Steviebone Posted May 20, 2007 Report Share Posted May 20, 2007 Below is a hijack this log... the computer in question has been scanned by SpyBOT S&D, Spy Sweeper, Avast Pro (boot time) and NOD32. Whenever the computer starts up, even before log in syslog shows continuous various outbound traffic to rogue destination ip adresses. The traffic is continuous and eats up anywhere from 4 to 85% of the CPU power according to task manager. The only thing showing consumption in task manager however is System Idle Process. At semi periodic intervals I get errors in services.exe result code 0 and a forced NT Authority Shutdown/Reboot.As there are over 70 programs installed on this workstation I would prefer NOT to have to rebuild from scratch. BTW, Acronis has been used to regulalry back up the OS daily but whatever it is is now embedded in all 7 OS backups.Here is the log:Logfile of HijackThis v1.99.1Scan saved at 2:02:22 AM, on 5/20/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\XP\System32\smss.exeC:\XP\system32\winlogon.exeC:\XP\system32\services.exeC:\XP\system32\lsass.exeC:\XP\system32\svchost.exeC:\XP\System32\svchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\XP\system32\spoolsv.exeC:\Program Files\Acronis\BackupServer\backupserver.exeC:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeC:\Program Files\Eset\nod32krn.exeC:\XP\system32\nvsvc32.exeC:\XP\System32\svchost.exeC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\XP\Explorer.exeC:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exeC:\Program Files\Eset\nod32kui.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\PTSync\PTSync.exeC:\Program Files\Acronis\TrueImageEnterpriseServer\TRUEIM~3.EXEC:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exeC:\Program Files\Acronis\TrueImageEnterpriseServer\TIMOUN~1.EXEC:\PROGRA~1\MOZILL~1\FIREFOX.EXEC:\Program Files\Webroot\Spy Sweeper\SSU.EXEC:\XP\system32\NOTEPAD.EXEC:\XP\system32\NOTEPAD.EXEC:\XP\system32\vsjitdebugger.exeC:\XP\system32\vsjitdebugger.exeC:\XP\system32\taskmgr.exeC:\Program Files\Hijackthis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.americansingles.com/F2 - REG:system.ini: Shell=C:\XP\Explorer.exeO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dllO2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Acrobat7\Acrobat\AcroIEFavClient.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Acrobat7\Acrobat\AcroIEFavClient.dllO3 - Toolbar: Cooxie - {DC99E960-6594-45e3-9D5D-141D825B8096} - C:\Program Files\Cooxie Toolbar\PrvcBand.dllO4 - HKLM\..\Run: [spySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintrayO4 - HKLM\..\RunOnce: [speedStartup] "C:\Program Files\Speed Startup\speedstartup.exe" runonceO4 - HKCU\..\Run: [speedStartup] "C:\Program Files\Speed Startup\speedstartup.exe" bootupO8 - Extra context menu item: Add to &Teleport - D:\TeleportUltra\teleport.htmO8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert link target to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlO8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlO8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert selection to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MsOffice\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://D:\OmniPage15\PDFConverter3\IEShellExt.dll /100O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dllO9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dllO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dllO9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dllO9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MsOffice\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1145986548799O17 - HKLM\System\CCS\Services\Tcpip\..\{90F742E6-14BD-42BD-B353-7487933899E6}: NameServer = 66.254.6.2,66.254.1.2O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dllO20 - Winlogon Notify: WgaLogon - C:\XP\SYSTEM32\WgaLogon.dllO20 - Winlogon Notify: WRNotifier - C:\XP\SYSTEM32\WRLogonNTF.dllO23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exeO23 - Service: Acronis Backup Server Service (AcronisBackupServerService) - Acronis - C:\Program Files\Acronis\BackupServer\backupserver.exeO23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeO23 - Service: Arcana Notification Agent (adnotify) - Unknown owner - C:\Program Files\Arcana Development\Notification Agent\ADNotify.exeO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: Arcana Scheduler - Arcana Development - C:\Program Files\Arcana Development\Arcana Scheduler\adscheduler.exeO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)O23 - Service: Acronis Group Server (GroupServer) - Acronis - C:\Program Files\Acronis\GroupServer\GroupServer.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\XP\system32\drivers\KodakCCS.exeO23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exeO23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exeO23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\XP\system32\nvsvc32.exeO23 - Service: O&O Defrag - O&O Software GmbH - C:\XP\system32\oodag.exeO23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - C:\Program Files\Zenturi\ProgramChecker\sassvc.exeO23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe Quote Link to post Share on other sites
Steviebone Posted May 20, 2007 Author Report Share Posted May 20, 2007 Here is an updated log after running spydetector:C:\XP\System32\smss.exeC:\XP\system32\winlogon.exeC:\XP\system32\services.exeC:\XP\system32\lsass.exeC:\XP\system32\svchost.exeC:\XP\System32\svchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\XP\system32\spoolsv.exeC:\Program Files\Acronis\BackupServer\backupserver.exeC:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeC:\Program Files\Eset\nod32krn.exeC:\XP\system32\nvsvc32.exeC:\Program Files\SpywareDetector\SDService.exeC:\XP\System32\svchost.exeC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\XP\Explorer.EXEC:\Program Files\SpywareDetector\SDSystemTray.exeC:\Program Files\Eset\nod32kui.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\PTSync\PTSync.exeC:\Program Files\Acronis\TrueImageEnterpriseServer\TRUEIM~3.EXEC:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exeC:\Program Files\Acronis\TrueImageEnterpriseServer\TIMOUN~1.EXEC:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exeC:\XP\system32\taskmgr.exeC:\Program Files\Webroot\Spy Sweeper\SSU.EXEC:\Program Files\Hijackthis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.americansingles.com/O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dllO2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Acrobat7\Acrobat\AcroIEFavClient.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Acrobat7\Acrobat\AcroIEFavClient.dllO3 - Toolbar: Cooxie - {DC99E960-6594-45e3-9D5D-141D825B8096} - C:\Program Files\Cooxie Toolbar\PrvcBand.dllO4 - HKLM\..\Run: [spySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintrayO4 - HKLM\..\Run: [sDAutoLiveupdate] "C:\Program Files\SpywareDetector\LiveUpdateSD.exe" -AUTOO4 - HKLM\..\Run: [systemTraySD] "C:\Program Files\SpywareDetector\SDSystemTray.exe" -AUTOO4 - HKLM\..\RunOnce: [speedStartup] "C:\Program Files\Speed Startup\speedstartup.exe" runonceO4 - HKCU\..\Run: [speedStartup] "C:\Program Files\Speed Startup\speedstartup.exe" bootupO8 - Extra context menu item: Add to &Teleport - D:\TeleportUltra\teleport.htmO8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert link target to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlO8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlO8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert selection to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MsOffice\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://D:\OmniPage15\PDFConverter3\IEShellExt.dll /100O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dllO9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dllO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dllO9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dllO9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MsOffice\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1145986548799O17 - HKLM\System\CCS\Services\Tcpip\..\{90F742E6-14BD-42BD-B353-7487933899E6}: NameServer = 66.254.6.2,66.254.1.2O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dllO20 - Winlogon Notify: SDNotify - C:\Program Files\SpywareDetector\SDNotify.dllO20 - Winlogon Notify: WgaLogon - C:\XP\SYSTEM32\WgaLogon.dllO20 - Winlogon Notify: WRNotifier - C:\XP\SYSTEM32\WRLogonNTF.dllO23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exeO23 - Service: Acronis Backup Server Service (AcronisBackupServerService) - Acronis - C:\Program Files\Acronis\BackupServer\backupserver.exeO23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeO23 - Service: Arcana Notification Agent (adnotify) - Unknown owner - C:\Program Files\Arcana Development\Notification Agent\ADNotify.exeO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: Arcana Scheduler - Arcana Development - C:\Program Files\Arcana Development\Arcana Scheduler\adscheduler.exeO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)O23 - Service: Acronis Group Server (GroupServer) - Acronis - C:\Program Files\Acronis\GroupServer\GroupServer.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\XP\system32\drivers\KodakCCS.exeO23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exeO23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exeO23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\XP\system32\nvsvc32.exeO23 - Service: O&O Defrag - O&O Software GmbH - C:\XP\system32\oodag.exeO23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - C:\Program Files\Zenturi\ProgramChecker\sassvc.exeO23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exeO23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeNote: although the rogue traffic on syslog has ceased for the moment, there were still out bounds detected during bootup going to unknown domains and task manager still shows continuous memory and resource useage with spikes to 100%. Quote Link to post Share on other sites
jwbirdsong Posted May 20, 2007 Report Share Posted May 20, 2007 (edited) Let's look a little deeper Download Combofix to your desktop.Doubleclick combofix.exeFollow the prompts.Don't click on the window while the fix is running, because that will cause your system to hang.When finished and after reboot (in case it asks to reboot), it should open a log, combofix.txt. Post this log in your next reply Edited May 20, 2007 by jwbirdsong Quote Link to post Share on other sites
Steviebone Posted May 20, 2007 Author Report Share Posted May 20, 2007 ok, combo found a rootkit as I half expected... below is the log after 3 reboots... unfortunately, on every reboot I have an MSI for Visual Foxpro trying to run now... I assume this may be the originally infected file trying to reload... on each reboot, before anything else (even speed startup) starts running, I get repeated message dialogs saying Windows Installer is preparing install for VFP9. I keep hitting cancel as quickly as possible but the window pops right back up... takes about 8 or 10 cancels to make it stay away... I fear this program will not give up perhaps until it has reinfected the machine... task manager is still going nuts showing constant activity 2-22% with never a pause... syslog is not showing any outbound traffic however so we're probably headed in the right direction....I'm going to run combofix a second time and see if the installer has indeed reinfected the machine..."Staypuffer" - 2007-05-20 10:29:12 Service Pack 2 ComboFix 07-05.20.9.V - Running from: "J:\Spywaredetector\" Rootkit driver pe386 is present. ... attempting disinfection pe386 ...... driver unloaded successfully. ADS removed - system32: deleted 79094 bytes in 1 streams. (((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))C:\DOCUME~1\STAYPU~1\Desktop.\internet explorer.lnkC:\Program Files\install.log((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-20 ))))))))))))))))))))))))))))))))))2007-05-20 06:42 2,922 --a------ C:\XP\system32\IE_Backup.reg2007-05-20 06:42 2,846,854 --a------ C:\XP\system32\Windows_Backup.reg2007-05-20 06:42 2,588 --a------ C:\XP\system32\startupBackup.reg2007-05-20 02:27 123 --a------ C:\XP\system\SysSD.dll2007-05-20 02:26 63,192 --a------ C:\XP\system32\CloseAll.exe2007-05-20 02:26 270,336 --a------ C:\XP\system32\CheckDll.dll2007-05-20 02:26 1,019,904 --a------ C:\XP\system32\VchReg.dll2007-05-20 02:25 <DIR> d-------- C:\Program Files\SpywareDetector2007-05-19 18:15 22,080 --a------ C:\XP\system32\drivers\sshrmd.sys2007-05-19 18:15 21,056 --a------ C:\XP\system32\drivers\sskbfd.sys2007-05-19 18:15 20,544 --a------ C:\XP\system32\drivers\SSFS0509.sys2007-05-19 18:15 144,960 --a------ C:\XP\system32\drivers\ssidrv.sys2007-05-19 18:15 <DIR> d-------- C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\Webroot2007-05-19 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Webroot2007-05-19 18:08 164 --a------ C:\install.dat2007-05-19 18:08 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Webroot2007-05-18 11:43 <DIR> d--h----- C:\XP\system32\GroupPolicy2007-05-17 22:04 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Texture Maker2007-05-17 22:03 <DIR> d-------- C:\Program Files\Texture Maker2007-05-17 17:39 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Google2007-05-15 13:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Spybot - Search & Destroy2007-05-08 01:29 <DIR> d-------- C:\Program Files\Network Chemistry2007-05-08 01:17 <DIR> d-------- C:\Program Files\WinPcap2007-05-08 01:17 <DIR> d-------- C:\Program Files\Nmap2007-04-26 18:37 298,496 --a------ C:\XP\uninst.exe(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))2007-05-17 22:39:02 -------- d-----w C:\Program Files\Google2007-05-16 04:57:49 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\WeatherBug2007-05-15 21:02:01 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\dvdcss2007-05-15 18:38:06 -------- d-----w C:\Program Files\MySpace2007-05-07 17:28:32 -------- d-----w C:\Program Files\EPSON Print CD2007-05-07 13:39:36 298,104 ----a-w C:\XP\system32\imon.dll2007-05-07 13:39:34 512,096 ----a-w C:\XP\system32\drivers\amon.sys2007-05-07 13:39:33 15,424 ----a-w C:\XP\system32\drivers\nod32drv.sys2007-05-03 05:49:55 -------- d-----w C:\Program Files\LeapFTP2007-04-30 15:46:10 745,600 ----a-w C:\XP\system32\aswBoot.exe2007-04-30 15:41:55 85,952 ----a-w C:\XP\system32\drivers\aswmon.sys2007-04-30 15:41:42 94,552 ----a-w C:\XP\system32\drivers\aswmon2.sys2007-04-30 15:39:41 23,416 ----a-w C:\XP\system32\drivers\aswRdr.sys2007-04-30 15:38:51 43,176 ----a-w C:\XP\system32\drivers\aswTdi.sys2007-04-30 15:37:23 26,888 ----a-w C:\XP\system32\drivers\aavmker4.sys2007-04-30 15:35:28 95,872 ----a-w C:\XP\system32\AVASTSS.scr2007-04-30 08:55:32 -------- d-----w C:\Program Files\ViceVersa Pro 22007-04-26 23:09:43 -------- d-----w C:\Program Files\IsoBuster2007-04-25 08:04:12 88,952 ----a-w C:\XP\system32\packet.dll2007-04-25 08:04:12 68,480 ----a-w C:\XP\system32\wanpacket.dll2007-04-25 08:04:12 42,000 ----a-w C:\XP\system32\drivers\npf.sys2007-04-25 08:04:12 240,496 ----a-w C:\XP\system32\wpcap.dll2007-04-21 03:30:35 -------- d-----w C:\Program Files\Speed Startup2007-04-20 03:28:54 1,040,384 ----a-w C:\XP\system32\libeay32.dll2007-04-20 03:27:57 196,608 ----a-w C:\XP\system32\ssleay32.dll2007-04-16 06:45:33 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\MySpace2007-04-09 04:37:55 -------- d-----w C:\Program Files\SlySoft2007-04-09 03:42:45 29,392 ----a-w C:\XP\system32\drivers\secdrv.sys2007-04-08 22:59:29 -------- d-----w C:\Program Files\PowerISO2007-04-06 21:14:04 542 ----a-w C:\hrlist.scr2007-04-06 20:32:08 371 ----a-w C:\getbilldirs.scr2007-04-06 20:31:54 371 ----a-w C:\gethbdirs.scr2007-04-06 20:28:28 139 ----a-w C:\tryftp.scr2007-04-06 05:46:37 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\Zeon2007-04-06 05:02:00 -------- d-----w C:\Program Files\G-Lock Software2007-04-05 15:31:07 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\G-Lock Software2007-04-04 10:33:04 -------- d-----w C:\Program Files\Yahoo!2007-03-18 17:28:30 5,885 ----a-w C:\XP\mozver.dat2007-03-17 13:43:01 292,864 ----a-w C:\XP\system32\winsrv.dll2007-03-15 19:35:33 -------- d-----w C:\Program Files\Tracker2007-03-15 10:52:51 -------- d-----w C:\Program Files\Registry Watch2007-03-15 10:14:59 720,896 ----a-w C:\XP\iun6002ev.exe2007-03-15 04:18:10 -------- d-----w C:\Program Files\Salive2007-03-15 04:17:28 -------- d--h--r C:\DOCUME~1\STAYPU~1\APPLIC~1\yahoo!2007-03-08 15:36:28 577,536 ----a-w C:\XP\system32\user32.dll2007-03-08 15:36:28 40,960 ----a-w C:\XP\system32\mf3216.dll2007-03-08 15:36:28 281,600 ----a-w C:\XP\system32\gdi32.dll2007-03-08 13:47:48 1,843,584 ----a-w C:\XP\system32\win32k.sys2007-03-08 04:59:59 -------- d-----w C:\Program Files\DirPrn2007-03-07 09:16:28 -------- d-----w C:\Program Files\'Net Monitor2007-03-07 09:13:15 -------- d-----w C:\Program Files\PTZone2007-03-07 09:10:26 -------- d-----w C:\Program Files\WinWatch2007-03-07 09:10:21 249,856 ------w C:\XP\Setup1.exe2007-03-07 09:10:09 -------- d-----w C:\Program Files\LanMon2007-03-07 09:09:11 73,216 ------w C:\XP\ST6UNST.EXE2007-02-28 08:59:01 26,000 ----a-w C:\XP\system32\E3TL.DLL2007-02-05 20:17:02 185,344 ----a-w C:\XP\system32\upnphost.dll(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2004-05-12 01:03]{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21]{AE7CD045-E861-484f-8273-0445EE161910}=D:\Acrobat7\Acrobat\AcroIEFavClient.dll [2005-09-24 00:41][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SpeedStartup"="C:\Program Files\Speed Startup\speedstartup.exe" [2006-12-14 17:12][HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]"SpeedStartup"=C:\Program Files\Speed Startup\speedstartup.exe runonce[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="D:\Internet\eudora\EuShlExt.dll" [2005-11-14 16:15][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]C:\Program Files\SpywareDetector\SDNotify.dll[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]Authentication Packages msv1_0 relog_ap[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*Contents of the 'Scheduled Tasks' folder2007-05-20 06:01:04 C:\XP\tasks\_viceversapr2_task_Ascend.job2007-05-20 11:19:10 C:\XP\tasks\_viceversapr2_task_Bashful2Booby.job2007-05-20 11:30:08 C:\XP\tasks\_viceversapr2_task_batch.job2007-05-20 18:01:35 C:\XP\tasks\_viceversapr2_task_Bills.job2007-03-26 09:40:18 C:\XP\tasks\_viceversapr2_task_documents_and_settings.job2007-05-20 11:20:37 C:\XP\tasks\_viceversapr2_task_Eudora.job2007-05-20 18:01:25 C:\XP\tasks\_viceversapr2_task_hits prg to Tweetie D.job2007-05-20 06:20:36 C:\XP\tasks\_viceversapr2_task_HITSSOURCES.job2007-05-20 14:00:31 C:\XP\tasks\_viceversapr2_task_HITSVEN.job2007-05-20 13:18:16 C:\XP\tasks\_viceversapr2_task_Idisk.job2007-05-20 13:00:22 C:\XP\tasks\_viceversapr2_task_Links.job2007-03-26 09:33:37 C:\XP\tasks\_viceversapr2_task_madden.job2007-05-20 08:50:46 C:\XP\tasks\_viceversapr2_task_newag.job2007-05-20 10:32:16 C:\XP\tasks\_viceversapr2_task_OHITS.job2007-05-20 11:34:08 C:\XP\tasks\_viceversapr2_task_personal.job2007-05-20 14:00:39 C:\XP\tasks\_viceversapr2_task_ServersAlive.job2007-05-20 11:45:13 C:\XP\tasks\_viceversapr2_task_Steviebone.job2007-03-26 11:38:02 C:\XP\tasks\_viceversapr2_task_Torrents.job2007-05-20 18:45:01 C:\XP\tasks\_viceversapr2_task_txdot.job2007-05-20 11:20:07 C:\XP\tasks\_viceversapr2_task_visaversaprofiles.job********************************************************************catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.netRootkit scan 2007-05-20 13:54:48Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ...scanning hidden autostart entries ...scanning hidden files ...scan completed successfullyhidden files: 0********************************************************************Completion time: 2007-05-20 14:04:04 - machine was rebootedC:\ComboFix-quarantined-files.txt ... 2007-05-20 14:04 --- E O F --- Quote Link to post Share on other sites
Steviebone Posted May 20, 2007 Author Report Share Posted May 20, 2007 ok, still got a rootkit and the windows installer is still persisting... how can I stop this from running, where in the registry would this be found and how do I stop it from repeatedlt reopening?"Staypuffer" - 2007-05-20 14:18:51 Service Pack 2 ComboFix 07-05.20.9.V - Running from: "J:\Spywaredetector\" Rootkit driver lzx32 is present. A rootkit scan is required ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-20 ))))))))))))))))))))))))))))))))))2007-05-20 14:04 49,152 --a------ C:\XP\nircmd.exe2007-05-20 06:42 2,922 --a------ C:\XP\system32\IE_Backup.reg2007-05-20 06:42 2,846,854 --a------ C:\XP\system32\Windows_Backup.reg2007-05-20 06:42 2,588 --a------ C:\XP\system32\startupBackup.reg2007-05-20 02:27 123 --a------ C:\XP\system\SysSD.dll2007-05-20 02:26 63,192 --a------ C:\XP\system32\CloseAll.exe2007-05-20 02:26 270,336 --a------ C:\XP\system32\CheckDll.dll2007-05-20 02:26 1,019,904 --a------ C:\XP\system32\VchReg.dll2007-05-20 02:25 <DIR> d-------- C:\Program Files\SpywareDetector2007-05-19 18:15 22,080 --a------ C:\XP\system32\drivers\sshrmd.sys2007-05-19 18:15 21,056 --a------ C:\XP\system32\drivers\sskbfd.sys2007-05-19 18:15 20,544 --a------ C:\XP\system32\drivers\SSFS0509.sys2007-05-19 18:15 144,960 --a------ C:\XP\system32\drivers\ssidrv.sys2007-05-19 18:15 <DIR> d-------- C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\Webroot2007-05-19 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Webroot2007-05-19 18:08 164 --a------ C:\install.dat2007-05-19 18:08 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Webroot2007-05-18 11:43 <DIR> d--h----- C:\XP\system32\GroupPolicy2007-05-17 22:04 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Texture Maker2007-05-17 22:03 <DIR> d-------- C:\Program Files\Texture Maker2007-05-17 17:39 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Google2007-05-15 13:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Spybot - Search & Destroy2007-05-08 01:29 <DIR> d-------- C:\Program Files\Network Chemistry2007-05-08 01:17 <DIR> d-------- C:\Program Files\WinPcap2007-05-08 01:17 <DIR> d-------- C:\Program Files\Nmap2007-04-26 18:37 298,496 --a------ C:\XP\uninst.exe(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))2007-05-17 22:39:02 -------- d-----w C:\Program Files\Google2007-05-16 04:57:49 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\WeatherBug2007-05-15 21:02:01 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\dvdcss2007-05-15 18:38:06 -------- d-----w C:\Program Files\MySpace2007-05-07 17:28:32 -------- d-----w C:\Program Files\EPSON Print CD2007-05-07 13:39:36 298,104 ----a-w C:\XP\system32\imon.dll2007-05-07 13:39:34 512,096 ----a-w C:\XP\system32\drivers\amon.sys2007-05-07 13:39:33 15,424 ----a-w C:\XP\system32\drivers\nod32drv.sys2007-05-03 05:49:55 -------- d-----w C:\Program Files\LeapFTP2007-04-30 15:46:10 745,600 ----a-w C:\XP\system32\aswBoot.exe2007-04-30 15:41:55 85,952 ----a-w C:\XP\system32\drivers\aswmon.sys2007-04-30 15:41:42 94,552 ----a-w C:\XP\system32\drivers\aswmon2.sys2007-04-30 15:39:41 23,416 ----a-w C:\XP\system32\drivers\aswRdr.sys2007-04-30 15:38:51 43,176 ----a-w C:\XP\system32\drivers\aswTdi.sys2007-04-30 15:37:23 26,888 ----a-w C:\XP\system32\drivers\aavmker4.sys2007-04-30 15:35:28 95,872 ----a-w C:\XP\system32\AVASTSS.scr2007-04-30 08:55:32 -------- d-----w C:\Program Files\ViceVersa Pro 22007-04-26 23:09:43 -------- d-----w C:\Program Files\IsoBuster2007-04-25 08:04:12 88,952 ----a-w C:\XP\system32\packet.dll2007-04-25 08:04:12 68,480 ----a-w C:\XP\system32\wanpacket.dll2007-04-25 08:04:12 42,000 ----a-w C:\XP\system32\drivers\npf.sys2007-04-25 08:04:12 240,496 ----a-w C:\XP\system32\wpcap.dll2007-04-21 03:30:35 -------- d-----w C:\Program Files\Speed Startup2007-04-20 03:28:54 1,040,384 ----a-w C:\XP\system32\libeay32.dll2007-04-20 03:27:57 196,608 ----a-w C:\XP\system32\ssleay32.dll2007-04-16 06:45:33 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\MySpace2007-04-09 04:37:55 -------- d-----w C:\Program Files\SlySoft2007-04-09 03:42:45 29,392 ----a-w C:\XP\system32\drivers\secdrv.sys2007-04-08 22:59:29 -------- d-----w C:\Program Files\PowerISO2007-04-06 21:14:04 542 ----a-w C:\hrlist.scr2007-04-06 20:32:08 371 ----a-w C:\getbilldirs.scr2007-04-06 20:31:54 371 ----a-w C:\gethbdirs.scr2007-04-06 20:28:28 139 ----a-w C:\tryftp.scr2007-04-06 05:46:37 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\Zeon2007-04-06 05:02:00 -------- d-----w C:\Program Files\G-Lock Software2007-04-05 15:31:07 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\G-Lock Software2007-04-04 10:33:04 -------- d-----w C:\Program Files\Yahoo!2007-03-18 17:28:30 5,885 ----a-w C:\XP\mozver.dat2007-03-17 13:43:01 292,864 ----a-w C:\XP\system32\winsrv.dll2007-03-15 19:35:33 -------- d-----w C:\Program Files\Tracker2007-03-15 10:52:51 -------- d-----w C:\Program Files\Registry Watch2007-03-15 10:14:59 720,896 ----a-w C:\XP\iun6002ev.exe2007-03-15 04:18:10 -------- d-----w C:\Program Files\Salive2007-03-15 04:17:28 -------- d--h--r C:\DOCUME~1\STAYPU~1\APPLIC~1\yahoo!2007-03-08 15:36:28 577,536 ----a-w C:\XP\system32\user32.dll2007-03-08 15:36:28 40,960 ----a-w C:\XP\system32\mf3216.dll2007-03-08 15:36:28 281,600 ----a-w C:\XP\system32\gdi32.dll2007-03-08 13:47:48 1,843,584 ----a-w C:\XP\system32\win32k.sys2007-03-08 04:59:59 -------- d-----w C:\Program Files\DirPrn2007-03-07 09:16:28 -------- d-----w C:\Program Files\'Net Monitor2007-03-07 09:13:15 -------- d-----w C:\Program Files\PTZone2007-03-07 09:10:26 -------- d-----w C:\Program Files\WinWatch2007-03-07 09:10:21 249,856 ------w C:\XP\Setup1.exe2007-03-07 09:10:09 -------- d-----w C:\Program Files\LanMon2007-03-07 09:09:11 73,216 ------w C:\XP\ST6UNST.EXE2007-02-28 08:59:01 26,000 ----a-w C:\XP\system32\E3TL.DLL2007-02-05 20:17:02 185,344 ----a-w C:\XP\system32\upnphost.dll(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2004-05-12 01:03]{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21]{AE7CD045-E861-484f-8273-0445EE161910}=D:\Acrobat7\Acrobat\AcroIEFavClient.dll [2005-09-24 00:41][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SpeedStartup"="C:\Program Files\Speed Startup\speedstartup.exe" [2006-12-14 17:12][HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]"SpeedStartup"=C:\Program Files\Speed Startup\speedstartup.exe runonce[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="D:\Internet\eudora\EuShlExt.dll" [2005-11-14 16:15][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]C:\Program Files\SpywareDetector\SDNotify.dll[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]Authentication Packages msv1_0 relog_ap[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*Contents of the 'Scheduled Tasks' folder2007-05-20 06:01:04 C:\XP\tasks\_viceversapr2_task_Ascend.job2007-05-20 11:19:10 C:\XP\tasks\_viceversapr2_task_Bashful2Booby.job2007-05-20 11:30:08 C:\XP\tasks\_viceversapr2_task_batch.job2007-05-20 19:30:03 C:\XP\tasks\_viceversapr2_task_Bills.job2007-03-26 09:40:18 C:\XP\tasks\_viceversapr2_task_documents_and_settings.job2007-05-20 11:20:37 C:\XP\tasks\_viceversapr2_task_Eudora.job2007-05-20 19:00:31 C:\XP\tasks\_viceversapr2_task_hits prg to Tweetie D.job2007-05-20 06:20:36 C:\XP\tasks\_viceversapr2_task_HITSSOURCES.job2007-05-20 14:00:31 C:\XP\tasks\_viceversapr2_task_HITSVEN.job2007-05-20 13:18:16 C:\XP\tasks\_viceversapr2_task_Idisk.job2007-05-20 13:00:22 C:\XP\tasks\_viceversapr2_task_Links.job2007-03-26 09:33:37 C:\XP\tasks\_viceversapr2_task_madden.job2007-05-20 08:50:46 C:\XP\tasks\_viceversapr2_task_newag.job2007-05-20 10:32:16 C:\XP\tasks\_viceversapr2_task_OHITS.job2007-05-20 11:34:08 C:\XP\tasks\_viceversapr2_task_personal.job2007-05-20 14:00:39 C:\XP\tasks\_viceversapr2_task_ServersAlive.job2007-05-20 11:45:13 C:\XP\tasks\_viceversapr2_task_Steviebone.job2007-03-26 11:38:02 C:\XP\tasks\_viceversapr2_task_Torrents.job2007-05-20 18:45:01 C:\XP\tasks\_viceversapr2_task_txdot.job2007-05-20 11:20:07 C:\XP\tasks\_viceversapr2_task_visaversaprofiles.job********************************************************************catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.netRootkit scan 2007-05-20 14:31:41Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ...scanning hidden autostart entries ...scanning hidden files ...scan completed successfullyhidden files: 0********************************************************************Completion time: 2007-05-20 14:38:44 - machine was rebootedC:\ComboFix-quarantined-files.txt ... 2007-05-20 14:38C:\ComboFix2.txt ... 2007-05-20 14:04 --- E O F --- Quote Link to post Share on other sites
