Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Undetectable virus, cannot run antivirus or antispyware apps
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Undetectable virus, cannot run antivirus or antispyware apps  
Forum Quick Jump
 
Vote Results :: 0 vote(s) total
0
YES - 0,0%
0
NO - 0,0%
0
SIMILAR - 0,0%

 
New Topic Post reply to : Undetectable virus, cannot run antivirus or antispyware apps Printable version of : Undetectable virus, cannot run antivirus or antispyware apps
[ << Previous Thread | Next Thread >> ]

DULBARK
New Member


Date Joined Oct 2009
Total Posts : 8
 
   Posted 10-29-2009 2:30 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Hi
I have a virus on my system that does not allow me to run antivirus programs.
Once an antivirus/antispyware program is installed and updated - then I try to run it most antivirus programs will terminate within seconds and if I try to run it I get the error message : "Windows cannot access the specified device , path or file. You may not have the appropriate permissions to access the item"

I also ran autoruns - whilst this was scanning I observed carefully a two files which were "e.exe" and "b.exe" before I go the chance to do anything the application terminated - and again I got the above error message when I tried to run autoruns again. This even happened in dos mode.

I have been able to run comodo antivirus - which of course does not detect the culprit. I was able to run hijack this, but this also terminated suddenly, and is no longer accessible. I have attached the log file.

I also ran rsit and the log file is attached. I seem to get the impression that whenever a program either accesses the virus or the area in the memory that the virus occupies the application is terminated with the above error message upon attempting to run the application again. I have now switched on DEP (data execution prevention) and since doing this cannot run an online scanner. With DEP on for essential windows services only - the system tends to hang.

Can you advise ?

File Attachment :
log.zip   4KB (application/zip)
This file has been downloaded 43 time(s).

File Attachment :
startuplist1.zip   4KB (application/zip)
This file has been downloaded 53 time(s).
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 10-29-2009 2:58 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Hello DULBARK and welcome smile
 
 
and download Win32kDiag.exe directly to your Desktop

Go to Start - Run, type cmd (and press OK). At the prompt type or copy/paste the following, pressing Enter after:

cd\
win32kdiag -r -f


Once that completes press any key to finish the scan. Post the new Win32kDiag.txt log with your next reply (it should be located on the desktop).

If by chance you cannot run the command window steps ->
Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK.
 
"%userprofile%\desktop\win32kdiag.exe" -f -r
 
When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here, along with a Gmer log.
 
 
and download the installer for Gmer to your desktop, then click that file to run Gmer.


If on it's opening scan Gmer locates items shown in red or indicates "hidden" or "rootkit", stop there, and click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please. We don't want any crashes just from taking an initial look at things.

If not, then click on Scan (before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan).

When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.
 
 
You can break logs into parts and use separate posts here when replying and posting the log files, if needed.


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

DULBARK
New Member


Date Joined Oct 2009
Total Posts : 8
 
   Posted 10-29-2009 4:15 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Hi Touch

Thanks for the assistance.
I've attached the files and followed the procedure you have given.


Additonal info (I am not sure if this will be useful to you)
Before I did all this I had run an application called RegRun.
This detected b.exe and also e.exe at re-boot.
I was given the option to delete these which I did, however upon installing malwarebytes (and running the program) after this deletion I got the same problem i.e. application was terminated within 10 seconds when initialising a scan, now I cannot access malwarebytes.

Thanks

File Attachment :
gmerlog.zip   5KB (application/zip)
This file has been downloaded 12 time(s).

File Attachment :
Win32kDiag.zip   2KB (application/zip)
This file has been downloaded 11 time(s).
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 10-29-2009 4:53 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Please copy and paste the logs -
 
 
You can break logs into parts and use separate posts here when replying and posting the log files, if needed.


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

DULBARK
New Member


Date Joined Oct 2009
Total Posts : 8
 
   Posted 10-29-2009 5:07 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Please find the win32kdiag log :-


Running from: C:\Documents and Settings\Administrator\desktop\win32kdiag.exe

Log file at : C:\Documents and Settings\Administrator\Desktop\Win32kDiag.txt

Removing all found mount points.

Attempting to reset file permissions.

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...



Found mount point : C:\WINDOWS\addins\addins

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\addins\addins

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP11D.tmp\ZAP11D.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP11D.tmp\ZAP11D.tmp

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP17.tmp\ZAP17.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP17.tmp\ZAP17.tmp

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP196.tmp\ZAP196.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP196.tmp\ZAP196.tmp

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2B.tmp\ZAP2B.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2B.tmp\ZAP2B.tmp

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4F.tmp\ZAP4F.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP4F.tmp\ZAP4F.tmp

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC.tmp\ZAPC.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC.tmp\ZAPC.tmp

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPF3.tmp\ZAPF3.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPF3.tmp\ZAPF3.tmp

Found mount point : C:\WINDOWS\assembly\temp\temp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\temp\temp

Found mount point : C:\WINDOWS\assembly\tmp\tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\tmp\tmp

