51
ADS C:\System Volume Information\_restore{0ED51
ADS C:\System Volume Information\_restore{0ED51
ADS C:\System Volume Information\_restore{0ED51
ADS C:\System Volume Information\_restore{0ED51
ADS C:\System Volume Information\_restore{0ED51
ComboFix 09-08-18.04 - Administrator 08/19/2009 15:26.3.2 - NTFSx86
Running from: c:\install\spyware\ComboFi
.
((((((((((((((((((((((((((
.
.
((((((((((((((((((((((((((
.
-------\Legacy_{79007602-0
-------\Legacy_{79007602-0
((((((((((((((((((((((((( Files Created from 2009-07-19 to 2009-08-19 ))))))))))))))))))))))))))
.
2009-08-19 17:55 . 2008-04-14 00:12 14336 ----a-w- c:\windows\system32\svchos
2009-08-19 17:21 . 2009-08-19 17:21 -------- d-----w- c:\documents and settings\administrator.SNP
2009-08-19 16:41 . 2009-08-19 16:41 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwareb
2009-08-19 16:35 . 2009-08-19 16:35 -------- d-----w- c:\program files\Unlocker
2009-08-19 16:20 . 2009-08-19 16:20 578560 -c--a-w- c:\windows\system32\dllcac
2009-08-19 16:19 . 2009-08-19 16:19 -------- d-----w- c:\windows\ERUNT
2009-08-19 16:18 . 2009-08-19 16:18 -------- d-----w- c:\documents and settings\Administrator\Loc
2009-08-19 16:12 . 2009-08-19 16:12 -------- d-----w- c:\documents and settings\dave\Application Data\Malwarebytes
2009-08-19 16:12 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\driver
2009-08-19 16:12 . 2009-08-19 19:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 16:12 . 2009-08-19 16:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-19 16:12 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\driver
2009-08-19 13:23 . 2009-08-19 13:23 -------- d-----w- c:\documents and settings\robert\Applicatio
2009-08-17 12:20 . 2009-08-17 12:20 -------- d-----w- c:\documents and settings\brent\Application
2009-08-16 01:33 . 2009-08-16 01:33 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2009-08-16 01:33 . 2009-08-16 01:33 87888 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2009-08-16 01:33 . 2009-08-16 01:33 875728 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2009-08-16 01:33 . 2009-08-16 01:33 371248 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2009-08-16 01:33 . 2009-08-16 01:33 259368 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2009-08-16 01:33 . 2009-08-16 01:33 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2009-08-16 01:33 . 2009-08-16 01:33 177520 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2009-08-16 01:33 . 2009-08-16 01:33 101936 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd
2009-08-05 03:10 . 2009-08-05 03:10 -------- d-----w- c:\documents and settings\dave\Local Settings\Application Data\Temp
2009-07-23 13:25 . 2009-07-23 13:25 -------- d-----w- c:\program files\Jetcast
.
((((((((((((((((((((((((((
.
2009-08-19 17:02 . 2008-05-01 01:04 -------- d-----w- c:\program files\Symantec AntiVirus
2009-08-19 16:40 . 2009-05-29 14:25 256 ----a-w- c:\windows\system32\pool.b
2009-08-18 05:37 . 2009-03-21 04:39 117760 ----a-w- c:\documents and settings\police\Applicatio
2009-08-17 20:42 . 2009-03-13 19:23 -------- d-----w- c:\program files\DYMO Label
2009-08-17 12:09 . 2008-05-01 15:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-16 17:20 . 2008-01-24 20:23 107208 -c--a-w- c:\documents and settings\Judge\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-11 05:09 . 2008-05-01 01:26 -------- d-----w- c:\documents and settings\police\Applicatio
2009-08-11 05:08 . 2008-02-21 16:24 -------- d-----w- c:\program files\Common Files\Roxio Shared
2009-08-11 05:08 . 2008-02-21 16:24 -------- d-----w- c:\program files\Roxio
2009-08-11 05:07 . 2009-05-29 14:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2009-08-11 05:03 . 2008-02-21 16:25 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-08-11 04:57 . 2009-04-22 19:41 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-08-11 04:42 . 2008-04-30 23:40 -------- d-----w- c:\program files\LogMeIn
2009-08-11 04:22 . 2009-03-07 23:56 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-06 19:10 . 2008-04-30 22:36 -------- d-----w- c:\program files\Microsoft Money
2009-07-18 21:25 . 2009-05-21 17:40 -------- d-----w- c:\program files\SJS
2009-06-25 14:59 . 2009-03-23 18:51 117760 ----a-w- c:\documents and settings\dave\Application Data\SUPERAntiSpyware.com\
2009-06-15 14:50 . 2009-06-15 14:50 390664 -c--a-w- c:\documents and settings\dave\Application Data\Real\RealPlayer\Updat
2009-05-21 19:37 . 2009-06-19 17:33 55 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\p
2008-03-06 20:35 . 2008-02-21 18:51 952 --sha-w- c:\windows\system32\KGyGaA
.