Steviebone Posted May 20, 2007 Author Report Share Posted May 20, 2007 ran rustockbfix exe then got this:Rustock.b-ADS attached to the System32-folder:Attempting to remove ADS...Looking for Rustock.b-files in the System32-folder:ECHO is off.******************* Post-run Status of system *******************Rustock.b-driver on the system: YOU NEED TO CONSULT MORE ADVANCED TOOLS!!The Gmer-rootkitscanner may be a good place to start.Gmer rootkit-scanner may be found here: http://www.gmer.netRustock.b-ADS attached to the System32-folder:ECHO is off.You should either run the tool again or consult more advanced toolsThe Gmer-rootkitscanner may be a good place to start.Gmer rootkit-scanner may be found here: http://www.gmer.netLooking for Rustock.b-files in the System32-folder:ECHO is off.You should either run the tool again or consult more advanced toolsSwandog46's Avenger or Gmer's-rootkitscanner may be a good place to start.Swandog46's Avenger may be found here: http://swandog46.geekstogo.com/avengernotes.htmGmer rootkit-scanner may be found here: http://www.gmer.net******************************* End of Logfile ******************************** Quote Link to post Share on other sites
Steviebone Posted May 20, 2007 Author Report Share Posted May 20, 2007 so I ran gmer... I have no idea what to do with this information: GMER 1.0.12.12244 - http://www.gmer.net Rootkit scan 2007-05-20 17:02:03 Windows 5.1.2600 Service Pack 2 ---- System - GMER 1.0.12 ---- SSDT 82F60CD8 ZwAllocateVirtualMemory SSDT a347bus.sys ZwClose SSDT 82FAE198 ZwCreateKey SSDT a347bus.sys ZwCreatePagingFile SSDT 82FE4880 ZwCreateProcess SSDT 82F7AB70 ZwCreateProcessEx SSDT 82F60FA8 ZwCreateThread SSDT 82FAD338 ZwDeleteKey SSDT 82FED248 ZwDeleteValueKey SSDT a347bus.sys ZwEnumerateKey SSDT a347bus.sys ZwEnumerateValueKey SSDT a347bus.sys ZwOpenFile SSDT a347bus.sys ZwOpenKey SSDT a347bus.sys ZwQueryKey SSDT a347bus.sys ZwQueryValueKey SSDT 82F60D50 ZwQueueApcThread SSDT 82F60BE8 ZwReadVirtualMemory SSDT 82FCBB38 ZwRenameKey SSDT 82F60E40 ZwSetContextThread SSDT 82FE75C0 ZwSetInformationKey SSDT 82F77210 ZwSetInformationProcess SSDT 82F60EB8 ZwSetInformationThread SSDT a347bus.sys ZwSetSystemPowerState SSDT 82FAD680 ZwSetValueKey SSDT 82F77198 ZwSuspendProcess SSDT 82F60DC8 ZwSuspendThread SSDT 82F77288 ZwTerminateProcess SSDT 82F60F30 ZwTerminateThread SSDT 82F60C60 ZwWriteVirtualMemory ---- Kernel code sections - GMER 1.0.12 ---- ? C:\XP\System32\DRIVERS\update.sys ---- User code sections - GMER 1.0.12 ---- .text C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe[1044] kernel32.dll!CreateThread + 1A 7C810651 4 Bytes [ AB, FA, C3, 83 ] ---- Devices - GMER 1.0.12 ---- Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82F992B0 Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE 829A6550 Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE 829A33D8 Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE 829A5B88 Device \Driver\Tcpip \Device\Ip IRP_MJ_READ 829A5A60 Device \Driver\Tcpip \Device\Ip IRP_MJ_WRITE 829A5938 Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION 829A5810 Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION 829A56E8 Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA 829A4C60 Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA 829A4B38 Device \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS 829A4A10 Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION 829A48E8 Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION 829A3E58 Device \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL 82983D90 Device \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL 82983C68 Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL 82983B40 Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL 829D2DA0 Device \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN 829D2C88 Device \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL 829D2B60 Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP 829D2A38 Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT 829D2910 Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY 829D27E8 Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY 829D26C0 Device \Driver\Tcpip \Device\Ip IRP_MJ_POWER 829D2598 Device \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL 829D2470 Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE 829D2348 Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA 829D2220 Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA 829D1FA8 Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP 829D1E90 Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE 829A6550 Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE 829A33D8 Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE 829A5B88 Device \Driver\Tcpip \Device\Tcp IRP_MJ_READ 829A5A60 Device \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE 829A5938 Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION 829A5810 Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION 829A56E8 Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA 829A4C60 Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA 829A4B38 Device \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS 829A4A10 Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION 829A48E8 Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION 829A3E58 Device \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL 82983D90 Device \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL 82983C68 Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL 82983B40 Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL 829D2DA0 Device \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN 829D2C88 Device \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL 829D2B60 Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP 829D2A38 Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT 829D2910 Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY 829D27E8 Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY 829D26C0 Device \Driver\Tcpip \Device\Tcp IRP_MJ_POWER 829D2598 Device \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL 829D2470 Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE 829D2348 Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA 829D2220 Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA 829D1FA8 Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP 829D1E90 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_NAMED_PIPE 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_EA 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_EA 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_VOLUME_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_VOLUME_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DIRECTORY_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FILE_SYSTEM_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_LOCK_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLEANUP 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE_MAILSLOT 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_SECURITY 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_SECURITY 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CHANGE 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_QUERY_QUOTA 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SET_QUOTA 82DBD540 Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 82DBD540 Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 8245BFB0 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_NAMED_PIPE 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_EA 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_EA 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_VOLUME_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_VOLUME_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DIRECTORY_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FILE_SYSTEM_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_LOCK_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLEANUP 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE_MAILSLOT 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_SECURITY 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_SECURITY 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CHANGE 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_QUERY_QUOTA 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SET_QUOTA 82DBD540 Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 82DBD540 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_NAMED_PIPE 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_READ 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_WRITE 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FLUSH_BUFFERS 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DIRECTORY_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_FILE_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SHUTDOWN 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_LOCK_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLEANUP 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE_MAILSLOT 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CHANGE 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_QUERY_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SET_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_NAMED_PIPE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLOSE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_READ 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_WRITE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_FLUSH_BUFFERS 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DIRECTORY_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_FILE_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SHUTDOWN 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_LOCK_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CLEANUP 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_CREATE_MAILSLOT 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_POWER 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_DEVICE_CHANGE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_QUERY_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_SET_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 IRP_MJ_PNP 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_NAMED_PIPE 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_READ 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_WRITE 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FLUSH_BUFFERS 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DIRECTORY_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_FILE_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SHUTDOWN 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_LOCK_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLEANUP 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE_MAILSLOT 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CHANGE 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_QUERY_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SET_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE_NAMED_PIPE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLOSE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_READ 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_WRITE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_FLUSH_BUFFERS 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DIRECTORY_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_FILE_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_INTERNAL_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SHUTDOWN 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_LOCK_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CLEANUP 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_CREATE_MAILSLOT 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_POWER 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_DEVICE_CHANGE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_QUERY_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_SET_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c IRP_MJ_PNP 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_CREATE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_CREATE_NAMED_PIPE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_CLOSE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_READ 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_WRITE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_QUERY_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SET_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_QUERY_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SET_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_FLUSH_BUFFERS 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_QUERY_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SET_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_DIRECTORY_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_FILE_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_INTERNAL_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SHUTDOWN 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_LOCK_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_CLEANUP 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_CREATE_MAILSLOT 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_QUERY_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SET_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_POWER 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_DEVICE_CHANGE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_QUERY_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_SET_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 IRP_MJ_PNP 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_CREATE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_CREATE_NAMED_PIPE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_CLOSE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_READ 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_WRITE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_QUERY_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SET_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_QUERY_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SET_EA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_FLUSH_BUFFERS 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_QUERY_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SET_VOLUME_INFORMATION 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_DIRECTORY_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_FILE_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_INTERNAL_DEVICE_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SHUTDOWN 