Found mount point : C:\WINDOWS\Config\Config

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Config\Config

Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Found mount point : C:\WINDOWS\ftpcache\ftpcache

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ftpcache\ftpcache

Found mount point : C:\WINDOWS\ime\imejp\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imejp\applets\applets

Found mount point : C:\WINDOWS\ime\imejp98\imejp98

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imejp98\imejp98

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729

Found mount point : C:\WINDOWS\Installer\{1219497F-FA96-4D8E-9571-9C27A2A66B38}\{1219497F-FA96-4D8E-9571-9C27A2A66B38}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\{1219497F-FA96-4D8E-9571-9C27A2A66B38}\{1219497F-FA96-4D8E-9571-9C27A2A66B38}

Found mount point : C:\WINDOWS\Installer\{548EAC70-EE00-11DD-908C-005056806466}\{548EAC70-EE00-11DD-908C-005056806466}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\{548EAC70-EE00-11DD-908C-005056806466}\{548EAC70-EE00-11DD-908C-005056806466}

Found mount point : C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81200000003}\{AC76BA86-7AD7-1033-7B44-A81200000003}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81200000003}\{AC76BA86-7AD7-1033-7B44-A81200000003}

Found mount point : C:\WINDOWS\Installer\{AC76BA86-7AD7-5464-3428-800000000003}\{AC76BA86-7AD7-5464-3428-800000000003}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\{AC76BA86-7AD7-5464-3428-800000000003}\{AC76BA86-7AD7-5464-3428-800000000003}

Found mount point : C:\WINDOWS\java\trustlib\trustlib

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\java\trustlib\trustlib

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files

Found mount point : C:\WINDOWS\msapps\msinfo\msinfo

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\msapps\msinfo\msinfo

Found mount point : C:\WINDOWS\PCHealth\ERRORREP\QHEADLES\QHEADLES

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHealth\ERRORREP\QHEADLES\QHEADLES

Found mount point : C:\WINDOWS\PCHealth\ERRORREP\QSIGNOFF\QSIGNOFF

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHealth\ERRORREP\QSIGNOFF\QSIGNOFF

Found mount point : C:\WINDOWS\PCHealth\HelpCtr\BATCH\BATCH

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\BATCH\BATCH

Found mount point : C:\WINDOWS\PCHealth\HelpCtr\Config\CheckPoint\CheckPoint

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\Config\CheckPoint\CheckPoint

Found mount point : C:\WINDOWS\PCHealth\HelpCtr\Config\News\News

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\Config\News\News

Found mount point : C:\WINDOWS\PCHealth\HelpCtr\HelpFiles\HelpFiles

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\HelpFiles\HelpFiles

Found mount point : C:\WINDOWS\PCHealth\HelpCtr\InstalledSKUs\InstalledSKUs

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\InstalledSKUs\InstalledSKUs

Found mount point : C:\WINDOWS\PCHealth\HelpCtr\System\DFS\DFS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\System\DFS\DFS

Found mount point : C:\WINDOWS\PCHealth\HelpCtr\System_OEM\System_OEM

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\System_OEM\System_OEM

Found mount point : C:\WINDOWS\PCHealth\HelpCtr\Temp\Temp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PCHealth\HelpCtr\Temp\Temp

Found mount point : C:\WINDOWS\PIF\PIF

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PIF\PIF

Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\backup\backup

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\backup\backup

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\backup\backup

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\backup\backup

Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Cannot access: C:\WINDOWS\system32\drivers\sfi.dat

Attempting to restore permissions of : C:\WINDOWS\system32\drivers\sfi.dat

2009-10-29 14:27:16 1474832 C:\WINDOWS\system32\drivers\sfi.dat ()



Cannot access: C:\WINDOWS\system32\dumprep.exe

Attempting to restore permissions of : C:\WINDOWS\system32\dumprep.exe

Cannot access: C:\WINDOWS\system32\eventlog.dll

Attempting to restore permissions of : C:\WINDOWS\system32\eventlog.dll

2004-08-04 07:56:42 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (Microsoft Corporation)

2008-04-14 00:11:53 56320 C:\WINDOWS\eventlog.dll (Microsoft Corporation)

2008-04-14 00:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Microsoft Corporation)

2008-04-14 00:11:53 61952 C:\WINDOWS\system32\eventlog.dll ()

2008-04-14 00:11:53 56320 C:\WINDOWS\system32\logevent(2).dll (Microsoft Corporation)

2008-04-14 00:11:53 56320 C:\WINDOWS\system32\logevent.dll (Microsoft Corporation)



Found mount point : C:\WINDOWS\Temp\ProdID\bases\bases

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Temp\ProdID\bases\bases

Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp



Finished!
Back to Top
 

DULBARK
New Member


Date Joined Oct 2009
Total Posts : 8
 
   Posted 10-29-2009 5:08 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Here is the GMERlog.