------- Sigcheck -------
[-] 2004-08-04 04:56 14336 8F078AE4ED187AAABC0A305146
[-] 2008-04-14 00:12 14336 27C6D03BCDB8CFEB96B716F3D8
[-] 2008-04-14 00:12 14336 27C6D03BCDB8CFEB96B716F3D8
[-] 2007-03-08 15:48 578048 7AA4F6C00405DFC4B70ED4214E
[-] 2008-04-14 00:12 578560 B26B135FF1B9F60C9388B4A7D1
[-] 2008-04-14 00:12 578560 B26B135FF1B9F60C9388B4A7D1
[-] 2009-08-19 16:20 578560 !HASH: COULD NOT OPEN FILE !!!!! c:\windows\system32\dllcac
[-] 2004-08-04 04:56 82944 2ED0B7F12A60F90092081C50FA
[-] 2008-04-14 00:12 82432 2CCC474EB85CEAA3E1FA172658
[-] 2008-04-14 00:12 82432 2CCC474EB85CEAA3E1FA172658
[-] 2008-03-01 13:03 827392 6316C2F0C61271C8ABDFF74291
[-] 2008-04-23 03:35 827392 41546B396A526918DA7995A02E
[-] 2008-06-23 16:01 827904 C66402A06B83B036C195242C0C
[-] 2008-08-26 09:08 827904 77C192FE56A70D7FA0247BA0A6
[-] 2008-10-16 20:24 827904 0D5B75171FF51775B630A431B6
[-] 2008-12-20 23:56 827904 044E0A4E9FE97C0FB9AFE9C89E
[-] 2009-03-03 00:17 828416 C8667854873938CA13C986F16B
[-] 2009-04-29 04:49 828928 62CCA075F44015147B8971DAFF
[-] 2006-10-19 20:12 664576 64CE26DB72810B30F7855EA51E
[-] 2007-08-13 23:54 818688 A4A0FC92358F39538A6494C42E
[-] 2007-10-10 23:56 824832 30C1E0F34AD2972C72A01DB5C7
[-] 2007-12-07 02:21 824832 806D274C9A6C3AAEA5EAE8E4AF
[-] 2008-03-01 13:06 826368 AD21461AEF8244EDEC2EF18E55
[-] 2008-04-23 04:16 826368 F6589BE784647CFDBC22EA51CC
[-] 2008-06-23 16:57 826368 8C13D4A7479FA0A026EDA8ABCE
[-] 2008-08-26 07:24 826368 EF8EBA98145BFA44E80D17A3B3
[-] 2008-10-16 20:38 826368 6741EAF7B7F110E803A6E38F6E
[-] 2008-12-20 23:15 826368 A82935D32D0672E8FF4E91AE39
[-] 2009-03-03 00:18 826368 28775945CCD53DEE280EF58DEA
[-] 2008-04-14 00:12 666112 7A4F775ABB2F1C97DEF3E73AFA
[-] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D8
[-] 2009-04-29 04:49 828928 62CCA075F44015147B8971DAFF
[-] 2007-10-10 23:56 824832 30C1E0F34AD2972C72A01DB5C7
[-] 2007-10-10 23:47 825344 0E5D918F87EFA7D2424D66B499
[-] 2007-10-11 05:57 666112 80D660A49E0D118144423099B2
[-] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D8
[-] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D8
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F
[-] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B
[-] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B
[-] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB88059
[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD
[-] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB88059
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F
[-] 2004-08-04 04:56 502272 01C3346C241652F43AED8E2149
[-] 2008-04-14 00:12 507904 ED0EF0A136DEC83DF69F041188
[-] 2008-04-14 00:12 507904 ED0EF0A136DEC83DF69F041188
[-] 2004-08-04 03:14 182912 558635D3AF1C7546D26067D5D9
[-] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE717
[-] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE717
