Undetectable virus, cannot run antivirus or antispyware apps
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16319 Posted 10-29-2009 2:58 (GMT +1) Hello DULBARK and welcome
and download Win32kDiag.exe directly to your Desktop
Go to Start - Run, type cmd (and press OK). At the prompt type or copy/paste the following, pressing Enter after:cd\ win32kdiag -r -f Once that completes press any key to finish the scan. Post the new Win32kDiag.txt log with your next reply (it should be located on the desktop). If by chance you cannot run the command window steps ->
Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK.
"%userprofile%\desktop\win32kdiag.exe" -f -r
When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here, along with a Gmer log.
and download the installer for Gmer to your desktop, then click that file to run Gmer. If on it's opening scan Gmer locates items shown in red or indicates "hidden " or "rootkit ", stop there, and click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please. We don't want any crashes just from taking an initial look at things. If not, then click on Scan (before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan). When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.
You can break logs into parts and use separate posts here when replying and posting the log files, if needed.
Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.
Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16319 Posted 10-29-2009 4:53 (GMT +1) Please copy and paste the logs -
You can break logs into parts and use separate posts here when replying and posting the log files, if needed.
Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.
Back to Top
DULBARK New Member Date Joined Oct 2009 Total Posts : 8 Posted 10-29-2009 5:07 (GMT +1) Please find the win32kdiag log :- Running from: C:\Documents and Settings\Administrator\desktop\win32kdiag.exe Log file at : C:\Documents and Settings\Administrator\Desktop\Win32kDiag.txt Removing all found mount points. Attempting to reset file permissions. WARNING: Could not get backup privileges! Searching 'C:\WINDOWS'... Found mount point : C:\WINDOWS\addins\addins Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\addins\addins Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP11D.tmp\ZAP11D.tmp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP11D.tmp\ZAP11D.tmp Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP17.tmp\ZAP17.tmp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP17.tmp\ZAP17.tmp Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP196.tmp\ZAP196.tmp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP196.tmp\ZAP196.tmp Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2B.tmp\ZAP2B.tmp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2B.tmp\ZAP2B.tmp Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4F.tmp\ZAP4F.tmp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4F.tmp\ZAP4F.tmp Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC.tmp\ZAPC.tmp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC.tmp\ZAPC.tmp Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPF3.tmp\ZAPF3.tmp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPF3.tmp\ZAPF3.tmp Found mount point : C:\WINDOWS\assembly\temp\temp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\assembly\temp\temp Found mount point : C:\WINDOWS\assembly\tmp\tmp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\assembly\tmp\tmp Found mount point : C:\WINDOWS\Config\Config Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Config\Config Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Connection Wizard\Connection Wizard Found mount point : C:\WINDOWS\ftpcache\ftpcache Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\ftpcache\ftpcache Found mount point : C:\WINDOWS\ime\imejp\applets\applets Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\ime\imejp\applets\applets Found mount point : C:\WINDOWS\ime\imejp98\imejp98 Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\ime\imejp98\imejp98 Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729 Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729 Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729 Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729 Found mount point : C:\WINDOWS\Installer\{1219497F-FA96-4D8E-9571-9C27A2A66B38}\{1219497F-FA96-4D8E-9571-9C27A2A66B38} Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Installer\{1219497F-FA96-4D8E-9571-9C27A2A66B38}\{1219497F-FA96-4D8E-9571-9C27A2A66B38} Found mount point : C:\WINDOWS\Installer\{548EAC70-EE00-11DD-908C-005056806466}\{548EAC70-EE00-11DD-908C-005056806466} Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Installer\{548EAC70-EE00-11DD-908C-005056806466}\{548EAC70-EE00-11DD-908C-005056806466} Found mount point : C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81200000003}\{AC76BA86-7AD7-1033-7B44-A81200000003} Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81200000003}\{AC76BA86-7AD7-1033-7B44-A81200000003} Found mount point : C:\WINDOWS\Installer\{AC76BA86-7AD7-5464-3428-800000000003}\{AC76BA86-7AD7-5464-3428-800000000003} Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Installer\{AC76BA86-7AD7-5464-3428-800000000003}\{AC76BA86-7AD7-5464-3428-800000000003} Found mount point : C:\WINDOWS\java\trustlib\trustlib Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\java\trustlib\trustlib Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files Found mount point : C:\WINDOWS\msapps\msinfo\msinfo Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\msapps\msinfo\msinfo Found mount point : C:\WINDOWS\PCHealth\ERRORREP\QHEADLES\QHEADLES Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PCHealth\ERRORREP\QHEADLES\QHEADLES Found mount point : C:\WINDOWS\PCHealth\ERRORREP\QSIGNOFF\QSIGNOFF Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PCHealth\ERRORREP\QSIGNOFF\QSIGNOFF Found mount point : C:\WINDOWS\PCHealth\HelpCtr\BATCH\BATCH Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\BATCH\BATCH Found mount point : C:\WINDOWS\PCHealth\HelpCtr\Config\CheckPoint\CheckPoint Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\Config\CheckPoint\CheckPoint Found mount point : C:\WINDOWS\PCHealth\HelpCtr\Config\News\News Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\Config\News\News