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_LOCK_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_CLEANUP 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_CREATE_MAILSLOT 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_QUERY_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SET_SECURITY 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_POWER 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SYSTEM_CONTROL 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_DEVICE_CHANGE 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_QUERY_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_SET_QUOTA 82DB42E0 Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 IRP_MJ_PNP 82DB42E0 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_NAMED_PIPE 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_EA 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_EA 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_VOLUME_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_VOLUME_INFORMATION 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DIRECTORY_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FILE_SYSTEM_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_LOCK_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLEANUP 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE_MAILSLOT 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_SECURITY 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_SECURITY 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CHANGE 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_QUERY_QUOTA 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SET_QUOTA 82DBD540 Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 82DBD540 Device \FileSystem\Srv \Device\LanmanServer IRP_MJ_READ 82016E98 Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE 829A6550 Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE 829A33D8 Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE 829A5B88 Device \Driver\Tcpip \Device\Udp IRP_MJ_READ 829A5A60 Device \Driver\Tcpip \Device\Udp IRP_MJ_WRITE 829A5938 Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION 829A5810 Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION 829A56E8 Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA 829A4C60 Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA 829A4B38 Device \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS 829A4A10 Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION 829A48E8 Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION 829A3E58 Device \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL 82983D90 Device \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL 82983C68 Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL 82983B40 Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL 829D2DA0 Device \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN 829D2C88 Device \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL 829D2B60 Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP 829D2A38 Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT 829D2910 Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY 829D27E8 Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY 829D26C0 Device \Driver\Tcpip \Device\Udp IRP_MJ_POWER 829D2598 Device \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL 829D2470 Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE 829D2348 Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA 829D2220 Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA 829D1FA8 Device \Driver\Tcpip \Device\Udp IRP_MJ_PNP 829D1E90 Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE 829A6550 Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE 829A33D8 Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE 829A5B88 Device \Driver\Tcpip \Device\RawIp IRP_MJ_READ 829A5A60 Device \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE 829A5938 Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION 829A5810 Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION 829A56E8 Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA 829A4C60 Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA 829A4B38 Device \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS 829A4A10 Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION 829A48E8 Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION 829A3E58 Device \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL 82983D90 Device \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL 82983C68 Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL 82983B40 Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL 829D2DA0 Device \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN 829D2C88 Device \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL 829D2B60 Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP 829D2A38 Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT 829D2910 Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY 829D27E8 Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY 829D26C0 Device \Driver\Tcpip \Device\RawIp IRP_MJ_POWER 829D2598 Device \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL 829D2470 Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE 829D2348 Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA 829D2220 Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA 829D1FA8 Device \Driver\Tcpip \Device\RawIp IRP_MJ_PNP 829D1E90 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 824B8708 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE 829A6550 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_NAMED_PIPE 829A33D8 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE 829A5B88 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_READ 829A5A60 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_WRITE 829A5938 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_INFORMATION 829A5810 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_INFORMATION 829A56E8 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_EA 829A4C60 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_EA 829A4B38 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FLUSH_BUFFERS 829A4A10 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_VOLUME_INFORMATION 829A48E8 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_VOLUME_INFORMATION 829A3E58 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DIRECTORY_CONTROL 82983D90 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FILE_SYSTEM_CONTROL 82983C68 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL 82983B40 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL 829D2DA0 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SHUTDOWN 829D2C88 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_LOCK_CONTROL 829D2B60 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP 829D2A38 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_MAILSLOT 829D2910 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_SECURITY 829D27E8 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_SECURITY 829D26C0 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_POWER 829D2598 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SYSTEM_CONTROL 829D2470 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CHANGE 829D2348 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_QUOTA 829D2220 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_QUOTA 829D1FA8 Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_PNP 829D1E90 Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 824B8708 Device \FileSystem\Npfs \Device\NamedPipe IRP_MJ_READ 8294FE70 Device \FileSystem\Msfs \Device\Mailslot IRP_MJ_READ 829DB400 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CREATE 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CREATE_NAMED_PIPE 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CLOSE 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_READ 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_WRITE 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_INFORMATION 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_INFORMATION 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_EA 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_EA 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_FLUSH_BUFFERS 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_VOLUME_INFORMATION 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_VOLUME_INFORMATION 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_DIRECTORY_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_FILE_SYSTEM_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_DEVICE_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SHUTDOWN 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_LOCK_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CLEANUP 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_CREATE_MAILSLOT 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_SECURITY 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_SECURITY 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_POWER 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SYSTEM_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_DEVICE_CHANGE 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_QUERY_QUOTA 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_SET_QUOTA 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1 IRP_MJ_PNP 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_CREATE 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_CREATE_NAMED_PIPE 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_CLOSE 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_READ 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_WRITE 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_QUERY_INFORMATION 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_SET_INFORMATION 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_QUERY_EA 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_SET_EA 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_FLUSH_BUFFERS 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_QUERY_VOLUME_INFORMATION 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_SET_VOLUME_INFORMATION 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_DIRECTORY_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_FILE_SYSTEM_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_SHUTDOWN 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_LOCK_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_CLEANUP 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_CREATE_MAILSLOT 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_QUERY_SECURITY 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_SET_SECURITY 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_POWER 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_DEVICE_CHANGE 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_QUERY_QUOTA 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_SET_QUOTA 82D47008 Device \Driver\a347scsi \Device\Scsi\a347scsi1Port3Path0Target0Lun0 IRP_MJ_PNP 82D47008 Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_READ 8294DFB0 Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_READ 8294DFB0 Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_READ 8294DFB0 Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_READ 8294DFB0 Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_READ 8294DFB0 Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 824A9458 ---- Modules - GMER 1.0.12 ---- Module _________ F853D000-F8555000 (98304 bytes) ---- Registry - GMER 1.0.12 ---- Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x46 0x47 0x15 0xB0 ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x25 0xDA 0xEC 0x7E ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ... Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\XP\system32\OLE32.DLL Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ... Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\[email protected] 277C3E89C499B260DD37410948245D4EF0F20E10950C565FF78C1B98AB8108FD49B9A5D4B4BC8A91 1C20E908F74267BDB63C6AB7C7F066FC361E452196606E00606F1C0E8C9AEFE583CB87EBB390683DE 869A138AE71EAD95A91193F0A4DC2FCB36A5A29117C23C3040D44D3BBEC60EE3F716FFEA3A443F604 22034E972F67716D4A1F0DAEC324C47089CED3F2CC122AD61F92ED23339508B961731AF4857F0F9A0 6AA94F1E139B5013BD974633704792F91CFD8CFDA49F1E4B0DFE57B6476B8AFE3440E0F5F6D99D06F 1DB038CA829B2DBA6F0AEB6C8953D1C9FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CF EBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667C038D530D6EB3452C0 38D530D6EB3452A6171C11EC38DE3D8F36E2B830ED536A1FE23375D0DC89E38A98A9CE7ED5A4E9AA7 5EBD488D5586AA24CCE959D5C24FC6114136BD03AD5DF429EB19F3FBE9CB8A72832553B26ABB53937 96540ADF6D7028C3D90EB6A3442605B37308E8545D4327AC7684DC3695BBA32BBE875A726A2FD1F22 2A6C5ECF8E8E347C2A74066169E8B7C6AF4D4726F14334F6D59B3BC3BF8C216AC91089C7D2AF23B9C 325078D9343A86DE4FCBFCF32DBFBFEF84839EE5616218DFC1C8EF40C3CB651C6B62459D3F9D2F4B4 D32ABC149248D365AF629D1CB9B55443A18D392DF0A0F05AD0BB Reg \Registry\USER\S-1-5-21-527237240-854245398-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0AF7744A-9721-FDD5-BA18-A9578358D751}@hadnkljcbmkdoggg 0x67 0x61 0x6B 0x6C ... Reg \Registry\USER\S-1-5-21-527237240-854245398-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0AF7744A-9721-FDD5-BA18-A9578358D751}@iaponpeaajedpgikna 0x63 0x61 0x68 0x6B ... Reg \Registry\USER\S-1-5-21-527237240-854245398-1343024091-1003\Software\Zepter Software\RegLib Reg \Registry\USER\S-1-5-21-527237240-854245398-1343024091-1003\Software\Zepter Software\RegLib ---- EOF - GMER 1.0.12 ---- Quote Link to post Share on other sites