[-] 2004-08-04 03:00 29056 4448006B6BC60E6C027932CFC3
[-] 2008-04-13 18:53 36608 3BB22519A194418D5FEC05D800
[-] 2008-04-13 18:53 36608 3BB22519A194418D5FEC05D800
[-] 2009-02-06 10:30 2066176 607352B9CB3D708C67F6039097
[-] 2008-08-14 19:39 2066048 A25E9B86EFFB2AF33BF51E676B
[-] 2007-02-28 09:15 2017280 2DFB215E291E3D9B1CF9A6739B
[-] 2008-08-14 09:33 2023936 8206B5F94A6A9450E934029420
[-] 2008-04-13 18:31 2023936 7F653A89F6E89E3AE0D49830EE
[-] 2009-02-07 23:02 2066048 5BA7F2141BC6DB06100D0E5A73
[-] 2008-04-13 18:31 2065792 109F8E3E3C82E337BB71B6BC9B
[-] 2009-02-06 10:32 2023936 65D4220799E6FC2CB079070A63
[-] 2009-02-07 23:02 2066048 5BA7F2141BC6DB06100D0E5A73
[-] 2009-02-07 23:35 2189184 EFE8EACE83EAAD5849A7A548FB
[-] 2008-08-14 20:11 2189184 31914172342BFF330063F343AC
[-] 2007-02-28 09:53 2137600 E6679C3023B17D8B78946BC5DF
[-] 2008-08-14 10:09 2145280 F6F8245B3A2E9CA834DD318E7A
[-] 2008-04-13 19:24 2145280 40F8880122A030A7E9E1FEDEA8
[-] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63
[-] 2008-04-13 19:27 2188928 0C89243C7C3EE199B96FCC1699
[-] 2009-02-06 11:06 2145280 0CBA44D0938D57F334C0862424
[-] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63
[-] 2008-04-14 00:12 1033728 12896823FB95BFB3DC9B46BCAE
[-] 2007-06-13 10:23 1033216 97BD6515465659FF8F3B7BE375
[-] 2008-04-14 00:12 1033728 12896823FB95BFB3DC9B46BCAE
[-] 2009-02-06 11:06 110592 020CEAAEDC8EB655B6506B8C70
[-] 2004-08-04 04:56 108032 C6CE6EEC82F187615D1002BB3B
[-] 2008-04-14 00:12 108544 0E776ED5F7CC9F94299E70461B
[-] 2008-04-14 00:12 108544 0E776ED5F7CC9F94299E70461B
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225
[-] 2004-08-04 04:56 13312 84885F9B82F4D55C6146EBF606
[-] 2008-04-14 00:12 13312 BF2466B3E18E970D8A976FB95F
[-] 2008-04-14 00:12 13312 BF2466B3E18E970D8A976FB95F
[-] 2004-08-04 04:56 15360 24232996A38C0B0CF151C2140A
[-] 2008-04-14 00:12 15360 5F1D5F88303D4A4DBC8E5F97BA
[-] 2008-04-14 00:12 15360 5F1D5F88303D4A4DBC8E5F97BA
[-] 2006-10-19 20:08 57856 AD3D9D191AEA7B5445FE1D82FF
[-] 2008-04-14 00:12 57856 D8E14A61ACC1D4A6CD0D38AEBA
[-] 2008-04-14 00:12 57856 D8E14A61ACC1D4A6CD0D38AEBA
[-] 2004-08-04 04:56 24576 39B1FFB03C2296323832ACBAE5
[-] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7
[-] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7
[-] 2004-08-04 04:56 295424 B60C877D16D9C880B952FDA04A
[-] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684
[-] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684
[-] 2009-03-21 13:59 991744 DA11D9D6ECBDF0F93436A4B7C1
[-] 2007-04-16 16:07 986112 09F7CB3687F86EDAA4CA081F7A
[-] 2008-04-14 00:11 989696 C24B983D211C34DA8FCC1AC384
[-] 2008-04-14 00:11 989696 C24B983D211C34DA8FCC1AC384
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBB
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBB
[-] 2004-08-04 04:56 17408 1B5F6923ABB450692E9FE0672C
[-] 2008-04-14 00:12 17408 50A166237A0FA771261275A405