Found mount point : C:\WINDOWS\PCHealth\HelpCtr\HelpFiles\HelpFiles Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\HelpFiles\HelpFiles Found mount point : C:\WINDOWS\PCHealth\HelpCtr\InstalledSKUs\InstalledSKUs Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\InstalledSKUs\InstalledSKUs Found mount point : C:\WINDOWS\PCHealth\HelpCtr\System\DFS\DFS Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\System\DFS\DFS Found mount point : C:\WINDOWS\PCHealth\HelpCtr\System_OEM\System_OEM Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\System_OEM\System_OEM Found mount point : C:\WINDOWS\PCHealth\HelpCtr\Temp\Temp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\Temp\Temp Found mount point : C:\WINDOWS\PIF\PIF Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\PIF\PIF Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Registration\CRMLog\CRMLog Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded Found mount point : C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\backup\backup Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\backup\backup Found mount point : C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\backup\backup Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\backup\backup Found mount point : C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\backup\backup Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\backup\backup Found mount point : C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\backup\backup Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\backup\backup Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment Cannot access: C:\WINDOWS\system32\drivers\sfi.dat Attempting to restore permissions of : C:\WINDOWS\system32\drivers\sfi.dat 2009-10-29 14:27:16 1474832 C:\WINDOWS\system32\drivers\sfi.dat () Cannot access: C:\WINDOWS\system32\dumprep.exe Attempting to restore permissions of : C:\WINDOWS\system32\dumprep.exe Cannot access: C:\WINDOWS\system32\eventlog.dll Attempting to restore permissions of : C:\WINDOWS\system32\eventlog.dll 2004-08-04 07:56:42 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (Microsoft Corporation) 2008-04-14 00:11:53 56320 C:\WINDOWS\eventlog.dll (Microsoft Corporation) 2008-04-14 00:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Microsoft Corporation) 2008-04-14 00:11:53 61952 C:\WINDOWS\system32\eventlog.dll () 2008-04-14 00:11:53 56320 C:\WINDOWS\system32\logevent(2).dll (Microsoft Corporation) 2008-04-14 00:11:53 56320 C:\WINDOWS\system32\logevent.dll (Microsoft Corporation) Found mount point : C:\WINDOWS\Temp\ProdID\bases\bases Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\Temp\ProdID\bases\bases Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp Mount point destination : \Device\__max++>\^ Removing mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp Finished! Back to Top
DULBARK New Member Date Joined Oct 2009 Total Posts : 8 Posted 10-29-2009 5:08 (GMT +1) Here is the GMERlog. GMER 1.0.15.15163 - http://www.gmer.net Rootkit scan 2009-10-29 15:01:57 Windows 5.1.2600 Service Pack 3 Running: 3dvke68h.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\axldypod.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAdjustPrivilegesToken [0xB55B3D46] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwClose [0xB53EAA00] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwConnectPort [0xB55B3250] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateFile [0xB55B38EA] SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) ZwCreateKey [0xBABE9800] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreatePort [0xB55B3132] SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xBA5A4282] SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xBA5A4474] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateSection [0xB53EB340] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xB53EAF90] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateThread [0xB53EBC60] SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) ZwDeleteKey [0xBABE9A00] SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) ZwDeleteValueKey [0xBABE9BE0] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwDuplicateObject [0xB53EAB60] SSDT spsb.sys ZwEnumerateKey [0xBA6C5CA4] SSDT spsb.sys ZwEnumerateValueKey [0xBA6C6032] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwLoadDriver [0xB53E8F80] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwMakeTemporaryObject [0xB55B34D4] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) Z!!!enFile [0xB55B3B2E] SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) Z!!!enKey [0xBABE9900] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) Z!!!enProcess [0xB53EA520] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) Z!!!enSection [0xB53EB170] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) Z!!!enThread [0xB55B2902] SSDT spsb.sys ZwQueryKey [0xBA6C610A] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwQuerySystemInformation [0xB53EB910] SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) ZwQueryValueKey [0xBABE9CC0] SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xBA5B6422] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRequestWaitReplyPort [0xB55B49F0] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwResumeThread [0xB53EBC10] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSecureConnectPort [0xB55B4C72] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSetContextThread [0xB53EBF90] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSetInformationFile [0xB53EC560] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSetSecurityObject [0xB53E7C40] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSystemInformation [0xB55B5084] SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) ZwSetValueKey [0xBABE9AF0] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwShutdownSystem [0xB55B346E] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSuspendThread [0xB53EBBC0] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSystemDebugControl [0xB53E92F0] SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xBA5A3F32] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateThread [0xB55B2ECA] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwWriteVirtualMemory [0xB53EAA20] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[284] [0xB53E6D40] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[285] [0xB53E6D50] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[286] [0xB53E6D60] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[287] [0xB53E6D80] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[288] [0xB53E6DA0] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[289] [0xB53E6DD0] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[290] [0xB53E6DE0] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[291] [0xB53E6E00] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[292] [0xB53E6E10] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[293] [0xB53E6ED0] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[294] [0xB53E6FA0] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[295] [0xB53E6FE0] SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[296] [0xB53E7020] INT 0x62 ? 8A954BF8 INT 0x63 ? 8A954BF8 INT 0x73 ? 8A5D6BF8 INT 0x82 ? 8A954BF8 INT 0x94 ? 8A5D6BF8 INT 0xA4 ? 8A5D6BF8 Code \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) FsRtlCheckLockForReadAccess Code \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) IoIsOperationSynchronous ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804EAF84 5 Bytes JMP B53EC980 \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) .text ntkrnlpa.exe!IoIsOperationSynchronous 804EF912 5 Bytes JMP B53ECE80 \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) .text ntkrnlpa.exe!ZwCallbackReturn + 2C58 805044F4 4 Bytes JMP 62B55B38 .text ntkrnlpa.exe!ZwCallbackReturn + 2CD4 80504570 2 Bytes [5A, 2A] .text ntkrnlpa.exe!ZwCallbackReturn + 2D68 80504604 2 Bytes [D4, 34] {AAM 0x34} ? spsb.sys The system cannot find the file specified. ! .text USBPORT.SYS!DllUnload B8AFF8AC 5 Bytes JMP 8A5D61D8 .text azqm89s4.SYS B8A78386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...] .text azqm89s4.SYS B8A783AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...] .text azqm89s4.SYS B8A783C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH} .text azqm89s4.SYS B8A783C9 1 Byte [30] .text azqm89s4.SYS B8A783C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL} .text ... ? win32k.sys:1 The system cannot find the file specified. ! ? win32k.sys:2 The system cannot find the file specified. ! ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 0040FB50 C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe (COMODO Internet Security/COMODO) .text C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] USER32.dll!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\5A354CC0.x86.dll .text C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\5A354CC0.x86.dll .text C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\5A354CC0.x86.dll .text C:\WINDOWS\system32\svchost.exe[984] USER32.dll!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\5A354CC0.x86.dll .text C:\WINDOWS\system32\svchost.exe[984] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\5A354CC0.x86.dll .text C:\WINDOWS\system32\svchost.exe[984] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\5A354CC0.x86.dll .text C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 0050DCB0 C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [BA6A8042] spsb.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [BA6A813E] spsb.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [BA6A80C0] spsb.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [BA6A8800] spsb.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [BA6A86D6] spsb.sys IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!READ_PORT_UCHAR] 1C8D9E88 IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KeGetCurrentIrql] 9E880000 IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KfRaiseIrql] 00001CA9 IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KfLowerIrql] 0E798366 IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!HalGetInterruptVector] 74AAB000 IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!HalTranslateBusAddress] 8186C636 IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KfReleaseSpinLock] 1C8386C6 IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000 IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!READ_PORT_USHORT] 001C8E86 IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200 IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CAA IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[WMILIB.SYS!WmiSystemControl] 8800001C IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB19E IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [BA6B7E9C] spsb.sys IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO) ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\5A354CC0.x86.dll IAT C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\5A354CC0.x86.dll IAT C:\WINDOWS\system32\svchost.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\5A354CC0.x86.dll IAT C:\WINDOWS\system32\svchost.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\5A354CC0.x86.dll IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [00617E10] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\IPHLPAPI.DLL [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\IPHLPAPI.DLL [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!DeleteObject] [00616EA0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [00617E10] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [00617DC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AdjustWindowRectEx] [00617B60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [00617280] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSystemMetrics] [00617930] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [00616E50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [00617310] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!RegisterClassW] [00617870] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [00616EE0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!FillRect] [00617C70] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DrawFrameControl] [00617CE0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DrawEdge] [00617CC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SystemParametersInfoW] [00617A50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetScrollInfo] [006170D0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!CallWindowProcW] [00617140] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetScrollInfo] [00616FC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!DeleteObject] [00616EA0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [00617DC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [00617E10] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [00617280] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [00617310] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [00616E50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!RegisterClassA] [006177B0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!RegisterClassW] [00617870] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SystemParametersInfoW] [00617A50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcW] [00617140] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcA] [006171E0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSystemMetrics] [00617930] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [GDI32.dll!DeleteObject] [00616EA0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00617E10] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [00617DC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SystemParametersInfoW] [00617A50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetSystemMetrics] [00617930] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetSysColor] [00616E50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CallWindowProcW] [00617140] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!RegisterClassW] [00617870] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DefWindowProcW] [00617310] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [00617DC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [00617E10] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [USER32.dll!GetSystemMetrics] [00617930] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 8A9531F8 AttachedDevice \FileSystem\Ntfs \Ntfs CFRPD.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) AttachedDevice \FileSystem\Ntfs \Ntfs CFRPD.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.) AttachedDevice \FileSystem\Ntfs \Ntfs klif.sys (spuper-ptor/Kaspersky Lab) AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO) Device \Driver\usbuhci \Device\USBPDO-0 8A5D51F8 Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A8E41F8 Device \Driver\dmio \Device\DmControl\DmConfig 8A8E41F8 Device \Driver\dmio \Device\DmControl\DmPnP 8A8E41F8 Device \Driver\dmio \Device\DmControl\DmInfo 8A8E41F8 Device \Driver\usbuhci \Device\USBPDO-1 8A5D51F8 Device \Driver\usbuhci \Device\USBPDO-2 8A5D51F8 Device \Driver\usbuhci \Device\USBPDO-3 8A5D51F8 Device \Driver\PCI_PNP9996 \Device\00000047 spsb.sys AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO) Device \Driver\Ftdisk \Device\HarddiskVolume1 8A9551F8 Device \Driver\sptd \Device\1170786246 spsb.sys Device \Driver\Cdrom \Device\CdRom0 8A5961F8 Device \Driver\Cdrom \Device\CdRom1 8A5961F8 Device \Driver\atapi \Device\Ide\IdePort0 [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort2 [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort3 [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\Cdrom \Device\CdRom2 8A5961F8 Device \Driver\NetBT \Device\NetBt_Wins_Export 8A5321F8 Device \Driver\NetBT \Device\NetbiosSmb 8A5321F8 AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO) AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO) Device \Driver\usbuhci \Device\USBFDO-0 8A5D51F8 Device \Driver\usbuhci \Device\USBFDO-1 8A5D51F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A3301F8 Device \Driver\usbuhci \Device\USBFDO-2 8A5D51F8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A3301F8 Device \Driver\usbuhci \Device\USBFDO-3 8A5D51F8 Device \Driver\Ftdisk \Device\FtControl 8A9551F8 Device \Driver\azqm89s4 \Device\Scsi\azqm89s41Port4Path0Target1Lun0 8A5911F8 Device \Driver\azqm89s4 \Device\Scsi\azqm89s41 8A5911F8 Device \Driver\azqm89s4 \Device\Scsi\azqm89s41Port4Path0Target0Lun0 8A5911F8 Device \FileSystem\Cdfs \Cdfs 8A4201F8 ---- Processes - GMER 1.0.15 ---- Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [884] 0x35670000 Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe [944] 0x35670000 Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [984] 0x35670000 Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1108] 0x35670000 Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1136] 0x35670000 Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [1204] 0x35670000 Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\Program Files\Java\jre6\bin\jqs.exe [1404] 0x35670000 Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\lxctcoms.exe [1444] 0x35670000 Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [1912] 0x35670000 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x67 0x5B 0x24 0xC1 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC8 0x20 0x40 0xF2 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF7 0xC2 0xDD 0x4D ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3B 0x22 0x9E 0x27 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x98 0xA2 0xAE 0xF2 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x67 0x5B 0x24 0xC1 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC8 0x20 0x40 0xF2 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF7 0xC2 0xDD 0x4D ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3B 0x22 0x9E 0x27 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x98 0xA2 0xAE 0xF2 ... ---- EOF - GMER 1.0.15 ---- Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16319 Posted 10-29-2009 6:57 (GMT +1) Seems you have some missing or infected system files, so let´s see if combofix can replace them ->
Please download Combofix from:
And save to the desktop al alg.exe
Close all other browser windows.
Double-click on the combofix icon found on your desktop.
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.
When finished, it will produce a logfile located at C:\combofix.txt.
Post the contents of that log in your next reply
The logs will be reasonably large so you may have to divide them into sections and make several posts to post them.
Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.