GMER 1.0.15.15163 - http://www.gmer.net
Rootkit scan 2009-10-29 15:01:57
Windows 5.1.2600 Service Pack 3
Running: 3dvke68h.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\axldypod.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwAdjustPrivilegesToken [0xB55B3D46]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwClose [0xB53EAA00]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwConnectPort [0xB55B3250]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreateFile [0xB55B38EA]
SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) ZwCreateKey [0xBABE9800]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwCreatePort [0xB55B3132]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xBA5A4282]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xBA5A4474]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateSection [0xB53EB340]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xB53EAF90]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwCreateThread [0xB53EBC60]
SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) ZwDeleteKey [0xBABE9A00]
SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) ZwDeleteValueKey [0xBABE9BE0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwDuplicateObject [0xB53EAB60]
SSDT spsb.sys ZwEnumerateKey [0xBA6C5CA4]
SSDT spsb.sys ZwEnumerateValueKey [0xBA6C6032]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwLoadDriver [0xB53E8F80]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwMakeTemporaryObject [0xB55B34D4]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) Z!!!enFile [0xB55B3B2E]
SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) Z!!!enKey [0xBABE9900]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) Z!!!enProcess [0xB53EA520]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) Z!!!enSection [0xB53EB170]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) Z!!!enThread [0xB55B2902]
SSDT spsb.sys ZwQueryKey [0xBA6C610A]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwQuerySystemInformation [0xB53EB910]
SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) ZwQueryValueKey [0xBABE9CC0]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xBA5B6422]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwRequestWaitReplyPort [0xB55B49F0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwResumeThread [0xB53EBC10]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSecureConnectPort [0xB55B4C72]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSetContextThread [0xB53EBF90]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSetInformationFile [0xB53EC560]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSetSecurityObject [0xB53E7C40]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwSetSystemInformation [0xB55B5084]
SSDT \??\C:\WINDOWS\system32\Drivers\regguard.sys (Registry Guard - registry keys protection driver for Windows NT/2000/XP/2003/Vista/Greatis Software) ZwSetValueKey [0xBABE9AF0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwShutdownSystem [0xB55B346E]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSuspendThread [0xB53EBBC0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwSystemDebugControl [0xB53E92F0]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xBA5A3F32]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys (COMODO Internet Security Sandbox Driver/COMODO) ZwTerminateThread [0xB55B2ECA]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) ZwWriteVirtualMemory [0xB53EAA20]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[284] [0xB53E6D40]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[285] [0xB53E6D50]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[286] [0xB53E6D60]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[287] [0xB53E6D80]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[288] [0xB53E6DA0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[289] [0xB53E6DD0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[290] [0xB53E6DE0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[291] [0xB53E6E00]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[292] [0xB53E6E10]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[293] [0xB53E6ED0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[294] [0xB53E6FA0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[295] [0xB53E6FE0]
SSDT \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) SSDT[296] [0xB53E7020]

INT 0x62 ? 8A954BF8
INT 0x63 ? 8A954BF8
INT 0x73 ? 8A5D6BF8
INT 0x82 ? 8A954BF8
INT 0x94 ? 8A5D6BF8
INT 0xA4 ? 8A5D6BF8

Code \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab) IoIsOperationSynchronous

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804EAF84 5 Bytes JMP B53EC980 \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab)
.text ntkrnlpa.exe!IoIsOperationSynchronous 804EF912 5 Bytes JMP B53ECE80 \SystemRoot\System32\DRIVERS\klif.sys (spuper-ptor/Kaspersky Lab)
.text ntkrnlpa.exe!ZwCallbackReturn + 2C58 805044F4 4 Bytes JMP 62B55B38
.text ntkrnlpa.exe!ZwCallbackReturn + 2CD4 80504570 2 Bytes [5A, 2A]
.text ntkrnlpa.exe!ZwCallbackReturn + 2D68 80504604 2 Bytes [D4, 34] {AAM 0x34}
? spsb.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B8AFF8AC 5 Bytes JMP 8A5D61D8
.text azqm89s4.SYS B8A78386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text azqm89s4.SYS B8A783AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text azqm89s4.SYS B8A783C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text azqm89s4.SYS B8A783C9 1 Byte [30]
.text azqm89s4.SYS B8A783C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
? win32k.sys:1 The system cannot find the file specified. !
? win32k.sys:2 The system cannot find the file specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 0040FB50 C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe (COMODO Internet Security/COMODO)
.text C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] USER32.dll!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\5A354CC0.x86.dll
.text C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\5A354CC0.x86.dll
.text C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\5A354CC0.x86.dll
.text C:\WINDOWS\system32\svchost.exe[984] USER32.dll!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\5A354CC0.x86.dll
.text C:\WINDOWS\system32\svchost.exe[984] GDI32.dll!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\5A354CC0.x86.dll
.text C:\WINDOWS\system32\svchost.exe[984] GDI32.dll!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\5A354CC0.x86.dll
.text C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 0050DCB0 C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [BA6A8042] spsb.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [BA6A813E] spsb.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [BA6A80C0] spsb.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [BA6A8800] spsb.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [BA6A86D6] spsb.sys
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!READ_PORT_UCHAR] 1C8D9E88
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KfRaiseIrql] 00001CA9
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KfLowerIrql] 0E798366
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!HalTranslateBusAddress] 8186C636
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!KfReleaseSpinLock] 1C8386C6
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!READ_PORT_USHORT] 001C8E86
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CAA
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
IAT \SystemRoot\System32\Drivers\azqm89s4.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB19E
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [BA6B7E9C] spsb.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [BA4E6740] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [BA4E6780] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [BA4E66E0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [BA4E67B0] inspect.sys (COMODO Internet Security Firewall Driver/COMODO)