[-] 2008-04-14 00:12 17408 50A166237A0FA771261275A405
[-] 2004-08-04 04:56 110080 87CA7CE6469577F059297B9D65
[-] 2008-04-14 00:11 110080 0DA85218E92526972A821587E6
[-] 2008-04-14 00:11 110080 0DA85218E92526972A821587E6
[-] 2008-03-01 13:03 3593216 4EE273E2B09317C1217EF0DB91
[-] 2008-04-23 03:35 3593728 4D612FF5D3B7EEF200595AE6F9
[-] 2008-06-23 16:01 3594240 28B8231CA8D55FC85E027A57C9
[-] 2008-08-26 09:08 3594752 25CC085720EE3617FD1F8AB9E2
[-] 2008-10-16 20:24 3595264 B74F31A4BD83797D7A083F9221
[-] 2008-12-13 06:26 3594752 C79FAD61CD4A26ED5AA8C16D99
[-] 2009-01-16 16:24 3596288 CC9D001B7370B292C35B366CA0
[-] 2009-02-21 07:39 3596800 1BB754AB47B327DE8DBF2FA18C
[-] 2009-04-29 04:49 3598336 C6FD770D518FB024245A0EE217
[-] 2006-10-19 20:12 3058176 D251679BD9EF0250201FB899EC
[-] 2007-08-13 23:54 3578368 C6EC2493346ED8888A549F5921
[-] 2007-10-31 10:12 3590656 8AB7ECF59D6EBBE986277B65ED
[-] 2007-12-08 05:21 3592192 A097C36412455F0C7E42377FAF
[-] 2008-03-01 22:36 3591680 AB2C88167D78D71D93558ACECB
[-] 2008-04-24 02:16 3591680 8976CAB317105F7431B08EA32A
[-] 2008-06-24 14:57 3592192 EC936148284F557F19C3331787
[-] 2008-08-27 08:24 3593216 1AD035E04A7068EC2820B055A3
[-] 2008-10-17 07:08 3593216 EACAEDEF6FA2A969DE5B36190D
[-] 2008-12-13 06:40 3593216 121EC39A64D64205A88C2C45B0
[-] 2009-01-17 02:35 3594752 3B413267DA8AE71C20E5EF3E54
[-] 2009-02-20 18:09 3595264 C7C3E41CC2F6EB4A629FE21841
[-] 2008-04-14 00:11 3066880 A706E122B398FE1AB85CB9B75D
[-] 2009-04-29 04:56 3596288 2B4315EC9E3124408A2A5074C4
[-] 2009-04-29 04:49 3598336 C6FD770D518FB024245A0EE217
[-] 2007-10-31 10:12 3590656 8AB7ECF59D6EBBE986277B65ED
[-] 2007-10-30 23:48 3593216 54D8B404F17AA74C666F7F3AEF
[-] 2007-10-30 09:55 3065856 79314A0A6B0DA78AFE491FF2D8
[-] 2009-04-29 04:56 3596288 2B4315EC9E3124408A2A5074C4
[-] 2009-04-29 04:56 3596288 2B4315EC9E3124408A2A5074C4
[-] 2004-08-04 02:58 24576 EBDEE8A2EE5393890A1ACEE971
[-] 2008-04-13 18:39 24576 463C1EC80CD17420A542B7F36A
[-] 2008-04-13 18:39 24576 463C1EC80CD17420A542B7F36A
[-] 2004-08-04 04:56 792064 6728270CB7DBB776ED086F5AC4
[-] 2008-04-14 00:11 792064 1280A158C722FA95A80FB7AEBE
[-] 2008-04-14 00:11 792064 1280A158C722FA95A80FB7AEBE
[-] 2004-08-04 04:56 22016 74D66B3DE265E8789153414E75
[-] 2008-04-14 00:11 22016 012DF358CEBAA23ACB26D82077
[-] 2008-04-14 00:11 22016 012DF358CEBAA23ACB26D82077
[-] 2001-08-23 12:00 4224 DA1F27D85E0D1525F6621372E7
[-] 2001-08-23 12:00 4224 DA1F27D85E0D1525F6621372E7
[-] 2001-08-23 12:00 2944 73C1E1F395918BC2C6DD67AF75
[-] 2001-08-23 12:00 2944 73C1E1F395918BC2C6DD67AF75
[-] 2006-02-15 00:22 142464 1EE7B434BA961EF845DE136224
[-] 2008-04-13 16:39 142592 8BED39E3C35D6A489438B81417
[-] 2008-04-13 16:39 142592 8BED39E3C35D6A489438B81417
[-] 2006-11-01 19:17 927504 925F8B61ED301A317BA850EBEE
[-] 2008-04-14 00:11 927504 CDDD4416B2B4C7295FE3FDB6DD
[-] 2008-04-14 00:11 927504 CDDD4416B2B4C7295FE3FDB6DD