Back to Top
DULBARK New Member Date Joined Oct 2009 Total Posts : 8 Posted 10-29-2009 9:28 (GMT +1) I have run Combofix here is part one. ComboFix 09-10-28.08 - Administrator 29/10/2009 18:19.1.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2047.1319 [GMT 0:00] Running from: c:\documents and settings\Administrator\Desktop\alg.exe.exe AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE} AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B} AV: Outpost Security Suite Pro *On-access scanning disabled* (Updated) {8A20CA2A-9E02-4A64-923B-0A38208EB7FD} AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6} FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} FW: Outpost Security Suite Pro *enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD} WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ADS - WINDOWS: deleted 24 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Administrator\Application Data\inst.exe c:\windows\system32\infopsvEV67s.dll Infected copy of c:\windows\system32\eventlog.dll was found and disinfected Restored copy from - c:\windows\eventlog.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED} ((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-29 ))))))))))))))))))))))))))))))) . 2009-10-29 17:10 . 2009-10-29 17:10 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys 2009-10-29 17:09 . 2009-10-29 17:53 -------- d-----w- c:\documents and settings\Administrator\.housecall6.6 2009-10-29 15:53 . 2009-10-29 15:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\Avira 2009-10-29 15:51 . 2009-10-29 15:49 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys 2009-10-29 15:51 . 2009-10-29 15:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys 2009-10-29 15:51 . 2009-10-29 15:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys 2009-10-29 15:51 . 2009-10-29 15:51 -------- d-----w- c:\program files\Avira 2009-10-29 14:15 . 2008-12-22 17:03 33512 ----a-w- c:\windows\system32\drivers\REGRUNRM.SYS 2009-10-29 14:15 . 2008-12-22 17:03 55184 ----a-w- c:\windows\system32\drivers\RegRunFM.SYS 2009-10-29 14:09 . 2009-09-10 14:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-29 14:09 . 2009-10-29 14:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-29 14:09 . 2009-09-10 14:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-29 14:04 . 2009-10-29 14:04 -------- d-----w- c:\windows\RestoreSafeDeleted 2009-10-29 13:42 . 2009-10-29 13:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\Regrun 2009-10-29 13:41 . 2009-10-29 13:49 29584 ----a-w- c:\windows\system32\drivers\regguard.sys 2009-10-29 13:41 . 2009-10-29 13:41 2 --shatr- c:\windows\winstart.bat 2009-10-29 13:41 . 2009-10-29 13:41 34760 ----a-w- c:\windows\system32\drivers\Partizan.sys 2009-10-29 13:41 . 2009-10-29 13:41 32480 ----a-w- c:\windows\system32\Partizan.exe 2009-10-29 13:38 . 2008-12-22 17:04 444128 ----a-w- c:\windows\RunGuard.exe 2009-10-29 13:38 . 2008-12-22 17:04 20192 ----a-w- c:\windows\WinBait.exe 2009-10-29 13:38 . 2009-10-29 13:38 -------- d-----w- c:\program files\Greatis 2009-10-29 12:54 . 2009-10-29 12:54 -------- d-----w- C:\rsit 2009-10-29 12:11 . 2008-02-25 11:44 603176 ----a-w- C:\autoruns.exe 2009-10-29 12:11 . 2008-02-25 11:44 513064 ----a-w- C:\autorunsc.exe 2009-10-28 01:09 . 2009-10-29 18:36 28704 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-10-28 01:09 . 2009-10-29 18:35 4066080 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-28 00:41 . 2009-10-28 10:48 -------- d-----w- c:\program files\Common Files\ParetoLogic 2009-10-28 00:41 . 2009-10-28 10:48 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic 2009-10-28 00:40 . 2009-10-28 00:40 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Downloaded Installations 2009-10-27 22:40 . 2009-10-27 22:40 19207 ----a-w- C:\MGlogs.zip 2009-10-27 18:48 . 2009-10-27 23:10 -------- d-----w- C:\MGtools 2009-10-27 18:41 . 2009-10-27 18:41 -------- d-----w- c:\windows\Junction 2009-10-27 18:41 . 2009-10-27 18:41 95616 ----a-w- c:\windows\junction.exe 2009-10-27 18:40 . 2009-10-27 18:36 46375 ----a-w- c:\windows\Junction.zip 2009-10-27 18:28 . 2009-10-27 18:28 47616 ----a-w- C:\Win32kDiag.exe 2009-10-27 18:11 . 2009-10-27 18:11 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure 2009-10-27 15:32 . 2009-10-27 15:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitDefender 2009-10-27 15:17 . 2009-10-27 15:18 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2009-10-27 14:35 . 2009-10-27 14:35 132 ----a-w- c:\windows\system32\rezumatenoi.dat 2009-10-27 14:02 . 2009-10-27 14:02 4 ----a-w- c:\windows\system32\aspdict-en.dat 2009-10-27 14:02 . 2009-10-27 14:02 16 ----a-w- c:\windows\system32\asdict.dat 2009-10-27 13:36 . 2009-10-27 13:36 -------- d-----w- C:\aaavault 2009-10-27 13:26 . 2009-10-29 15:51 -------- d-----w- c:\windows\LastGood 2009-10-27 13:25 . 2009-10-27 14:36 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender 2009-10-27 13:25 . 2009-10-27 13:25 -------- d-----w- c:\program files\BitDefender 2009-10-27 13:21 . 2009-10-27 14:36 -------- d-----w- c:\program files\Common Files\BitDefender 2009-10-27 01:36 . 2009-10-27 01:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files 2009-10-26 12:01 . 2009-10-29 12:54 -------- d-----w- c:\program files\Trend Micro 2009-10-26 11:56 . 2008-04-14 00:11 56320 ------w- c:\windows\eventlog.dll 2009-10-26 10:26 . 