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\5A354CC0.x86.dll
IAT C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe[944] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\5A354CC0.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\5A354CC0.x86.dll
IAT C:\WINDOWS\system32\svchost.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\5A354CC0.x86.dll
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [00617E10] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\IPHLPAPI.DLL [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\IPHLPAPI.DLL [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!DeleteObject] [00616EA0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [00617E10] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [00617DC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AdjustWindowRectEx] [00617B60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [00617280] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSystemMetrics] [00617930] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [00616E50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [00617310] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!RegisterClassW] [00617870] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [00616EE0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!FillRect] [00617C70] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DrawFrameControl] [00617CE0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DrawEdge] [00617CC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SystemParametersInfoW] [00617A50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetScrollInfo] [006170D0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!CallWindowProcW] [00617140] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetScrollInfo] [00616FC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!DeleteObject] [00616EA0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [00617DC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [00617E10] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [00617280] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [00617310] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [00616E50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!RegisterClassA] [006177B0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!RegisterClassW] [00617870] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SystemParametersInfoW] [00617A50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcW] [00617140] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcA] [006171E0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSystemMetrics] [00617930] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [GDI32.dll!DeleteObject] [00616EA0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [00617E10] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [00617DC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SystemParametersInfoW] [00617A50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetSystemMetrics] [00617930] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetSysColor] [00616E50] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CallWindowProcW] [00617140] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!RegisterClassW] [00617870] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DefWindowProcW] [00617310] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [00617D80] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [00617DC0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [00617E10] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!CreateThread] [00617720] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetModuleHandleA] [00617E60] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\CRYPT32.dll [USER32.dll!GetSystemMetrics] [00617930] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [00617D40] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
IAT C:\Program Files\Comodo\COMODO Internet Security\cfp.exe[3532] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [00617EF0] C:\Program Files\Comodo\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 8A9531F8

AttachedDevice \FileSystem\Ntfs \Ntfs CFRPD.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs CFRPD.sys (COMODO Safe Delete Filter/COMODO Security Solutions Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs klif.sys (spuper-ptor/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)

Device \Driver\usbuhci \Device\USBPDO-0 8A5D51F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A8E41F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A8E41F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A8E41F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A8E41F8
Device \Driver\usbuhci \Device\USBPDO-1 8A5D51F8
Device \Driver\usbuhci \Device\USBPDO-2 8A5D51F8
Device \Driver\usbuhci \Device\USBPDO-3 8A5D51F8
Device \Driver\PCI_PNP9996 \Device\00000047 spsb.sys

AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)

Device \Driver\Ftdisk \Device\HarddiskVolume1 8A9551F8
Device \Driver\sptd \Device\1170786246 spsb.sys
Device \Driver\Cdrom \Device\CdRom0 8A5961F8
Device \Driver\Cdrom \Device\CdRom1 8A5961F8
Device \Driver\atapi \Device\Ide\IdePort0 [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort3 [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-e [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 [BA5DBB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom2 8A5961F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A5321F8
Device \Driver\NetBT \Device\NetbiosSmb 8A5321F8

AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)

Device \Driver\usbuhci \Device\USBFDO-0 8A5D51F8
Device \Driver\usbuhci \Device\USBFDO-1 8A5D51F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A3301F8
Device \Driver\usbuhci \Device\USBFDO-2 8A5D51F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A3301F8
Device \Driver\usbuhci \Device\USBFDO-3 8A5D51F8
Device \Driver\Ftdisk \Device\FtControl 8A9551F8
Device \Driver\azqm89s4 \Device\Scsi\azqm89s41Port4Path0Target1Lun0 8A5911F8
Device \Driver\azqm89s4 \Device\Scsi\azqm89s41 8A5911F8
Device \Driver\azqm89s4 \Device\Scsi\azqm89s41Port4Path0Target0Lun0 8A5911F8
Device \FileSystem\Cdfs \Cdfs 8A4201F8
---- Processes - GMER 1.0.15 ----

Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [884] 0x35670000
Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe [944] 0x35670000
Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [984] 0x35670000
Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1108] 0x35670000
Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1136] 0x35670000
Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [1204] 0x35670000
Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\Program Files\Java\jre6\bin\jqs.exe [1404] 0x35670000
Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\lxctcoms.exe [1444] 0x35670000
Library \\?\globalroot\Device\__max++>\5A354CC0.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [1912] 0x35670000

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x67 0x5B 0x24 0xC1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC8 0x20 0x40 0xF2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF7 0xC2 0xDD 0x4D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3B 0x22 0x9E 0x27 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x98 0xA2 0xAE 0xF2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x67 0x5B 0x24 0xC1 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC8 0x20 0x40 0xF2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xF7 0xC2 0xDD 0x4D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3B 0x22 0x9E 0x27 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x98 0xA2 0xAE 0xF2 ...