[-] 2009-02-09 10:56 401408 9222562D44021B988B9F9F6220
[-] 2006-10-19 20:09 398336 C369DF215D352B6F3A0B8C3469
[-] 2008-04-14 00:12 399360 2589FE6015A316C0F5D5112B4D
[-] 2008-04-14 00:12 399360 2589FE6015A316C0F5D5112B4D
[-] 2009-02-09 12:10 401408 6B27A5C03DFB94B42457390654
[-] 2009-02-09 12:10 401408 6B27A5C03DFB94B42457390654
[-] 2004-08-04 04:56 33792 95FD808E4AC22ABA025A7B3EAC
[-] 2008-04-14 00:11 33792 986B1FF5814366D71E0AC5755C
[-] 2008-04-14 00:11 33792 986B1FF5814366D71E0AC5755C
[-] 2006-10-19 20:13 617472 B0124CB21D28B1C9F678B566B6
[-] 2008-04-14 00:11 617472 06F247492BC786CE5C24A23E17
[-] 2008-04-14 00:11 617472 06F247492BC786CE5C24A23E17
[-] 2001-08-23 12:00 921088 AEF3D788DBF40C7C4D204EA45E
[-] 2004-08-04 04:57 1050624 5AF68A5E44734A082442668E9C
[-] 2008-04-14 00:12 1054208 BD38D1EBE24A46BD3EDA059560
[-] 2001-08-23 12:00 11648 9859C0F6936E723E4892D7141B
[-] 2004-08-04 04:56 5120 E8A12A12EA9088B4327D49EDCA
[-] 2008-04-14 00:12 5120 96E1C926F22EE1BFBAE82901A3
[-] 2008-04-14 00:12 5120 96E1C926F22EE1BFBAE82901A3
[-] 2004-08-04 04:56 407040 96353FCECBA774BB8DA74A1C65
[-] 2008-04-14 00:12 407040 1B7F071C51B77C272875C3A23E
[-] 2008-04-14 00:12 407040 1B7F071C51B77C272875C3A23E
[-] 2004-08-04 04:56 382464 2C69EC7E5A311334D10DD95F33
[-] 2008-04-14 00:12 409088 574738F61FCA2935F5265DC4E5
[-] 2008-04-14 00:12 409088 574738F61FCA2935F5265DC4E5
[-] 2008-04-14 00:12 409088 574738F61FCA2935F5265DC4E5
[-] 2004-08-04 04:56 180224 0F78E27F563F2AAF74B91A49E2
[-] 2008-04-14 00:12 181248 A86BB5E61BF3E39B62AB4C7E70
[-] 2008-04-14 00:12 181248 A86BB5E61BF3E39B62AB4C7E70
[-] 2004-08-04 04:56 55808 82B24CB70E5944E6E34662205A
[-] 2008-04-14 00:11 56320 6D4FEB43EE538FC5428CC7F056
[-] 2008-04-14 00:11 60928 !HASH: COULD NOT OPEN FILE !!!!! c:\windows\system32\eventl
[-] 2004-08-04 03:05 14336 02000ABF34AF4C218C35D25702
[-] 2008-04-13 18:57 14336 B153AFFAC761E7F5FCFA822B9C
[-] 2008-04-13 18:57 14336 B153AFFAC761E7F5FCFA822B9C
[-] 2007-02-09 11:10 574464 19A811EF5F1ED5C926A028CE10
[-] 2008-04-13 19:15 574976 78A08DD6A8D65E697C18E1DB01
[-] 2008-04-13 19:15 574976 78A08DD6A8D65E697C18E1DB01
[-] 2005-01-28 18:44 25088 140EF97B64F560FD78643CAE2C
[-] 2004-08-04 04:56 52224 C086483E3DBA8C1C0A687EC8D5
[-] 2006-10-19 02:47 27136 C51B4A5C05A5475708E3C81C77
[-] 2006-10-19 02:47 27136 C51B4A5C05A5475708E3C81C77
[-] 2004-08-04 04:56 129536 EEF46DAB68229A14DA3D8E73C9
[-] 2008-04-14 00:12 129024 295D21F14C335B53CB8154E5B1
[-] 2008-04-14 00:12 129024 295D21F14C335B53CB8154E5B1
[-] 2004-08-04 04:56 60416 10654F9DDCEA9C46CFB7755423
[-] 2008-04-14 00:11 62464 3D4E199942E29207970E04315D
[-] 2008-04-14 00:11 62464 3D4E199942E29207970E04315D
[-] 2004-08-04 04:56 77312 E3CFCCDDA4EDD1D0DC9168B2E1
[-] 2008-04-14 00:11 77824 A06CE3399D16DB864F55FAEB1F
[-] 2008-04-14 00:11 77824 A06CE3399D16DB864F55FAEB1F