2009-10-26 11:43 0 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\prvlcl.dat 2009-10-25 21:31 . 2009-10-26 17:09 -------- d-----w- C:\$AVG 2009-10-25 21:30 . 2009-10-26 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9 2009-10-25 20:36 . 2009-10-25 20:36 -------- d-----w- c:\documents and settings\Administrator\Application DataComodoGroup 2009-10-25 20:31 . 2009-10-25 20:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\ComodoGroup 2009-10-25 20:21 . 2009-10-25 20:21 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes 2009-10-25 20:20 . 2009-10-25 20:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-10-25 20:09 . 2009-10-25 20:11 -------- d-----w- c:\windows\BDOSCAN8 2009-10-25 20:09 . 2009-10-25 20:09 -------- d-----w- c:\windows\LastGood.Tmp 2009-10-25 17:32 . 2009-10-25 17:32 87104 ----a-w- c:\windows\system32\drivers\inspect.sys 2009-10-25 17:32 . 2009-10-25 17:32 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys 2009-10-25 17:32 . 2009-10-25 17:32 179792 ----a-w- c:\windows\system32\guard32.dll 2009-10-25 17:32 . 2009-10-25 17:32 132296 ----a-w- c:\windows\system32\drivers\cmdguard.sys 2009-10-25 10:28 . 2009-10-29 15:49 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-10-24 20:49 . 2009-10-29 16:32 0 ----a-r- c:\windows\win32k.sys 2009-10-24 20:48 . 2009-10-24 20:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Webroot 2009-10-24 20:48 . 2009-10-24 20:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\Webroot 2009-10-24 20:47 . 2009-10-24 20:47 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-10-24 20:47 . 2009-10-24 20:47 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\PC Tools 2009-10-24 20:47 . 2009-10-24 20:47 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Tools 2009-10-24 20:47 . 2009-10-24 20:47 -------- d-----w- c:\program files\Common Files\PC Tools 2009-10-24 20:46 . 2009-10-24 20:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2009-10-24 18:58 . 2009-10-24 19:30 -------- dc----w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} 2009-10-24 18:58 . 2009-10-24 19:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2009-10-22 14:29 . 2009-10-24 19:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\Webroot(2) 2009-10-21 18:18 . 2009-10-24 20:46 -------- d-----w- c:\program files\Common Files\PC Tools(2) 2009-10-21 18:03 . 2009-10-24 20:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater(2) 2009-10-20 18:51 . 2009-10-24 20:47 -------- d-----w- c:\program files\HangWord 2009-10-20 15:16 . 2009-10-29 16:10 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat 2009-10-20 09:16 . 2009-10-20 09:16 -------- d-----w- c:\program files\Vocabulary Wizard 67E 2009-10-19 15:02 . 2009-10-19 15:02 -------- d-----w- c:\program files\Interlex 2 2009-10-16 20:04 . 2009-10-16 20:04 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia 2009-10-16 20:04 . 2009-10-16 20:04 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Suite 2009-10-16 20:04 . 2009-10-16 20:04 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite 2009-10-16 19:39 . 2009-10-16 19:39 -------- d-----w- c:\program files\Common Files\PCSuite 2009-10-16 19:39 . 2009-10-16 19:39 -------- d-----w- c:\program files\Common Files\Nokia 2009-10-16 19:39 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys 2009-10-16 19:39 . 2009-10-16 19:39 -------- d-----w- c:\program files\PC Connectivity Solution 2009-10-16 19:38 . 2009-02-09 07:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll 2009-10-16 19:38 . 2009-10-16 19:39 -------- d-----w- c:\program files\Nokia 2009-10-16 19:37 . 2009-10-16 19:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations 2009-10-16 19:32 . 2009-10-29 15:20 -------- d-sh--w- c:\windows\ftpcache Back to Top
DULBARK New Member Date Joined Oct 2009 Total Posts : 8 Posted 10-29-2009 9:29 (GMT +1) Here is part two..... . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-29 18:33 . 2009-10-28 01:09 55460 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-10-29 18:33 . 2009-10-28 01:09 3692 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-10-29 15:51 . 2008-06-28 19:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira 2009-10-29 15:46 . 2008-06-30 15:08 -------- d-----w- c:\program files\Mozilla Thunderbird 2009-10-29 14:03 . 2008-06-30 19:20 -------- d-----w- c:\program files\Windows Live Mail desktop 2009-10-27 01:31 . 2008-12-10 15:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-10-27 01:30 . 2008-06-28 17:42 -------- d-----w- c:\program files\CCleaner 2009-10-26 22:40 . 2008-07-01 18:51 -------- d-----w- c:\program files\ProcessGuard 2009-10-25 20:26 . 2008-05-26 16:24 -------- d-----w- c:\program files\Comodo 2009-10-25 20:01 . 2009-06-14 23:57 -------- d-----w- c:\program files\Chandler1.0.3 2009-10-25 19:59 . 2008-12-10 15:14 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-10-25 18:06 . 2008-05-26 16:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo 2009-10-25 00:07 . 2008-06-28 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools 2009-10-24 20:46 . 2008-05-26 20:19 -------- d-----w- c:\program files\Google 2009-10-24 11:20 . 2008-05-26 20:37 -------- d-----w- c:\documents and settings\Administrator\Application Data\StarOffice8 2009-10-22 14:19 . 2009-03-10 10:51 164 ----a-w- c:\windows\install.dat 2009-10-22 13:51 . 2008-06-28 14:30 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-10-18 18:50 . 