---- EOF - GMER 1.0.15 ----
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 10-29-2009 6:57 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Seems you have some missing or infected system files, so let´s see if combofix can replace them ->
 
Please download Combofix from:
 
 And save to the desktop al alg.exe

Close all other browser windows.
 
Double-click on the combofix icon found on your desktop.
 
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.

 When finished, it will produce a logfile located at C:\combofix.txt.
 

Post the contents of that log in your next reply
 
The logs will be reasonably large so you may have to divide them into sections and make several posts to post them.


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

DULBARK
New Member


Date Joined Oct 2009
Total Posts : 8
 
   Posted 10-29-2009 9:28 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
I have run Combofix here is part one.


ComboFix 09-10-28.08 - Administrator 29/10/2009 18:19.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2047.1319 [GMT 0:00]
Running from: c:\documents and settings\Administrator\Desktop\alg.exe.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
AV: Outpost Security Suite Pro *On-access scanning disabled* (Updated) {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FW: Outpost Security Suite Pro *enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Application Data\inst.exe
c:\windows\system32\infopsvEV67s.dll

Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\eventlog.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}


((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-29 )))))))))))))))))))))))))))))))
.

2009-10-29 17:10 . 2009-10-29 17:10 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-10-29 17:09 . 2009-10-29 17:53 -------- d-----w- c:\documents and settings\Administrator\.housecall6.6
2009-10-29 15:53 . 2009-10-29 15:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\Avira
2009-10-29 15:51 . 2009-10-29 15:49 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-29 15:51 . 2009-10-29 15:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-29 15:51 . 2009-10-29 15:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-29 15:51 . 2009-10-29 15:51 -------- d-----w- c:\program files\Avira
2009-10-29 14:15 . 2008-12-22 17:03 33512 ----a-w- c:\windows\system32\drivers\REGRUNRM.SYS
2009-10-29 14:15 . 2008-12-22 17:03 55184 ----a-w- c:\windows\system32\drivers\RegRunFM.SYS
2009-10-29 14:09 . 2009-09-10 14:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-29 14:09 . 2009-10-29 14:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-29 14:09 . 2009-09-10 14:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-29 14:04 . 2009-10-29 14:04 -------- d-----w- c:\windows\RestoreSafeDeleted
2009-10-29 13:42 . 2009-10-29 13:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\Regrun
2009-10-29 13:41 . 2009-10-29 13:49 29584 ----a-w- c:\windows\system32\drivers\regguard.sys
2009-10-29 13:41 . 2009-10-29 13:41 2 --shatr- c:\windows\winstart.bat
2009-10-29 13:41 . 2009-10-29 13:41 34760 ----a-w- c:\windows\system32\drivers\Partizan.sys
2009-10-29 13:41 . 2009-10-29 13:41 32480 ----a-w- c:\windows\system32\Partizan.exe
2009-10-29 13:38 . 2008-12-22 17:04 444128 ----a-w- c:\windows\RunGuard.exe
2009-10-29 13:38 . 2008-12-22 17:04 20192 ----a-w- c:\windows\WinBait.exe
2009-10-29 13:38 . 2009-10-29 13:38 -------- d-----w- c:\program files\Greatis
2009-10-29 12:54 . 2009-10-29 12:54 -------- d-----w- C:\rsit
2009-10-29 12:11 . 2008-02-25 11:44 603176 ----a-w- C:\autoruns.exe
2009-10-29 12:11 . 2008-02-25 11:44 513064 ----a-w- C:\autorunsc.exe
2009-10-28 01:09 . 2009-10-29 18:36 28704 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-28 01:09 . 2009-10-29 18:35 4066080 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-28 00:41 . 2009-10-28 10:48 -------- d-----w- c:\program files\Common Files\ParetoLogic
2009-10-28 00:41 . 2009-10-28 10:48 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-10-28 00:40 . 2009-10-28 00:40 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Downloaded Installations
2009-10-27 22:40 . 2009-10-27 22:40 19207 ----a-w- C:\MGlogs.zip
2009-10-27 18:48 . 2009-10-27 23:10 -------- d-----w- C:\MGtools
2009-10-27 18:41 . 2009-10-27 18:41 -------- d-----w- c:\windows\Junction
2009-10-27 18:41 . 2009-10-27 18:41 95616 ----a-w- c:\windows\junction.exe
2009-10-27 18:40 . 2009-10-27 18:36 46375 ----a-w- c:\windows\Junction.zip
2009-10-27 18:28 . 2009-10-27 18:28 47616 ----a-w- C:\Win32kDiag.exe
2009-10-27 18:11 . 2009-10-27 18:11 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2009-10-27 15:32 . 2009-10-27 15:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitDefender
2009-10-27 15:17 . 2009-10-27 15:18 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-27 14:35 . 2009-10-27 14:35 132 ----a-w- c:\windows\system32\rezumatenoi.dat
2009-10-27 14:02 . 2009-10-27 14:02 4 ----a-w- c:\windows\system32\aspdict-en.dat
2009-10-27 14:02 . 2009-10-27 14:02 16 ----a-w- c:\windows\system32\asdict.dat
2009-10-27 13:36 . 2009-10-27 13:36 -------- d-----w- C:\aaavault
2009-10-27 13:26 . 2009-10-29 15:51 -------- d-----w- c:\windows\LastGood
2009-10-27 13:25 . 2009-10-27 14:36 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender
2009-10-27 13:25 . 2009-10-27 13:25 -------- d-----w- c:\program files\BitDefender
2009-10-27 13:21 . 2009-10-27 14:36 -------- d-----w- c:\program files\Common Files\BitDefender
2009-10-27 01:36 . 2009-10-27 01:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-26 12:01 . 2009-10-29 12:54 -------- d-----w- c:\program files\Trend Micro
2009-10-26 11:56 . 2008-04-14 00:11 56320 ------w- c:\windows\eventlog.dll
2009-10-26 10:26 . 2009-10-26 11:43 0 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\prvlcl.dat
2009-10-25 21:31 . 2009-10-26 17:09 -------- d-----w- C:\$AVG
2009-10-25 21:30 . 2009-10-26 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-10-25 20:36 . 2009-10-25 20:36 -------- d-----w- c:\documents and settings\Administrator\Application DataComodoGroup
2009-10-25 20:31 . 2009-10-25 20:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\ComodoGroup
2009-10-25 20:21 . 2009-10-25 20:21 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-25 20:20 . 2009-10-25 20:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-25 20:09 . 2009-10-25 20:11 -------- d-----w- c:\windows\BDOSCAN8
2009-10-25 20:09 . 2009-10-25 20:09 -------- d-----w- c:\windows\LastGood.Tmp
2009-10-25 17:32 . 2009-10-25 17:32 87104 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-10-25 17:32 . 2009-10-25 17:32 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-10-25 17:32 . 2009-10-25 17:32 179792 ----a-w- c:\windows\system32\guard32.dll
2009-10-25 17:32 . 2009-10-25 17:32 132296 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-10-25 10:28 . 2009-10-29 15:49 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-24 20:49 . 2009-10-29 16:32 0 ----a-r- c:\windows\win32k.sys
2009-10-24 20:48 . 2009-10-24 20:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Webroot
2009-10-24 20:48 . 2009-10-24 20:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\Webroot
2009-10-24 20:47 . 2009-10-24 20:47 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-24 20:47 . 2009-10-24 20:47 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\PC Tools
2009-10-24 20:47 . 2009-10-24 20:47 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Tools
2009-10-24 20:47 . 2009-10-24 20:47 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-24 20:46 . 2009-10-24 20:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-10-24 18:58 . 2009-10-24 19:30 -------- dc----w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-24 18:58 . 2009-10-24 19:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-22 14:29 . 2009-10-24 19:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\Webroot(2)
2009-10-21 18:18 . 2009-10-24 20:46 -------- d-----w- c:\program files\Common Files\PC Tools(2)
2009-10-21 18:03 . 2009-10-24 20:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater(2)
2009-10-20 18:51 . 2009-10-24 20:47 -------- d-----w- c:\program files\HangWord
2009-10-20 15:16 . 2009-10-29 16:10 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2009-10-20 09:16 . 2009-10-20 09:16 -------- d-----w- c:\program files\Vocabulary Wizard 67E
2009-10-19 15:02 . 2009-10-19 15:02 -------- d-----w- c:\program files\Interlex 2
2009-10-16 20:04 . 2009-10-16 20:04 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia
2009-10-16 20:04 . 2009-10-16 20:04 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Suite
2009-10-16 20:04 . 2009-10-16 20:04 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-10-16 19:39 . 2009-10-16 19:39 -------- d-----w- c:\program files\Common Files\PCSuite
2009-10-16 19:39 . 2009-10-16 19:39 -------- d-----w- c:\program files\Common Files\Nokia
2009-10-16 19:39 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-10-16 19:39 . 2009-10-16 19:39 -------- d-----w- c:\program files\PC Connectivity Solution
2009-10-16 19:38 . 2009-02-09 07:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-10-16 19:38 . 2009-10-16 19:39 -------- d-----w- c:\program files\Nokia
2009-10-16 19:37 . 2009-10-16 19:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-10-16 19:32 . 2009-10-29 15:20 -------- d-sh--w- c:\windows\ftpcache
Back to Top
 

DULBARK
New Member


Date Joined Oct 2009
Total Posts : 8
 
   Posted 10-29-2009 9:29 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Here is part two.....