Steviebone Posted May 21, 2007 Author Report Share Posted May 21, 2007 I ran avg in safe mode, reran combofix, and for a brief period it looked as tho this might have done it... but alas... the windows installer for vfp9 persisted popping up continuously on every reboot until I let it run... here is the avg and another current hijack log:Logfile of HijackThis v1.99.1Scan saved at 1:24:51 AM, on 5/21/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\XP\System32\smss.exeC:\XP\system32\winlogon.exeC:\XP\system32\services.exeC:\XP\system32\lsass.exeC:\XP\system32\svchost.exeC:\XP\System32\svchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\XP\system32\spoolsv.exeC:\Program Files\Acronis\BackupServer\backupserver.exeC:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\Program Files\Eset\nod32krn.exeC:\XP\system32\nvsvc32.exeC:\Program Files\SpywareDetector\SDService.exeC:\XP\System32\svchost.exeC:\XP\Explorer.EXEC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\XP\system32\wuauclt.exeC:\Program Files\Eset\nod32kui.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exeC:\Program Files\SpywareDetector\SDSystemTray.exeC:\Program Files\PTSync\PTSync.exeC:\Program Files\Acronis\TrueImageEnterpriseServer\TRUEIM~3.EXEC:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exeC:\Program Files\Acronis\TrueImageEnterpriseServer\TIMOUN~1.EXEC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\Program Files\Webroot\Spy Sweeper\SSU.EXEC:\Program Files\Hijackthis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.americansingles.com/O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dllO2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Acrobat7\Acrobat\AcroIEFavClient.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Acrobat7\Acrobat\AcroIEFavClient.dllO3 - Toolbar: Cooxie - {DC99E960-6594-45e3-9D5D-141D825B8096} - C:\Program Files\Cooxie Toolbar\PrvcBand.dllO4 - HKLM\..\Run: [spySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintrayO4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimizedO4 - HKLM\..\RunOnce: [speedStartup] "C:\Program Files\Speed Startup\speedstartup.exe" runonceO4 - HKCU\..\Run: [speedStartup] "C:\Program Files\Speed Startup\speedstartup.exe" bootupO8 - Extra context menu item: Add to &Teleport - D:\TeleportUltra\teleport.htmO8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert link target to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlO8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlO8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert selection to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MsOffice\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://D:\OmniPage15\PDFConverter3\IEShellExt.dll /100O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dllO9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dllO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dllO9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dllO9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MsOffice\OFFICE11\REFIEBAR.DLLO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1145986548799O17 - HKLM\System\CCS\Services\Tcpip\..\{90F742E6-14BD-42BD-B353-7487933899E6}: NameServer = 66.254.6.2,66.254.1.2O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dllO20 - Winlogon Notify: SDNotify - C:\Program Files\SpywareDetector\SDNotify.dllO20 - Winlogon Notify: WgaLogon - C:\XP\SYSTEM32\WgaLogon.dllO20 - Winlogon Notify: WRNotifier - C:\XP\SYSTEM32\WRLogonNTF.dllO23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exeO23 - Service: Acronis Backup Server Service (AcronisBackupServerService) - Acronis - C:\Program Files\Acronis\BackupServer\backupserver.exeO23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeO23 - Service: Arcana Notification Agent (adnotify) - Unknown owner - C:\Program Files\Arcana Development\Notification Agent\ADNotify.exeO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: Arcana Scheduler - Arcana Development - C:\Program Files\Arcana Development\Arcana Scheduler\adscheduler.exeO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Acronis Group Server (GroupServer) - Acronis - C:\Program Files\Acronis\GroupServer\GroupServer.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\XP\system32\drivers\KodakCCS.exeO23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exeO23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exeO23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\XP\system32\nvsvc32.exeO23 - Service: O&O Defrag - O&O Software GmbH - C:\XP\system32\oodag.exeO23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - C:\Program Files\Zenturi\ProgramChecker\sassvc.exeO23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exeO23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeavg:---------------------------------------------------------AVG Anti-Spyware - Scan Report--------------------------------------------------------- + Created at: 11:32:38 PM 5/20/2007 + Scan result: F:\Audio Programs and Plugins\Holding\CyberlinkPower2go\CyberLink.Power2Go.Deluxe.v5.50.2614.Multilingual.Incl.Keymaker\keygen.exe -> Logger.Banker : Cleaned.F:\Audio Programs and Plugins\Holding\XPGenuine\Make Windows XP Genuine\3) Genuine.rar/Port_RockXP_v4.exe/RockXP4.exe -> Not-A-Virus.PSWTool.Win32.RAS.a : Cleaned.:mozilla.355:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.356:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.357:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.358:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.359:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.360:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.361:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.362:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.363:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.364:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.365:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.366:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.367:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.368:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.369:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.370:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.371:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.372:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.373:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.374:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.375:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.376:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.377:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.378:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.379:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.380:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.381:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.382:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.383:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.384:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.385:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.386:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.387:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.388:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.389:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.390:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.391:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.392:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.393:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.394:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.395:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.396:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.397:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.398:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.399:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.400:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.401:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.402:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.403:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.404:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.405:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.510:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.559:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.676:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.695:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.730:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.761:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.820:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.839:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.:mozilla.450:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.:mozilla.451:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.:mozilla.452:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.:mozilla.453:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.:mozilla.241:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.:mozilla.242:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.:mozilla.243:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.:mozilla.245:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.:mozilla.250:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.:mozilla.251:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.:mozilla.252:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.:mozilla.253:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.:mozilla.254:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.:mozilla.179:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.:mozilla.180:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.:mozilla.182:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.:mozilla.183:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.:mozilla.184:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.:mozilla.186:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.:mozilla.87:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.:mozilla.420:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.:mozilla.892:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.:mozilla.416:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.:mozilla.417:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.:mozilla.418:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.:mozilla.419:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.:mozilla.192:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.:mozilla.193:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.:mozilla.194:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.:mozilla.195:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.:mozilla.196:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.:mozilla.197:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.:mozilla.198:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.:mozilla.200:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.:mozilla.201:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.:mozilla.694:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.:mozilla.869:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.:mozilla.870:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.:mozilla.871:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.:mozilla.872:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.:mozilla.503:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.:mozilla.504:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.:mozilla.505:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.:mozilla.506:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.:mozilla.142:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.:mozilla.143:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.:mozilla.261:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.:mozilla.262:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.:mozilla.263:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.:mozilla.264:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.:mozilla.265:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.:mozilla.244:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.:mozilla.246:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.:mozilla.247:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.:mozilla.248:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.:mozilla.249:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.:mozilla.110:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.:mozilla.447:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.:mozilla.464:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.:mozilla.556:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.:mozilla.574:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.:mozilla.585:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.:mozilla.650:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.:mozilla.655:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.:mozilla.660:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.:mozilla.224:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.225:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.227:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.228:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.231:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.232:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.704:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.705:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.706:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.707:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.708:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.709:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.896:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.:mozilla.115:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.:mozilla.927:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.:mozilla.786:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.:mozilla.787:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.:mozilla.539:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.:mozilla.540:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.:mozilla.541:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.:mozilla.283:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.:mozilla.284:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.:mozilla.331:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Msn : Cleaned.:mozilla.332:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Msn : Cleaned.:mozilla.335:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Msn : Cleaned.:mozilla.7:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.:mozilla.8:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.:mozilla.9:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.:mozilla.931:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.:mozilla.932:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.:mozilla.727:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.:mozilla.728:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.:mozilla.729:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.:mozilla.428:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.:mozilla.255:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.:mozilla.256:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.:mozilla.257:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.:mozilla.258:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.:mozilla.259:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.:mozilla.260:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.:mozilla.285:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.:mozilla.286:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.:mozilla.287:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.:mozilla.288:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.:mozilla.289:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.:mozilla.290:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.:mozilla.291:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.:mozilla.602:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.:mozilla.603:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.:mozilla.604:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.:mozilla.605:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.:mozilla.606:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.:mozilla.607:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.:mozilla.608:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.:mozilla.609:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.:mozilla.610:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.:mozilla.629:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.:mozilla.205:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.206:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.207:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.208:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.209:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.210:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.211:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.212:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.213:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.214:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.215:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.216:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.217:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.218:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.219:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.220:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.221:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.222:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.223:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.:mozilla.149:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.:mozilla.150:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.:mozilla.151:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.:mozilla.152:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.:mozilla.153:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.:mozilla.154:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.:mozilla.731:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.:mozilla.732:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.:mozilla.733:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.:mozilla.734:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.:mozilla.735:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.:mozilla.736:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.:mozilla.737:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.:mozilla.738:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.:mozilla.21:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.22:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.23:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.24:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.25:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.26:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.27:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.28:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.29:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.30:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.31:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.32:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.33:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.34:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.35:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.36:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.37:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.38:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.39:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.40:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.41:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.46:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.47:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.48:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.49:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.50:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.51:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.52:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.53:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.54:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.55:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.56:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.57:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.58:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.59:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.60:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.61:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.62:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.63:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.64:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.65:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.66:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.67:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.68:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.69:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.:mozilla.421:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.:mozilla.422:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.:mozilla.423:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.:mozilla.424:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.:mozilla.920:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.:mozilla.899:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.:mozilla.266:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.:mozilla.267:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.:mozilla.268:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.:mozilla.269:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.:mozilla.270:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.:mozilla.271:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.:mozilla.272:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.:mozilla.273:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.:mozilla.274:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.:mozilla.444:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.:mozilla.148:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.:mozilla.89:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.:mozilla.128:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.:mozilla.79:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.:mozilla.944:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.:mozilla.135:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.:mozilla.136:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.:mozilla.137:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.:mozilla.138:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.:mozilla.139:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.:mozilla.140:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.:mozilla.141:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.:mozilla.485:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.:mozilla.486:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.:mozilla.487:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.:mozilla.488:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.C:\Program Files\Teleport Ultra\scheduler.exe -> Trojan.Agent.iu : Cleaned.D:\TeleportUltra\scheduler.exe -> Trojan.Agent.iu : Cleaned.F:\Audio Programs and Plugins\Audio Programs\Vegas\SONY.Vegas.6.0c.FULL.Include.Keymaker-PDX.zip/KEYGEN/SONYkeygen.exe -> Trojan.Pakes.edg : Cleaned.F:\Audio Programs and Plugins\Audio Programs\Vegas\install\KEYGEN\SONYkeygen.exe -> Trojan.Pakes.edg : Cleaned.D:\Acronis Complete Suite\Acronis Complete\WinRAR.v3.51.WinALL.Cracked-CORE\cr-wr351.zip/crack.exe -> Trojan.Small : Cleaned.F:\Audio Programs and Plugins\Holding\SpiderWriter\Spider_Writer_v5-20-00610\Spider_Writer_v5[1].20.0610Patch.zip/crack.exe -> Trojan.Small : Cleaned.::Report end Quote Link to post Share on other sites
jwbirdsong Posted May 21, 2007 Report Share Posted May 21, 2007 (edited) Sorry for the delay, lots going on. As you can well imaging log are our one line into your computer so the more info I have the better armed I'll be... You said you ran the Rustock.b-fix.. Was it the -- By ejvindh?? Could you post that log also please.Download and Save Blacklight Beta (graphical user interface version) to your desktop.Double-click fsbl.exe then accept the agreement.click > scan then > next,You'll see a list of all items found.Don't choose for rename yet! I want to see the log first, because legit items can also be present there... like "wbemtest.exe" :!:There will be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers)1.) Download and install Rootkit Unhooker.2.) Disconnect from the internet and close all active protection programs especially HIPs programs like Prevx1 which will interfere. Leave your firewall on.3.) Next, it is very important for you to Temporarily Disable Active Protection for any security programs you have enabled such as Prevx while we complete the fixes. You may keep firewall enabled.Click Start --> All Programs --> Rootkit Unhooker to run the program. Click Hidden Process Detector - then click File --> Quick Report and save the information on that page.Click Hidden Drivers Detector- then click File --> Quick Report and save the information on that page.Click Code Hooks Detector- then click File --> Quick Report and save the information on that page.Click Hidden Files Detector - then click Scan Do not touch your computer during the scan.At the end of the Hidden File scan, save the report and then post all four labelled reports back here.Plus the other logs asked for above.I realise that is a lot of logs to post..take as many post as you need OR if you use the ADDREPLY option (Not quick reply) there should be an attach file option, you can just attach file if you prefer.PS ADDED You may get an error about missing Windows DLL when running one of the 4 scans from Unhooker it's normal and shouldn't effect the other scans... Edited May 21, 2007 by jwbirdsong ADDED PS Quote Link to post Share on other sites
Steviebone Posted May 21, 2007 Author Report Share Posted May 21, 2007 below is the log u asked for:Rustock.b-ADS attached to the System32-folder:Attempting to remove ADS...Looking for Rustock.b-files in the System32-folder:ECHO is off.******************* Post-run Status of system *******************Rustock.b-driver on the system:YOU NEED TO CONSULT MORE ADVANCED TOOLS!!The Gmer-rootkitscanner may be a good place to start.Gmer rootkit-scanner may be found here: http://www.gmer.netRustock.b-ADS attached to the System32-folder:ECHO is off.You should either run the tool again or consult more advanced toolsThe Gmer-rootkitscanner may be a good place to start.Gmer rootkit-scanner may be found here: http://www.gmer.netLooking for Rustock.b-files in the System32-folder:ECHO is off.You should either run the tool again or consult more advanced toolsSwandog46's Avenger or Gmer's-rootkitscanner may be a good place to start.Swandog46's Avenger may be found here: http://swandog46.geekstogo.com/avengernotes.htmGmer rootkit-scanner may be found here: http://www.gmer.net----------------I then ran gmer, the log is in an above post... I had no idea what to do with the information it presented.No matter what I did, whenever I rebooted, early in the log on process I got a Windows installer trying to re-install vIsual Foxpro 9, a program which was already on my computer and running fine. No matter how many times I clicked cancel, the installer would close and immediately reopen itself. I would have to click cancel at least 12-15 times (the installer would close and then restart each time) to make the window go away for good. I fear this may have been the vehicle used to infect the machine. I could find no registry entries anywhere that where telling it to run on startup. I have several starup monitors and none of them showed an entry for it either... very suspiscious IMO. I finally got tired of hovering over the mouse all the way thru each 5 minute boot and let it do its thing to see what would happen. I said it was preparing to instal VFP9, would gather a bunch of data and then finally close without ever installing anything near as I could tell.Subsequent scans did not turn up any rootkit, however, spydetector said that rustock backdoor had been successfully removed whenever I tried to run the rust checker. So I am now assuming from reading your post that I need to close all protection programs but my firewall while performing these checks.. this may invalidate much of previous information as I have avast pro, nod32, spybot S&D, spysweeper, spydetector and now avg all loaded on the system now. So before running combofix, etc, I should have all other protection programs disabled?Running the rust checker now just returns an error after reboot saying it can't find files.I DID run the avgantirootkit in depth scan last night and it found no rootkits. However, several of the protection programs were also running at the time...current status: tho I can see no outbound in the syslogs, task manager shows continuous memory useage and constant cpu useage from 2 up to 86% even tho no applications are open. Average is probably about 12%. However, on all my other computer systems when nothing is running tactual useage hovers near zero with NO spikes. Over night, my available memory has been reduced to almost zero as well. CLosing all the protection programs only freed a small portion oif the memory and had no effect on the task manager reported cpu activity. ALl of it always gets lumped under system idle even tho the computer doesnt seem to be doing anything.I noticed there didnt seem to be anyway to unload the nod32krn from task manager, it and its memory allocation seemed to hang around no matter how I closed the app. Sam thing with Spy Sweeper... even tho it has been unloaded using its own menu the app remains in the task manager list sucking up resources even tho it is not doing anything. BTW, Spy Sweper seems to be a huge resource hog. With all of its protections enabled CPU is at near 100% all the time even with no other applications open.Maybe Im obsessing too much over the CPU activity, but having anything spiking resources when u are running some applications, especially those with real time graphics (like games for example) are adverserly noticeably affected.(sigh)... I will now try your latest suggestion and then post the results in a while.Thanks for your help, I really appreciate it. Quote Link to post Share on other sites