2008-07-07 15:09 -------- d-----w- c:\program files\Mozilla Sunbird 2009-10-16 19:39 . 2009-07-28 23:14 -------- d-----w- c:\program files\DIFX 2009-10-16 11:38 . 2009-07-28 23:11 -------- d-----w- c:\documents and settings\All Users\Application Data\LGMOBILEAX 2009-10-05 18:15 . 2009-02-24 14:47 -------- d-----w- c:\program files\lx_cats 2009-10-04 13:05 . 2002-03-25 20:02 12528 ----a-w- c:\windows\system32\drivers\secdrv.sys 2009-09-29 11:04 . 2009-09-29 11:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited 2009-09-24 09:15 . 2008-07-05 19:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype 2009-09-11 14:18 . 2002-08-29 03:41 136192 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-04 21:03 . 2001-08-23 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-09-03 13:52 . 2009-09-03 13:52 -------- d-----w- c:\program files\Patrick Computer Services 2009-08-29 08:08 . 2006-06-23 10:33 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-26 08:00 . 2002-08-29 03:41 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-05 11:41 . 2008-06-28 18:38 49512 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT 2009-08-05 09:01 . 2008-05-25 12:28 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-08-04 19:50 . 2009-08-04 19:50 56736 ----a-w- c:\windows\system32\drivers\CFRPD.sys 2009-08-04 15:13 . 2002-08-29 01:04 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-08-04 14:20 . 2002-08-29 01:04 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe 1999-02-15 18:25 . 1999-02-15 18:25 348 ----a-w- c:\program files\Europress KS3 ProductsKS3Maths.del 2009-09-13 22:10 . 2009-10-27 13:46 47104 ----a-w- c:\program files\mozilla firefox\components\FFComm.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IE Privacy Keeper"="c:\program files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" [2005-12-03 1015808] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "Regrun2"="c:\progra~1\Greatis\REGRUN~1\WatchDog.exe" [2008-12-22 384224] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TBPanel"="c:\program files\XpertVision\TBPanel.exe" [2008-01-29 2157064] "SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816] "SkyTel"="c:\windows\SkyTel.EXE" [2007-04-04 1822720] "RTHDCPL"="c:\windows\RTHDCPL.EXE" [2007-04-10 16126464] "nwiz"="c:\windows\system32\nwiz.exe" [2008-01-08 1626112] "NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2008-01-08 81920] "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2008-01-08 8523776] "EzPrint"="c:\program files\Lexmark 5400 Series\ezprint.exe" [2007-03-19 82864] "Lexmark 5400 Series Fax Server"="c:\program files\Lexmark 5400 Series\fm3032.exe" [2007-03-19 304048] "lxctmon.exe"="c:\program files\Lexmark 5400 Series\lxctmon.exe" [2007-03-19 291760] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "LXCTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll" [2006-11-21 106496] "COMODO Internet Security"="c:\program files\Comodo\COMODO Internet Security\cfp.exe" [2009-10-25 1799952] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "RegRun WinBait"="c:\windows\winbait.exe" [2008-12-22 20192] "@RegRunOnSecure"="c:\progra~1\Greatis\REGRUN~1\OnSecure.exe" [2008-12-22 61664] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-10-29 209153] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\Administrator\Start Menu\Programs\Startup\ OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{F552DDE6-2090-4bf4-B924-6141E87789A5}"= "c:\progra~1\Greatis\REGRUN~1\RRShell.dll" [2008-10-20 335943] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Spamihilator\\cdcc.exe"= "c:\\Program Files\\Spamihilator\\dccproc.exe"= "c:\\Program Files\\Spamihilator\\spamihilator.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "c:\\Program Files\\JetAudio\\JetAudio.exe"= "c:\\WINDOWS\\system32\\lxctcoms.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [x] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [x] R2 AntiVirUpgradeService;Avira Upgrade Service;c:\windows\TEMP\AVSETUP_4ae390b2\basic\avupgsvc.exe [x] R2 gupdate1c9abdd319dbaf4;Google Update Service (gupdate1c9abdd319dbaf4);c:\program files\Google\Update\GoogleUpdate.exe [x] R3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;c:\docume~1\ADMINI~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys [x] R3 FlashUSB;FlashUSB;c:\windows\system32\DRIVERS\FlashUSB.sys [2009-05-12 16896] R3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver;c:\docume~1\ADMINI~1\LOCALS~1\Temp\F-Secure\BlackLight\fsbldrv.sys [x] R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [x] R3 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [2009-10-29 34760] R3 QCNCE;QCNCE;c:\docume~1\ADMINI~1\LOCALS~1\Temp\QCNCE.exe [x] R3 RegGuard;RegGuard;c:\windows\system32\Drivers\regguard.sys [2009-10-29 29584] R3 REGRUNFM;REGRUNFM;c:\windows\system32\drivers\RegRunFM.SYS [2008-12-22 55184] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [x] R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [x] R3 XBLJB;XBLJB;c:\docume~1\ADMINI~1\LOCALS~1\Temp\XBLJB.exe [x] S0 CFRPD;CFRPD;c:\windows\System32\drivers\CFRPD.sys [2009-08-04 56736] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-04-03 130936] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2009-10-25 132296] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2009-10-25 25160] S2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [2009-10-29 194817] S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-10-29 108289] S2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2009-10-29 434945] Back to Top