.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-29 18:33 . 2009-10-28 01:09 55460 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-29 18:33 . 2009-10-28 01:09 3692 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-29 15:51 . 2008-06-28 19:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-10-29 15:46 . 2008-06-30 15:08 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-10-29 14:03 . 2008-06-30 19:20 -------- d-----w- c:\program files\Windows Live Mail desktop
2009-10-27 01:31 . 2008-12-10 15:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-27 01:30 . 2008-06-28 17:42 -------- d-----w- c:\program files\CCleaner
2009-10-26 22:40 . 2008-07-01 18:51 -------- d-----w- c:\program files\ProcessGuard
2009-10-25 20:26 . 2008-05-26 16:24 -------- d-----w- c:\program files\Comodo
2009-10-25 20:01 . 2009-06-14 23:57 -------- d-----w- c:\program files\Chandler1.0.3
2009-10-25 19:59 . 2008-12-10 15:14 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-25 18:06 . 2008-05-26 16:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo
2009-10-25 00:07 . 2008-06-28 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-10-24 20:46 . 2008-05-26 20:19 -------- d-----w- c:\program files\Google
2009-10-24 11:20 . 2008-05-26 20:37 -------- d-----w- c:\documents and settings\Administrator\Application Data\StarOffice8
2009-10-22 14:19 . 2009-03-10 10:51 164 ----a-w- c:\windows\install.dat
2009-10-22 13:51 . 2008-06-28 14:30 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-18 18:50 . 2008-07-07 15:09 -------- d-----w- c:\program files\Mozilla Sunbird
2009-10-16 19:39 . 2009-07-28 23:14 -------- d-----w- c:\program files\DIFX
2009-10-16 11:38 . 2009-07-28 23:11 -------- d-----w- c:\documents and settings\All Users\Application Data\LGMOBILEAX
2009-10-05 18:15 . 2009-02-24 14:47 -------- d-----w- c:\program files\lx_cats
2009-10-04 13:05 . 2002-03-25 20:02 12528 ----a-w- c:\windows\system32\drivers\secdrv.sys
2009-09-29 11:04 . 2009-09-29 11:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2009-09-24 09:15 . 2008-07-05 19:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype
2009-09-11 14:18 . 2002-08-29 03:41 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2001-08-23 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-03 13:52 . 2009-09-03 13:52 -------- d-----w- c:\program files\Patrick Computer Services
2009-08-29 08:08 . 2006-06-23 10:33 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2002-08-29 03:41 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-05 11:41 . 2008-06-28 18:38 49512 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2008-05-25 12:28 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 19:50 . 2009-08-04 19:50 56736 ----a-w- c:\windows\system32\drivers\CFRPD.sys
2009-08-04 15:13 . 2002-08-29 01:04 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2002-08-29 01:04 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
1999-02-15 18:25 . 1999-02-15 18:25 348 ----a-w- c:\program files\Europress KS3 ProductsKS3Maths.del
2009-09-13 22:10 . 2009-10-27 13:46 47104 ----a-w- c:\program files\mozilla firefox\components\FFComm.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IE Privacy Keeper"="c:\program files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" [2005-12-03 1015808]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Regrun2"="c:\progra~1\Greatis\REGRUN~1\WatchDog.exe" [2008-12-22 384224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"="c:\program files\XpertVision\TBPanel.exe" [2008-01-29 2157064]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"SkyTel"="c:\windows\SkyTel.EXE" [2007-04-04 1822720]
"RTHDCPL"="c:\windows\RTHDCPL.EXE" [2007-04-10 16126464]
"nwiz"="c:\windows\system32\nwiz.exe" [2008-01-08 1626112]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2008-01-08 81920]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2008-01-08 8523776]
"EzPrint"="c:\program files\Lexmark 5400 Series\ezprint.exe" [2007-03-19 82864]
"Lexmark 5400 Series Fax Server"="c:\program files\Lexmark 5400 Series\fm3032.exe" [2007-03-19 304048]
"lxctmon.exe"="c:\program files\Lexmark 5400 Series\lxctmon.exe" [2007-03-19 291760]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"LXCTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll" [2006-11-21 106496]
"COMODO Internet Security"="c:\program files\Comodo\COMODO Internet Security\cfp.exe" [2009-10-25 1799952]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"RegRun WinBait"="c:\windows\winbait.exe" [2008-12-22 20192]
"@RegRunOnSecure"="c:\progra~1\Greatis\REGRUN~1\OnSecure.exe" [2008-12-22 61664]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-10-29 209153]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{F552DDE6-2090-4bf4-B924-6141E87789A5}"= "c:\progra~1\Greatis\REGRUN~1\RRShell.dll" [2008-10-20 335943]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Spamihilator\\cdcc.exe"=
"c:\\Program Files\\Spamihilator\\dccproc.exe"=
"c:\\Program Files\\Spamihilator\\spamihilator.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\JetAudio\\JetAudio.exe"=
"c:\\WINDOWS\\system32\\lxctcoms.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [x]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [x]
R2 AntiVirUpgradeService;Avira Upgrade Service;c:\windows\TEMP\AVSETUP_4ae390b2\basic\avupgsvc.exe [x]
R2 gupdate1c9abdd319dbaf4;Google Update Service (gupdate1c9abdd319dbaf4);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;c:\docume~1\ADMINI~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys [x]
R3 FlashUSB;FlashUSB;c:\windows\system32\DRIVERS\FlashUSB.sys [2009-05-12 16896]
R3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver;c:\docume~1\ADMINI~1\LOCALS~1\Temp\F-Secure\BlackLight\fsbldrv.sys [x]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [x]
R3 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [2009-10-29 34760]
R3 QCNCE;QCNCE;c:\docume~1\ADMINI~1\LOCALS~1\Temp\QCNCE.exe [x]
R3 RegGuard;RegGuard;c:\windows\system32\Drivers\regguard.sys [2009-10-29 29584]
R3 REGRUNFM;REGRUNFM;c:\windows\system32\drivers\RegRunFM.SYS [2008-12-22 55184]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [x]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [x]
R3 XBLJB;XBLJB;c:\docume~1\ADMINI~1\LOCALS~1\Temp\XBLJB.exe [x]
S0 CFRPD;CFRPD;c:\windows\System32\drivers\CFRPD.sys [2009-08-04 56736]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-04-03 130936]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2009-10-25 132296]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2009-10-25 25160]
S2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [2009-10-29 194817]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-10-29 108289]
S2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2009-10-29 434945]
Back to Top
 