[-] 2006-10-19 20:07 249344 1418A3A6E76E5A2E3F5E43866E
[-] 2008-04-14 00:12 249856 3CB78C17BB664637787C9A1C98
[-] 2008-04-14 00:12 249856 3CB78C17BB664637787C9A1C98
[-] 2008-06-20 17:46 245248 832E4DD8964AB7ACC880B2837C
[-] 2008-06-20 17:43 245248 FCEE5FCB99F7C724593365C706
[-] 2008-06-20 17:36 245248 1DFCA7713EA5A70D5D93B436AE
[-] 2008-04-14 00:12 245248 B4138E99236F0F57D4CF49BAE9
[-] 2004-08-04 04:56 245248 4E74AF063C3271FBEA20DD940C
[-] 2008-04-14 00:12 245248 B4138E99236F0F57D4CF49BAE9
[-] 2008-06-20 17:46 245248 832E4DD8964AB7ACC880B2837C
[-] 2008-06-20 17:46 245248 832E4DD8964AB7ACC880B2837C
[-] 2006-10-19 20:10 197632 3516D8A18B36784B1005B950B8
[-] 2008-04-14 00:12 198144 13E67B55B3ABD7BF3FE7AAE5A0
[-] 2008-04-14 00:12 198144 13E67B55B3ABD7BF3FE7AAE5A0
[-] 2008-07-07 20:26 253952 D4991D98F2DB73C60D042F1AEF
[-] 2008-07-07 20:23 253952 F17F6226BDC0CD5F0BEF0DAF84
[-] 2008-07-07 20:06 253952 A4AB3DCA4A383F0DF4988ABDEB
[-] 2008-04-14 00:11 246272 19A799805B24990867B00C120D
[-] 2006-10-19 20:09 243200 95F5FEA4C6DE2C3F28784D0DCC
[-] 2008-04-14 00:11 246272 19A799805B24990867B00C120D
[-] 2008-07-07 20:26 253952 D4991D98F2DB73C60D042F1AEF
[-] 2008-07-07 20:26 253952 D4991D98F2DB73C60D042F1AEF
[-] 2004-08-04 04:56 170496 92BDF74F12D6CBEC43C94D4B7F
[-] 2008-04-14 00:12 171008 3805DF0AC4296A34BA4BF93B34
[-] 2008-04-14 00:12 171008 3805DF0AC4296A34BA4BF93B34
[-] 2004-08-04 04:56 13824 49911DD39E023BB6C45E4E436C
[-] 2008-04-14 00:12 13824 F92E1076C42FCD6DB3D72D8CFE
[-] 2008-04-14 00:12 13824 F92E1076C42FCD6DB3D72D8CFE
[-] 2004-08-04 04:56 435200 B62F29C00AC55A761B2E45877D
[-] 2008-04-14 00:12 435200 156F64A3345BD23C600655FB4D
[-] 2008-04-14 00:12 435200 156F64A3345BD23C600655FB4D
[-] 2004-08-04 04:56 89088 44DB7A9BDD2FB58747D123FBF1
[-] 2008-04-14 00:12 88576 AD188BE7BDF94E8DF4CA0A55C0
[-] 2008-04-14 00:12 88576 AD188BE7BDF94E8DF4CA0A55C0
[-] 2004-08-04 04:56 1580544 30A609E00BD1D4FFC49D6B5A43
[-] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D
[-] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D
[-] 2004-08-04 04:56 190976 92360854316611F6CC47161221
[-] 2008-04-14 00:12 192512 0A9A7365A1CA4319AA7C1D6CD8
[-] 2008-04-14 00:12 192512 0A9A7365A1CA4319AA7C1D6CD8
[-] 2004-08-04 04:56 59904 3151427DB7D87107D1C5BE58FA
[-] 2008-04-14 00:12 59904 5B19B557B0C188210A56A6B699
[-] 2008-04-14 00:12 59904 5B19B557B0C188210A56A6B699
[-] 2004-08-04 04:56 71680 4B8D61792F7175BED48859CC18
[-] 2008-04-14 00:12 71680 0A5679B3714EDAB99E357057EE
[-] 2008-04-14 00:12 71680 0A5679B3714EDAB99E357057EE
[-] 2007-02-05 20:17 185344 ACA5D98663D879C6BAAFCEA7E2
[-] 2008-04-14 00:12 185856 1EBAFEB9A3FBDC41B8D9C7F0F6
[-] 2008-04-14 00:12 185856 1EBAFEB9A3FBDC41B8D9C7F0F6
[-] 2006-12-19 21:50 135168 53D9184A21C5CBF600D918E51E
[-] 2008-04-14 00:12 135168 1926899BF9FFE2602B63074971
[-] 2008-04-14 00:12 135168 1926899BF9FFE2602B63074971
.
((((((((((((((((((((((((((
.