DULBARK New Member Date Joined Oct 2009 Total Posts : 8 Posted 10-29-2009 9:35 (GMT +1) Now part three ......to complete the trilogy. --- Other Services/Drivers In Memory --- *NewlyCreated* - CLASSPNP_2 *NewlyCreated* - MBR *Deregistered* - CLASSPNP_2 *Deregistered* - mbr . Contents of the 'Scheduled Tasks' folder 2009-08-06 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.uk LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll Trusted Zone: google.co.uk\www Trusted Zone: live.com\by113w.bay113.mail Trusted Zone: microsoft.com\*.windowsupdate Trusted Zone: microsoft.com\update Trusted Zone: microsoft.com\windowsupdate Trusted Zone: windowsupdate.com\download DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\fii5c4qq.default\ FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:official FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll FF - plugin: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\fii5c4qq.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\Opera\program\plugins\np_gp.dll FF - plugin: c:\program files\Sun\StarOffice 8\program\npsoplugin.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - ORPHANS REMOVED - - - - HKCU-Run-COMODO livePCsupport - (no file) HKLM-Run-SClassWidget - (no file) Notify-avgrsstarter - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-29 18:36 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run LXCTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? scanning hidden files ... ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spie.sys >>UNKNOWN [0x8A902938]<< kernel: MBR read successfully user & kernel MBR OK Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net atapi.sys @ 0x0 0x0 bytes \Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xBA5DBB40 atapi.sys \Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xBA5DBB40 atapi.sys \Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xBA5DBB40 atapi.sys \Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xBA5DBB40 atapi.sys \Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xBA5DBB40 atapi.sys \Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xBA5DBB40 atapi.sys \Driver\atapi IRP hooks detected ! ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f9,b1,0c,4b,79,73,d1,45,a0,99,54,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f9,b1,0c,4b,79,73,d1,45,a0,99,54,\ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'lsass.exe'(668) c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll c:\program files\Avira\AntiVir Desktop\avsda.dll - - - - - - - > 'explorer.exe'(3044) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Comodo\COMODO Internet Security\cmdagent.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\lxctcoms.exe c:\windows\System32\nvsvc32.exe c:\windows\system32\RUNDLL32.EXE c:\program files\OpenOffice.org 3\program\soffice.exe c:\program files\OpenOffice.org 3\program\soffice.bin . ************************************************************************** . Completion time: 2009-10-29 18:49 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-29 18:48 Pre-Run: 198,970,920,960 bytes free Post-Run: 199,132,884,992 bytes free - - End Of File - - CC68D132562229073A12CFE54D224F63 Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16319 Posted 10-30-2009 6:03 (GMT +1) Great, combofix replace the infected file
"Infected copy of c:\windows\system32\eventlog.dll was found and disinfected Restored copy from - c:\windows\eventlog.dll"
Please tell how things are running now ?
Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.
Back to Top
DULBARK New Member Date Joined Oct 2009 Total Posts : 8 Posted 10-30-2009 8:57 (GMT +1) Here is some additional info: Before running Combofix I got a trial version of Avira working. Last week the free version picked up Trojan.Dropper/Gen but could not quarantine the file. When combofix was running the avira was deactivated but picked the file eventlog.dll and quarantined successfully. I then installed Malwarebytes and ran a scan this gave me another infected file which was Win32k.sys in the windows directory. After running a full system scan I also detected a file called A0221256.dll which I think was in the sytem restore part of the drive. Now my PC is runnning much better - but it seems to be very slow for a while after boot up, I'm guessing it's the security software on it. I am using Webroot at the moment / Comodo, but after this expereince need a zero day threat detector as I had downloaded some files last week which did not show a virus upon scan but this week after submission to comodo they gave an update the same day which verified a Trojan. The Webroot also detects this file now. Many thanks for your help......... I have over 20 years experience in business development....drop me a line anytime If I can return a (free) favour. Back to Top
Forum Information Currently it is Saturday, November 21, 2009 4:07 PM (GMT +1) There are a total of 73.034 posts in 17.116 threads. In the last 3 days there were 14 new threads and 71 reply posts. View Active Threads Who's Online This forum has 30334 registered members. Please welcome our newest member, sushil . 40 Guest(s), 0 Registered Member(s) are currently online. Details 5 Latest Threads