DULBARK
New Member


Date Joined Oct 2009
Total Posts : 8
 
   Posted 10-29-2009 9:35 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Now part three ......to complete the trilogy.


--- Other Services/Drivers In Memory ---

*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder

2009-08-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
Trusted Zone: google.co.uk\www
Trusted Zone: live.com\by113w.bay113.mail
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: windowsupdate.com\download
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\fii5c4qq.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\fii5c4qq.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\Sun\StarOffice 8\program\npsoplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-COMODO livePCsupport - (no file)
HKLM-Run-SClassWidget - (no file)
Notify-avgrsstarter - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-29 18:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...


**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spie.sys >>UNKNOWN [0x8A902938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

atapi.sys @ 0x0 0x0 bytes

\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xBA5DBB40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xBA5DBB40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xBA5DBB40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xBA5DBB40 atapi.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xBA5DBB40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xBA5DBB40 atapi.sys
\Driver\atapi IRP hooks detected !

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f9,b1,0c,4b,79,73,d1,45,a0,99,54,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,f9,b1,0c,4b,79,73,d1,45,a0,99,54,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(668)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
c:\program files\Avira\AntiVir Desktop\avsda.dll

- - - - - - - > 'explorer.exe'(3044)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Comodo\COMODO Internet Security\cmdagent.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxctcoms.exe
c:\windows\System32\nvsvc32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
.
**************************************************************************
.
Completion time: 2009-10-29 18:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-29 18:48

Pre-Run: 198,970,920,960 bytes free
Post-Run: 199,132,884,992 bytes free

- - End Of File - - CC68D132562229073A12CFE54D224F63
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 10-30-2009 6:03 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Great, combofix replace the infected file ;-)
 
"Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\eventlog.dll"
 
 

Please tell how things are running now ?


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

DULBARK
New Member


Date Joined Oct 2009
Total Posts : 8
 
   Posted 10-30-2009 8:57 (GMT +1)    Quote: Undetectable virus, cannot run antivirus or antispyware appsAlert an admin about: Undetectable virus, cannot run antivirus or antispyware apps
Here is some additional info:

Before running Combofix I got a trial version of Avira working.
Last week the free version picked up Trojan.Dropper/Gen but could not quarantine the file.
When combofix was running the avira was deactivated but picked the file eventlog.dll and quarantined successfully.
I then installed Malwarebytes and ran a scan this gave me another infected file which was Win32k.sys in the windows directory.
After running a full system scan I also detected a file called A0221256.dll which I think was in the sytem restore part of the drive.
Now my PC is runnning much better - but it seems to be very slow for a while after boot up, I'm guessing it's the security software on it.
I am using Webroot at the moment / Comodo, but after this expereince need a zero day threat detector as I had downloaded some files
last week which did not show a virus upon scan but this week after submission to comodo they gave an update the same day which verified
a Trojan. The Webroot also detects this file now.

Many thanks for your help.........
I have over 20 years experience in business development....drop me a line anytime If I can return a (free) favour.
Back to Top
 
New Topic Post reply to : Undetectable virus, cannot run antivirus or antispyware apps Printable version of : Undetectable virus, cannot run antivirus or antispyware apps
 
Forum Information
Currently it is Saturday, November 21, 2009 4:07 PM (GMT +1)
There are a total of 73.034 posts in 17.116 threads.
In the last 3 days there were 14 new threads and 71 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil.
40 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Constant scanning andskipped files? (3)21-11-2009 14:33:51 (Dickens)
Cannot install anti-virus softeware or do window updates... need help (17)21-11-2009 13:46:11 (superjesse)
Michael Vick jerseys (1)21-11-2009 09:42:37 (Dickens)
Arizona Cardinals Jerseys (1)21-11-2009 09:37:23 (Dickens)
How to remove this Malware/Virus (0)21-11-2009 06:54:16 (bozzack)