+ 2009-08-19 19:06 . 2009-08-19 19:06 8192 c:\windows\ERUNT\SDFIX\Use
- 2009-08-19 16:19 . 2009-08-19 16:19 8192 c:\windows\ERUNT\SDFIX\Use
+ 2009-08-19 19:06 . 2009-08-19 19:06 1028096 c:\windows\ERUNT\SDFIX\Use
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"ctfmon.exe"="c:\windows\s
[HKEY_LOCAL_MACHINE\SOFTWA
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712]
"RoxioDragToDisc"="c:\prog
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInS
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 52840]
"vptray"="c:\progra~1\SYMA
"Client Access Service"="c:\program files\IBM\Client Access\cwbsvstr.exe" [2005-06-08 20530]
"Client Access Help Update"="c:\program files\IBM\Client Access\cwbinhlp.exe" [2005-06-08 24626]
"Client Access Check Version"="c:\program files\IBM\Client Access\cwbckver.exe" [2005-06-08 45106]
"Client Access Express Welcome"="c:\program files\IBM\Client Access\cwbwlwiz.exe" [2005-06-08 20480]
"Client Access PC5250 Sound"="c:\program files\IBM\Client Access\Emulator\pcssnd.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe
"JobHisInit"="c:\program files\RDS\RMClient\JobHisI
"MplSetUp"="c:\program files\RDS\RMClient\MplSetU
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\reals
"BlackBerryAutoUpdate"="c:
"RoxWatchTray"="c:\program
"UnlockerAssistant"="c:\pr
[hkey_local_machine\softwa
"{5AE067D3-9AFB-48E0-853A-
[HKEY_LOCAL_MACHINE\softwa
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SAS
[HKEY_LOCAL_MACHINE\softwa
2008-12-17 14:34 46392 ----a-w- c:\program files\Citrix\GoToAssist Express Customer\136\g2ax_winlogon
[HKEY_LOCAL_MACHINE\softwa
2008-10-20 19:58 87352 ----a-w- c:\windows\system32\LMIini
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
"c:\\WINDOWS\\system32\\sp
[HKLM\~\services\sharedacc
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22
R2 gupdate1c9a5f289928a3c;Goo
R3 GoToAssist Express Customer;GoToAssist Express Customer;c:\program files\Citrix\GoToAssist Express Customer\136\g2ax_service.
R3 HBMW;HBMW;c:\docume~1\dave
R3 SASENUM;SASENUM;c:\program
R4 LMIRfsClientNP;LMIRfsClien
S1 SASDIFSV;SASDIFSV;c:\progr
S1 SASKUTIL;SASKUTIL;c:\progr
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.s
S2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32
S2 SavRoam;SavRoam;c:\program
S2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\Intel\AMT\UNS.exe [2007-06-12 2521880]
S3 EraserUtilRebootDrv;Eraser
[HKEY_LOCAL_MACHINE\softwa
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
2009-08-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google
2009-08-19 c:\windows\Tasks\GoogleUpd
- c:\program files\Google\Update\Google
2009-08-19 c:\windows\Tasks\GoogleUpd
- c:\program files\Google\Update\Google
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://nycourts.gov/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Offic
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
Trusted Zone: complusdata.com\citrix
TCP: {F4334BEC-3891-471B-8EE9-D
.
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-19 15:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\CW
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Symantec AntiVirus\DefWatch.exe\""
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\DLA\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\DLA\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\Driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\DLA\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\DLA\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\DLA\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\DLA\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\Driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\DLA\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\DLA\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\driv
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\Driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\Driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="c:\windows\s
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\Mi
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Citrix\GoToAssist Express Customer\136\g2ax_service.
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Google\Update\Google
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Google\Common\Google
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\docume~1\d
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%WINDIR%\PCH
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\Sy
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\Sy
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="c:\program files\HP\Digital Imaging\bin\hpqcxs08.dll"
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\Driv
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe"
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Common Files\InstallShield\Driver
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\windows\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%systemroot%\
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\progra~1
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\LogMeIn\x86\RaMaint.
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\window
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\program files\Intel\AMT\LMS.exe"
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\LogMeIn\x86\LogMeIn.
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe\""
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\sy
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\sy
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%systemroot%\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="c:\windows\s
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\windows\
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE\""
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="c:\windows\s
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\sy
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\Driv
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\sy
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\Driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="System32\Driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe\"
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Roxio\Digital Home 9\RoxioUpnpService9.exe\""
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLi
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMe
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWa
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Symantec AntiVirus\SavRoam.exe\""
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Common Files\Symantec Shared\SNDSrvc.exe\""
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\progra
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\sy
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Symantec AntiVirus\Rtvscan.exe\""
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\??\c:\window
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\SystemRoot\S
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\SystemRoot\S
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\sy
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\program files\Intel\AMT\UNS.exe"
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\SystemRoot\S
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%systemroot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\driv
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="c:\windows\s
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ImagePath"="c:\windows\sy
[HKEY_LOCAL_MACHINE\System
"ImagePath"="\"c:\program files\Windows Media Player\WMPNetwk.exe\""
[HKEY_LOCAL_MACHINE\System
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SYSTEMROOT%
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="c:\windows\s
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
"ImagePath"="system32\DRIV
[HKEY_LOCAL_MACHINE\System
"ImagePath"="%SystemRoot%\
[HKEY_LOCAL_MACHINE\System
"ServiceDll"="%SystemRoot%
[HKEY_LOCAL_MACHINE\System
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1180)
c:\program files\SUPERAntiSpyware\SAS
c:\program files\Citrix\GoToAssist Express Customer\136\g2ax_winlogon
c:\windows\system32\LMIini
c:\windows\system32\LMIRfs
B7A97EBC.x86.dll 35670000 53248 \\?\globalroot\Device\__ma
- - - - - - - > 'lsass.exe'(1236)
c:\program files\Bonjour\mdnsNSP.dll
- - - - - - - > 'explorer.exe'(744)
c:\program files\Unlocker\UnlockerHoo
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
c:\program files\Intel\AMT\atchksrv.e
c:\program files\Bonjour\mDNSResponde
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\LogMeIn\x86\LMIGuard
c:\program files\Research In Motion\BlackBerry\DesktopM
c:\program files\RDS\PLTBar.exe
c:\program files\PrintKey2000\Printke
c:\program files\RDS\RMClient\PMCTray
.
**************************
.
Completion time: 2009-08-19 15:37 - machine was rebooted
ComboFix-quarantined-files
ComboFix2.txt 2009-08-19 18:57
ComboFix3.txt 2009-08-19 18:47
Pre-Run: 140,658,302,976 bytes free
Post-Run: 140,647,583,744 bytes free
1014 --- E O F --- 2009-06-11 16:03
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Just like what jeff said, try going for LiveXP from Winbuilder (http://winbuilder.net/dow
Download Kaspersky Live CD from: ftp://ftp.downloads1.kaspe
Connect the PC to an ethernet connection for Kaspersky to update its definitions (it cannot use wireless i believe).
I haven't analyze the logs yet.... the rootkit is showing in the log... but I need to check what files are patched.
Can I ask you to also run Rootrepeal and this other tool and post the logs plese?
1. Download RootRepeal from the following location and save it to your desktop.
Zip Mirrors (Recommended)
Primary Mirror
http://rootrepeal.go
Se
http://ad13.geekstog
Rar Mirrors - Only if you know what a RAR is and can extract it.
Primary Mirror:
http://ad13.geeksto
Secondary
http://ad13.geeksto
Extract RootRepeal.exe from the archive.
Open RootRepeal on your desktop.
Click the "Report" tab.
Click the "Scan" button.
Check all seven boxes:
o Drivers
o Files
o Processes
o SSDT
o Stealth Objects
o Hidden Services
o Shadow SSDT
Push Yes
Check the box for your main system drive (Usually C:), and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the "Save Report" button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
Please download this tool and run it.
http://ad13.geekstogo.c
It will create a file "Win32kDiag.txt" on the desktop. Please post the result here.
As u can use spybot or Malwarebytes' Anti-Malware scan ur computer.
Spybot
http://www.safer-networkin
Malwarebytes' Anti-Malware
http://www.malwarebytes.or
Sorry I didn't see the last 2 post, but I already fixed it last night.
I agree that wiping the driving and starting fresh is the only way to make sure the virus is 100% gone. I was looking to fix it so I can learn more and quite frankly I want to defeat these virus without having to succumb to them by having to wipe the system and reinstall everything.
I already had a bootable cd but the computer blue screened with them.
Here's how I cleaned it for others looking for a solution.
I took out the hard drive and put it into another computer and cleaned it by running malwarebytes and gmer. Gmer's MBR.exe didn't show a mbr virus. Once back in the computer I had to do a repair install of windows and some update. I ran scans with gmer and malwarebytes and it came out clean. I also checked processes with process explorer from sysinternals and don't see it anymore. I can't be positive it is 100% clean so I'll keep an eye on it and if it comes back I'll have to wipe the drive.
Business Accounts
Answer for Membership
by: Jeff_RodgersPosted on 2009-08-19 at 12:48:54ID: 25136601
I would never trust a PC that has been infected with a root kit. Rootkits can run at the hardware layer below the Operating system and as such you can never tell whether its completely gone or not.
I would consider the hardware compromised, blow it away using a boot disk or LiveCD OS and completely overwrite the drive before using it again.