Steviebone Posted May 21, 2007 Author Report Share Posted May 21, 2007 I cannot reach the server where the unhooker program is located... got another link for it? How about an IP address (perhaps its a DNS issue?). Quote Link to post Share on other sites
Steviebone Posted May 21, 2007 Author Report Share Posted May 21, 2007 using the one found here: http://www.antirootkit.com/software/RootKit-Unhooker.htmhope this is the same Quote Link to post Share on other sites
Steviebone Posted May 21, 2007 Author Report Share Posted May 21, 2007 btw, whats an HIP program? (sorry for the dummie question) Quote Link to post Share on other sites
jwbirdsong Posted May 21, 2007 Report Share Posted May 21, 2007 Kind of in reverse order. whats an HIP programHost Intrusion Prevention like System Safety Monitor or Kaspersky's Proactive Defense Moduleusing the one found here: http://www.antirootkit.com/software/RootKit-Unhooker.htmhope this is the sameYep..one note on the 'usage speech' I inluded...each time you save one of the results you need to change name else it will overwrite previous result--it does NOT append.I see in my previous reply some how my link for Blacklite didn't get included.http://www.f-secure.com/exclude/blacklight/index.shtmlThen follow instruction in last post. Just make sure to get the GRAPHIC and not the commandline version.It's QUITE possible that your high CPU usage is NOW due to the fact that you have both Nod and Avast on the machine...The WILL battle for control of the system and eat up resouorces.Let's see the Unhooker logs and Blacklight log....I think we may now just be chasing your rogue startup installer. Quote Link to post Share on other sites
Steviebone Posted May 21, 2007 Author Report Share Posted May 21, 2007 ok thanks for all ur help..a couple of notes, I finally let the installer go... whatever it did it did and has not come back the last few rebootsthe rootkit program runs the hidden file scan but crashes near the end every time... Ive checked the disk for errors but nada... at the point only one file is listed in the window... to the best of my knowledege no log is ever written for that function, the other three logs are copied below..As for resource useage, in safe mode of course the task manager looks right. I disabled ALL of the programs however for these tests, following the instructions in the page you referenced AND going to startup controller and disabling all of them... I then checked on reboot and none of the programs had loaded. Even still, with NONE of those programs loaded the activity remains... including constant memory allocation changes... again task manager only indicates system idle at 98-99% even though no applications are opne there doesnt appear to be anything else running.I will download backlight next and post the results.Here are the other logs:RkUnhooker report generator v0.6==============================================Rootkit Unhooker kernel version: 3.31.150.420==============================================Windows Major Version: 5Windows Minor Version: 1Windows Build Number: 2600==============================================Process: SystemProcess Id: 4EPROCESS Address: 0x82FCA490Process: C:\XP\system32\nvsvc32.exeProcess Id: 288EPROCESS Address: 0x82487890Process: C:\XP\system32\smss.exeProcess Id: 532EPROCESS Address: 0x82494020Process: C:\XP\system32\csrss.exeProcess Id: 648EPROCESS Address: 0x8217A360Process: C:\XP\system32\winlogon.exeProcess Id: 676EPROCESS Address: 0x822EEBC8Process: C:\XP\system32\services.exeProcess Id: 720EPROCESS Address: 0x8213CC88Process: C:\Program Files\Acronis\TrueImageEnterpriseServer\TRUEIM~3.EXEProcess Id: 724EPROCESS Address: 0x81E6ADA0Process: C:\XP\system32\lsass.exeProcess Id: 732EPROCESS Address: 0x82169A18Process: C:\XP\system32\svchost.exeProcess Id: 884EPROCESS Address: 0x82113460Process: C:\XP\system32\svchost.exeProcess Id: 972EPROCESS Address: 0x820E1020Process: C:\XP\system32\svchost.exeProcess Id: 1028EPROCESS Address: 0x820CE300Process: C:\Program Files\SpywareDetector\SDService.exeProcess Id: 1076EPROCESS Address: 0x824D5AC8Process: C:\XP\system32\svchost.exeProcess Id: 1088EPROCESS Address: 0x820DBB50Process: C:\XP\system32\svchost.exeProcess Id: 1132EPROCESS Address: 0x82492980Process: C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeProcess Id: 1148EPROCESS Address: 0x820DC8E0Process: C:\Program Files\Alwil Software\Avast4\ashServ.exeProcess Id: 1204EPROCESS Address: 0x820CB8E0Process: C:\XP\system32\spoolsv.exeProcess Id: 1408EPROCESS Address: 0x82054B30Process: C:\Program Files\Common Files\Acronis\Agent\agent.exeProcess Id: 1524EPROCESS Address: 0x8202BDA0Process: C:\Program Files\Acronis\BackupServer\backupserver.exeProcess Id: 1540EPROCESS Address: 0x82017DA0Process: C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeProcess Id: 1572EPROCESS Address: 0x82060350Process: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeProcess Id: 1608EPROCESS Address: 0x8208C020Process: C:\Program Files\PTSync\PTSync.exeProcess Id: 1616EPROCESS Address: 0x81EAB020Process: C:\XP\system32\svchost.exeProcess Id: 1620EPROCESS Address: 0x8204CDA0Process: C:\Program Files\Acronis\GroupServer\GroupServer.exeProcess Id: 1704EPROCESS Address: 0x81FEE5B0Process: C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exeProcess Id: 1780EPROCESS Address: 0x81F9DDA0Process: C:\XP\system32\wdfmgr.exeProcess Id: 1996EPROCESS Address: 0x81FE6890Process: C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeProcess Id: 2120EPROCESS Address: 0x821B0890Process: C:\XP\system32\taskmgr.exeProcess Id: 2412EPROCESS Address: 0xFE03F608Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exeProcess Id: 2436EPROCESS Address: 0x8214C930Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exeProcess Id: 2468EPROCESS Address: 0x82E68020Process: C:\Program Files\Acronis\TrueImageEnterpriseServer\TIMOUN~1.EXEProcess Id: 2484EPROCESS Address: 0xFDA9B890Process: C:\XP\system32\alg.exeProcess Id: 2712EPROCESS Address: 0x81EC7890Process: C:\XP\system32\wuauclt.exeProcess Id: 2888EPROCESS Address: 0x82E54020Process: C:\RkUnhooker\oAi7c8OoI7xio.exeProcess Id: 3028EPROCESS Address: 0xFCFC95B0Process: C:\XP\explorer.exeProcess Id: 3852EPROCESS Address: 0x81E27DA0---------------------RkUnhooker report generator v0.6==============================================Rootkit Unhooker kernel version: 3.31.150.420==============================================Windows Major Version: 5Windows Minor Version: 1Windows Build Number: 2600==============================================Driver: Address: 0xF853D000Size: 98304 bytesDriver: ?_unknown_code_page_?Address: 0x82F6F278Size: 3464 bytesDriver: ?_unknown_code_page_?Address: 0x82DC1B78Size: 1160 bytesDriver: ?_unknown_code_page_?Address: 0x82D49008Size: 4088 bytesDriver: ?_unknown_code_page_?Address: 0x82E775C8Size: 2616 bytesDriver: ?_unknown_code_page_?Address: 0x82985D68Size: 664 bytesDriver: ?_unknown_code_page_?Address: 0x82985C40Size: 960 bytesDriver: ?_unknown_code_page_?Address: 0x82985B18Size: 1256 bytesDriver: ?_unknown_code_page_?Address: 0x82C387B0Size: 2128 bytesDriver: ?_unknown_code_page_?Address: 0x82C38688Size: 2424 bytesDriver: ?_unknown_code_page_?Address: 0x82C38560Size: 2720 bytesDriver: ?_unknown_code_page_?Address: 0x82C38438Size: 3016 bytesDriver: ?_unknown_code_page_?Address: 0x82C38310Size: 3312 bytesDriver: ?_unknown_code_page_?Address: 0x82C381E8Size: 3608 bytesDriver: ?_unknown_code_page_?Address: 0x82C379A0Size: 1632 bytesDriver: ?_unknown_code_page_?Address: 0x82C37888Size: 1912 bytesDriver: ?_unknown_code_page_?Address: 0x82C37760Size: 2208 bytesDriver: ?_unknown_code_page_?Address: 0x82C37638Size: 2504 bytesDriver: ?_unknown_code_page_?Address: 0x82C37510Size: 2800 bytesDriver: ?_unknown_code_page_?Address: 0x82C373E8Size: 3096 bytesDriver: ?_unknown_code_page_?Address: 0x82C372C0Size: 3392 bytesDriver: ?_unknown_code_page_?Address: 0x829AC810Size: 2032 bytesDriver: ?_unknown_code_page_?Address: 0x829AC6E8Size: 2328 bytesDriver: ?_unknown_code_page_?Address: 0x829AC5C0Size: 2624 bytesDriver: ?_unknown_code_page_?Address: 0x829AC498Size: 2920 bytesDriver: ?_unknown_code_page_?Address: 0x829AC370Size: 3216 bytesDriver: ?_unknown_code_page_?Address: 0x829AC248Size: 3512 bytesDriver: ?_unknown_code_page_?Address: 0x829ABDA0Size: 608 bytesDriver: ?_unknown_code_page_?Address: 0x82AE81A0Size: 3680 bytesDriver: ?_unknown_code_page_?Address: 0x824D0820Size: 2016 bytesDriver: ?_unknown_code_page_?Address: 0x824F52E8Size: 3352 bytesDriver: ?_unknown_code_page_?Address: 0x82B9EFA8Size: 88 bytesDriver: ?_unknown_code_page_?Address: 0x82B9EF30Size: 208 bytesDriver: ?_unknown_code_page_?Address: 0x8245C750Size: 2224 bytesDriver: ?_unknown_code_page_?Address: 0x820AEBD0Size: 1072 bytesDriver: ?_unknown_code_page_?Address: 0x824D4370Size: 3216 bytesDriver: ?_unknown_code_page_?Address: 0x829929E8Size: 1560 bytesDriver: ?_unknown_code_page_?Address: 0x82DB3430Size: 3024 bytesDriver: ?_unknown_code_page_?Address: 0x82AF17E0Size: 2080 bytesDriver: ?_unknown_code_page_?Address: 0x8245E1A0Size: 3680 bytesDriver: a347bus.sysAddress: 0xF862D000Size: 163840 bytesDriver: a347scsi.sysAddress: 0xF8B80000Size: 8192 bytesDriver: C:\XP\System32\Drivers\Aavmker4.SYSAddress: 0xF8A76000Size: 20480 bytesDriver: ACPI.sysAddress: 0xF85FF000Size: 188416 bytesDriver: ACPI_HALAddress: 0x806EC000Size: 81280 bytesDriver: C:\XP\system32\drivers\aec.sysAddress: 0xB92B8000Size: 143360 bytesDriver: C:\XP\system32\drivers\Afc.sysAddress: 0xF8A5E000Size: 32768 bytesDriver: C:\XP\System32\drivers\afd.sysAddress: 0xF67B8000Size: 139264 bytesDriver: C:\XP\System32\DRIVERS\amdk7.sysAddress: 0xF8726000Size: 40960 bytesDriver: C:\XP\system32\drivers\amon.sysAddress: 0xB9892000Size: 503808 bytesDriver: C:\XP\System32\Drivers\AnyDVD.sysAddress: 0xF8786000Size: 36864 bytesDriver: C:\XP\System32\Drivers\Asapi.SYSAddress: 0xF8936000Size: 32768 bytesDriver: C:\XP\System32\drivers\aspi32.sysAddress: 0xF669E000Size: 20480 bytesDriver: C:\XP\System32\Drivers\aswMon2.SYSAddress: 0xB9B92000Size: 90112 bytesDriver: C:\XP\System32\Drivers\aswRdr.SYSAddress: 0xB9564000Size: 16384 bytesDriver: C:\XP\System32\Drivers\aswTdi.SYSAddress: 0xF8886000Size: 36864 bytesDriver: C:\XP\System32\DRIVERS\audstub.sysAddress: 0xF8CBB000Size: 4096 bytesDriver: C:\XP\System32\DRIVERS\AvgArCln.sysAddress: 0xF8D0F000Size: 4096 bytesDriver: avgarkt.sysAddress: 0xF8B7A000Size: 8192 bytesDriver: C:\XP\System32\DRIVERS\AvgAsCln.sysAddress: 0xF8D19000Size: 4096 bytesDriver: C:\XP\System32\Drivers\Beep.SYSAddress: 0xF8B9C000Size: 8192 bytesDriver: C:\XP\system32\BOOTVID.dllAddress: 0xF8A86000Size: 12288 bytesDriver: C:\XP\System32\Drivers\Cdfs.SYSAddress: 0xF7BC8000Size: 65536 bytesDriver: C:\XP\System32\DRIVERS\cdrom.sysAddress: 0xF8796000Size: 53248 bytesDriver: C:\XP\System32\DRIVERS\CLASSPNP.SYSAddress: 0xF86E6000Size: 53248 bytesDriver: C:\XP\system32\drivers\cmaudio.sysAddress: 0xF7F05000Size: 380928 bytesDriver: C:\XP\system32\DRIVERS\ctoss2k.sysAddress: 0xF7D17000Size: 196608 bytesDriver: C:\XP\system32\DRIVERS\ctsfm2k.sysAddress: 0xF7C2D000Size: 155648 bytesDriver: C:\XP\system32\DRIVERS\DcCam.sysAddress: 0xF8846000Size: 36864 bytesDriver: C:\XP\system32\drivers\dcfs2k.sysAddress: 0xF6168000Size: 40960 bytesDriver: disk.sysAddress: 0xF86D6000Size: 36864 bytesDriver: C:\XP\System32\drivers\dmboot.sysAddress: 0xF7C53000Size: 802816 bytesDriver: dmio.sysAddress: 0xF8555000Size: 155648 bytesDriver: dmload.sysAddress: 0xF8B7E000Size: 8192 bytesDriver: C:\XP\system32\drivers\DMusic.sysAddress: 0xB9648000Size: 53248 bytesDriver: C:\XP\system32\drivers\drmk.sysAddress: 0xF8736000Size: 61440 bytesDriver: C:\XP\system32\drivers\drmkaud.sysAddress: 0xF8D88000Size: 4096 bytesDriver: C:\XP\System32\Drivers\dump_atapi.sysAddress: 0xF60C8000Size: 98304 bytesDriver: C:\XP\System32\Drivers\dump_WMILIB.SYSAddress: 0xF8BC4000Size: 8192 bytesDriver: C:\XP\System32\drivers\Dxapi.sysAddress: 0xF66F2000Size: 12288 bytesDriver: C:\XP\System32\drivers\dxg.sysAddress: 0xBF000000Size: 73728 bytesDriver: C:\XP\System32\drivers\dxgthk.sysAddress: 0xF8CD1000Size: 4096 bytesDriver: C:\XP\System32\DRIVERS\el90xbc5.sysAddress: 0xF7C1C000Size: 69632 bytesDriver: C:\XP\System32\Drivers\ElbyCDFL.sysAddress: 0xF8A56000Size: 28672 bytesDriver: C:\XP\System32\Drivers\ElbyCDIO.sysAddress: 0xF8BC2000Size: 8192 bytesDriver: C:\XP\System32\Drivers\ElbyDelay.sysAddress: 0xF8B84000Size: 8192 bytesDriver: C:\XP\system32\DRIVERS\EXPORTIT.SYSAddress: 0xF6976000Size: 155648 bytesDriver: C:\XP\System32\DRIVERS\fdc.sysAddress: 0xF8A36000Size: 28672 bytesDriver: C:\XP\System32\Drivers\Fips.SYSAddress: 0xF88C6000Size: 36864 bytesDriver: C:\XP\System32\DRIVERS\flpydisk.sysAddress: 0xF89A6000Size: 20480 bytesDriver: fltmgr.sysAddress: 0xF8505000Size: 131072 bytesDriver: C:\XP\System32\Drivers\Fs_Rec.SYSAddress: 0xF8B96000Size: 8192 bytesDriver: ftdisk.sysAddress: 0xF857B000Size: 126976 bytesDriver: C:\XP\system32\DRIVERS\gameenum.sysAddress: 0xF8365000Size: 12288 bytesDriver: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sysAddress: 0xF8D80000Size: 4096 bytesDriver: C:\XP\system32\hal.dllAddress: 0x806EC000Size: 81280 bytesDriver: C:\XP\System32\Drivers\HIDCLASS.SYSAddress: 0xF8866000Size: 36864 bytesDriver: C:\XP\system32\DRIVERS\HIDPARSE.SYSAddress: 0xF89DE000Size: 28672 bytesDriver: hpt3xx.sysAddress: 0xF86C6000Size: 45056 bytesDriver: C:\XP\System32\Drivers\HTTP.sysAddress: 0xB9014000Size: 266240 bytesDriver: C:\XP\System32\DRIVERS\i8042prt.sysAddress: 0xF8756000Size: 53248 bytesDriver: C:\XP\system32\DRIVERS\imapi.sysAddress: 0xF8776000Size: 45056 bytesDriver: C:\XP\System32\DRIVERS\ipnat.sysAddress: 0xF6802000Size: 135168 bytesDriver: C:\XP\System32\DRIVERS\ipsec.sysAddress: 0xF687B000Size: 77824 bytesDriver: isapnp.sysAddress: 0xF8676000Size: 36864 bytesDriver: C:\XP\system32\drivers\iviaspi.sysAddress: 0xF8A6E000Size: 24576 bytesDriver: C:\XP\System32\DRIVERS\kbdclass.sysAddress: 0xF8A4E000Size: 24576 bytesDriver: C:\XP\system32\KDCOM.DLLAddress: 0xF8B76000Size: 8192 bytesDriver: C:\XP\system32\drivers\kmixer.sysAddress: 0xB928D000Size: 176128 bytesDriver: C:\XP\system32\drivers\ks.sysAddress: 0xF7EBE000Size: 143360 bytesDriver: KSecDD.sysAddress: 0xF84DC000Size: 94208 bytesDriver: C:\XP\system32\DRIVERS\L8042Kbd.sysAddress: 0xF8345000Size: 12288 bytesDriver: C:\XP\system32\DRIVERS\LHidKE.SysAddress: 0xF89AE000Size: 24576 bytesDriver: C:\XP\System32\Drivers\LHidUsbK.SysAddress: 0xF8856000Size: 36864 bytesDriver: C:\XP\system32\DRIVERS\LMouKE.SysAddress: 0xF7BD8000Size: 65536 bytesDriver: C:\XP\system32\DRIVERS\lv302af.sysAddress: 0xF8BB0000Size: 8192 bytesDriver: C:\XP\system32\DRIVERS\LV302AV.SYSAddress: 0xF63C3000Size: 913408 bytesDriver: C:\XP\system32\DRIVERS\lvsvf2.sysAddress: 0xF61A8000Size: 2207744 bytesDriver: C:\XP\System32\Drivers\mnmdd.SYSAddress: 0xF8BA0000Size: 8192 bytesDriver: C:\XP\System32\DRIVERS\mouclass.sysAddress: 0xF8986000Size: 24576 bytesDriver: C:\XP\System32\DRIVERS\mouhid.sysAddress: 0xF696A000Size: 12288 bytesDriver: MountMgr.sysAddress: 0xF86A6000Size: 45056 bytesDriver: C:\XP\System32\DRIVERS\mrxdav.sysAddress: 0xB99FD000Size: 184320 bytesDriver: C:\XP\System32\DRIVERS\mrxsmb.sysAddress: 0xF66F6000Size: 454656 bytesDriver: C:\XP\System32\Drivers\Msfs.SYSAddress: 0xF89F6000Size: 20480 bytesDriver: C:\XP\System32\DRIVERS\msgpc.sysAddress: 0xF8876000Size: 36864 bytesDriver: C:\XP\System32\DRIVERS\mssmbios.sysAddress: 0xF8309000Size: 16384 bytesDriver: Mup.sysAddress: 0xF83BD000Size: 110592 bytesDriver: C:\XP\SYSTEM32\Drivers\NDIS.SYSAddress: 0xF859A000Size: 184320 bytesDriver: C:\XP\System32\DRIVERS\ndistapi.sysAddress: 0xF8325000Size: 12288 bytesDriver: C:\XP\System32\DRIVERS\ndiswan.sysAddress: 0xF7B51000Size: 94208 bytesDriver: C:\XP\System32\Drivers\NDProxy.SYSAddress: 0xF8826000Size: 40960 bytesDriver: C:\XP\System32\DRIVERS\netbios.sysAddress: 0xF88A6000Size: 36864 bytesDriver: C:\XP\System32\DRIVERS\netbt.sysAddress: 0xF67DA000Size: 163840 bytesDriver: C:\XP\system32\drivers\nod32drv.sysAddress: 0xF8BAA000Size: 8192 bytesDriver: C:\XP\system32\drivers\npf.sysAddress: 0xB97B8000Size: 36864 bytesDriver: C:\XP\System32\Drivers\Npfs.SYSAddress: 0xF8A06000Size: 32768 bytesDriver: Ntfs.sysAddress: 0xF844F000Size: 577536 bytesDriver: C:\XP\system32\ntoskrnl.exeAddress: 0x804D7000Size: 2180352 bytesDriver: C:\XP\System32\Drivers\Null.SYSAddress: 0xF8D0B000Size: 4096 bytesDriver: C:\XP\System32\nv4_disp.dllAddress: 0xBF012000Size: 3928064 bytesDriver: C:\XP\System32\DRIVERS\nv4_mini.sysAddress: 0xF7F9E000Size: 3534848 bytesDriver: C:\XP\system32\DRIVERS\nvcap.sysAddress: 0xF6022000Size: 110592 bytesDriver: C:\XP\system32\DRIVERS\nvtunep.sysAddress: 0xF66DA000Size: 16384 bytesDriver: C:\XP\system32\DRIVERS\nvtvsnd.sysAddress: 0xF7B78000Size: 45056 bytesDriver: C:\XP\system32\DRIVERS\NVxbar.sysAddress: 0xF66E2000Size: 12288 bytesDriver: C:\XP\system32\drivers\P17.sysAddress: 0xF7D47000Size: 1392640 bytesDriver: C:\XP\System32\DRIVERS\parport.sysAddress: 0xF7C08000Size: 81920 bytesDriver: PartMgr.sysAddress: 0xF8906000Size: 20480 bytesDriver: C:\XP\System32\Drivers\ParVdm.SYSAddress: 0xF8BA6000Size: 8192 bytesDriver: pci.sysAddress: 0xF85EE000Size: 69632 bytesDriver: C:\XP\System32\DRIVERS\PCIIDEX.SYSAddress: 0xF88FE000Size: 28672 bytesDriver: C:\XP\System32\Drivers\Pcouffin.sysAddress: 0xF87E6000Size: 40960 bytesDriver: C:\XP\system32\drivers\pfc.sysAddress: 0xF8335000Size: 12288 bytesDriver: PnpManagerAddress: 0x804D7000Size: 2180352 bytesDriver: C:\XP\system32\drivers\portcls.sysAddress: 0xF7EE1000Size: 147456 bytesDriver: C:\XP\System32\DRIVERS\ptilink.sysAddress: 0xF896E000Size: 20480 bytesDriver: PxHelp20.sysAddress: 0xF890E000Size: 20480 bytesDriver: C:\XP\System32\DRIVERS\rasacd.sysAddress: 0xF8329000Size: 12288 bytesDriver: C:\XP\System32\DRIVERS\rasl2tp.sysAddress: 0xF87B6000Size: 53248 bytesDriver: C:\XP\System32\DRIVERS\raspppoe.sysAddress: 0xF87C6000Size: 45056 bytesDriver: C:\XP\System32\DRIVERS\raspptp.sysAddress: 0xF87D6000Size: 49152 bytesDriver: C:\XP\System32\DRIVERS\raspti.sysAddress: 0xF897E000Size: 20480 bytesDriver: RAWAddress: 0x804D7000Size: 2180352 bytesDriver: C:\XP\System32\DRIVERS\rdbss.sysAddress: 0xF678D000Size: 176128 bytesDriver: C:\XP\System32\DRIVERS\RDPCDD.sysAddress: 0xF8BA4000Size: 8192 bytesDriver: C:\XP\System32\DRIVERS\rdpdr.sysAddress: 0xF7AF8000Size: 200704 bytesDriver: C:\XP\System32\DRIVERS\redbook.sysAddress: 0xF87A6000Size: 61440 bytesDriver: C:\XP\System32\Drivers\rkhdrv31.SYSAddress: 0xF8976000Size: 20480 bytesDriver: C:\XP\System32\Drivers\SCDEmu.SYSAddress: 0xF8A3E000Size: 32768 bytesDriver: C:\XP\system32\DRIVERS\SCSIPORT.SYSAddress: 0xF8525000Size: 98304 bytesDriver: C:\XP\System32\DRIVERS\secdrv.sysAddress: 0xF8956000Size: 28672 bytesDriver: C:\XP\System32\DRIVERS\serenum.sysAddress: 0xF834D000Size: 16384 bytesDriver: C:\XP\System32\DRIVERS\serial.sysAddress: 0xF8746000Size: 65536 bytesDriver: snapman.sysAddress: 0xF83D8000Size: 102400 bytesDriver: C:\XP\system32\drivers\splitter.sysAddress: 0xF8BF4000Size: 8192 bytesDriver: sr.sysAddress: 0xF84F3000Size: 73728 bytesDriver: C:\XP\System32\DRIVERS\srv.sysAddress: 0xB97F0000Size: 335872 bytesDriver: SSFS0509.SYSAddress: 0xF8696000Size: 36864 bytesDriver: SSHRMD.SYSAddress: 0xF8686000Size: 36864 bytesDriver: SSIDRV.SYSAddress: 0xF85C7000Size: 159744 bytesDriver: C:\XP\System32\Drivers\sskbfd.sysAddress: 0xF8766000Size: 49152 bytesDriver: C:\XP\system32\DRIVERS\STREAM.SYSAddress: 0xF88E6000Size: 49152 bytesDriver: C:\XP\System32\DRIVERS\swenum.sysAddress: 0xF8B8C000Size: 8192 bytesDriver: C:\XP\system32\drivers\swmidi.sysAddress: 0xB9AE2000Size: 57344 bytesDriver: C:\XP\system32\drivers\sysaudio.sysAddress: 0xB9368000Size: 61440 bytesDriver: C:\XP\System32\DRIVERS\tcpip.sysAddress: 0xF6823000Size: 360448 bytesDriver: C:\XP\SYSTEM32\Drivers\TDI.SYSAddress: 0xF88F6000Size: 20480 bytesDriver: C:\XP\System32\DRIVERS\termdd.sysAddress: 0xF87F6000Size: 40960 bytesDriver: C:\XP\system32\DRIVERS\tifsfilt.sysAddress: 0xF899E000Size: 32768 bytesDriver: timntr.sysAddress: 0xF83F1000Size: 385024 bytesDriver: C:\XP\System32\DRIVERS\update.sysAddress: 0xF7AC4000Size: 212992 bytesDriver: C:\XP\system32\drivers\usbaudio.sysAddress: 0xF7BE8000Size: 61440 bytesDriver: C:\XP\System32\DRIVERS\usbccgp.sysAddress: 0xF89CE000Size: 32768 bytesDriver: C:\XP\System32\DRIVERS\USBD.SYSAddress: 0xF8B90000Size: 8192 bytesDriver: C:\XP\system32\DRIVERS\usbehci.sysAddress: 0xF8966000Size: 28672 bytesDriver: C:\XP\System32\DRIVERS\usbhub.sysAddress: 0xF8816000Size: 61440 bytesDriver: C:\XP\System32\DRIVERS\usbohci.sysAddress: 0xF895E000Size: 20480 bytesDriver: C:\XP\System32\DRIVERS\USBPORT.SYSAddress: 0xF7E9B000Size: 143360 bytesDriver: C:\XP\System32\DRIVERS\usbprint.sysAddress: 0xF8946000Size: 28672 bytesDriver: C:\XP\system32\DRIVERS\USBSTOR.SYSAddress: 0xF8A26000Size: 28672 bytesDriver: C:\XP\System32\DRIVERS\usbuhci.sysAddress: 0xF893E000Size: 20480 bytesDriver: D:\Virtual CD\VCdRom.sysAddress: 0xF7B31000Size: 12288 bytesDriver: C:\XP\System32\drivers\vga.sysAddress: 0xF89E6000Size: 24576 bytesDriver: viaagp.sysAddress: 0xF86F6000Size: 45056 bytesDriver: viaide.sysAddress: 0xF8B7C000Size: 8192 bytesDriver: C:\XP\System32\DRIVERS\VIDEOPRT.SYSAddress: 0xF7F8A000Size: 81920 bytesDriver: VolSnap.sysAddress: 0xF86B6000Size: 53248 bytesDriver: C:\XP\System32\DRIVERS\wanarp.sysAddress: 0xF8896000Size: 36864 bytesDriver: C:\XP\System32\watchdog.sysAddress: 0xF89D6000Size: 20480 bytesDriver: C:\XP\system32\drivers\wdmaud.sysAddress: 0xB92DB000Size: 86016 bytesDriver: Win32kAddress: 0xBF800000Size: 1847296 bytesDriver: C:\XP\System32\win32k.sysAddress: 0xBF800000Size: 1847296 bytesDriver: C:\XP\system32\drivers\WmBEnum.sysAddress: 0xF8301000Size: 12288 bytesDriver: C:\XP\System32\DRIVERS\WMILIB.SYSAddress: 0xF8B78000Size: 8192 bytesDriver: WMIxWDMAddress: 0x804D7000Size: 2180352 bytesDriver: C:\XP\system32\drivers\WmXlCore.sysAddress: 0xF8806000Size: 45056 bytesDriver: C:\XP\System32\drivers\ws2ifsl.sysAddress: 0xF7B3D000Size: 12288 bytes----RkUnhooker report generator v0.6==============================================Rootkit Unhooker kernel version: 3.31.150.420==============================================Windows Major Version: 5Windows Minor Version: 1Windows Build Number: 2600==============================================[2120]SpySweeper.exe-->kernel32.dll-->CreateThread, Type: Inline - PushRet at address 0x7C810651 hook handler located in [unknown_code_page]ntoskrnl.exe+0x0000B9A8, Type: Inline - RelativeCall at address 0x804E29A8 hook handler located in [unknown_code_page]tcpip.sys-->ndis.sys-->NdisRegisterProtocol, Type: IAT modification at address 0xF6861F60 hook handler located in [unknown_code_page]wanarp.sys-->ndis.sys-->NdisDeregisterProtocol, Type: IAT modification at address 0xF889BB1C hook handler located in [unknown_code_page]wanarp.sys-->ndis.sys-->NdisRegisterProtocol, Type: IAT modification at address 0xF889BB28 hook handler located in [unknown_code_page]As always, thanks a million for your assistance! Quote Link to post Share on other sites
Steviebone Posted May 21, 2007 Author Report Share Posted May 21, 2007 (edited) Backlight didn't find anything.BTW, I have 8 other machines in here including some servers. Even with apps running on them most of them idle at 0-2% only spiking when an app does something (such as a web hit). Even then the spike is small and non-repetitive.The activity here is repetitive and continuous... I'm pretty sure there's still a rogue process running somewhere.... Edited May 21, 2007 by Steviebone Quote Link to post Share on other sites
Steviebone Posted May 22, 2007 Author Report Share Posted May 22, 2007 (edited) ok I think I fugured it out... I downloaded a program called process explorer which is more detailed than task manager (of course everything Windows has built in sucks compared to third party alternatives!). This program broke the activity down much better. The spikes were coming from hardware interrupts. Hardware interrupts? Yep. It was all the USB drives. I disconnected the USB drives and wahla... the interrupt load went down as did the overall activity which now hovers between 0-4%... acceptable if not perfect.I'm hoping the system is now clean. Let me know if you see anything else in the logs that appears suspicous... I never liked USB drives anyway... I suppose there's still the small possibility that the rogue program resided on one of the drives and was running from there which was causing the interrupts.... Edited May 22, 2007 by Steviebone Quote Link to post Share on other sites
jwbirdsong Posted May 22, 2007 Report Share Posted May 22, 2007 You been (at least) a half a step ahead of me the whole way....Process Explorer (the one from SysInternals ??) was my next recommendation to you. All of your scan look good w/ possibly one exception. I'd like you to upload one file or me to look at please.Please go here to upload a suspicious file for analysis. Enter your username from this forumCopy and paste the link to this threadBrowse for this filename: C:\XP\system32\DRIVERS\EXPORTIT.SYSIn the comments, please mention that I asked you to upload this fileClick on Send FileThe ONLY other references I find to it are a Kodak file and it's allways in a Kodak sub folder..Just like to look at it and make sure.Jst keep an eye on your resources (Doesn't really seem I need to tell YOU that tho )If you would give one final (?) Combofix log and let me have a look at that file hopefully we can put an end to this..Sorry I wasn't timely enough to be of more assistance to you in this..but it seems you REALLY had it pretty well handled all along. Quote Link to post Share on other sites
Steviebone Posted May 22, 2007 Author Report Share Posted May 22, 2007 (edited) file uploaded... will post combofix log shortly...sysinternals yes... great replacement for task manager... still wondering why the USB interuupts were triggering with no disk access but then I think USB drives are polled... one reason why they stink...btw, u been plenty of help, thanksYou been (at least) a half a step ahead of me the whole way....Process Explorer (the one from SysInternals ??) was my next recommendation to you. All of your scan look good w/ possibly one exception. I'd like you to upload one file or me to look at please.Please go here to upload a suspicious file for analysis. Enter your username from this forumCopy and paste the link to this threadBrowse for this filename: C:\XP\system32\DRIVERS\EXPORTIT.SYSIn the comments, please mention that I asked you to upload this fileClick on Send FileThe ONLY other references I find to it are a Kodak file and it's allways in a Kodak sub folder..Just like to look at it and make sure.Jst keep an eye on your resources (Doesn't really seem I need to tell YOU that tho )If you would give one final (?) Combofix log and let me have a look at that file hopefully we can put an end to this..Sorry I wasn't timely enough to be of more assistance to you in this..but it seems you REALLY had it pretty well handled all along. Edited May 22, 2007 by Steviebone Quote Link to post Share on other sites
Steviebone Posted May 22, 2007 Author Report Share Posted May 22, 2007 well chit...I ran combofix, but I forgot to turn off all my protective programs first. Immediately upon execution spydetector popped up window that said "Rustock.b successfully removed". Then towards the end of the scan another popup saying Trojan.Agent removed. Then combo said disinfecting and rebooting. After reboot, the following log was generated:"Staypuffer" - 2007-05-22 9:18:29 Service Pack 2 ComboFix 07-05.20.9.V - Running from: "J:\Spywaredetector\" Rootkit driver lzx32 is present. A rootkit scan is required ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-22 ))))))))))))))))))))))))))))))))))2007-05-21 23:15 <DIR> d-------- C:\ProcessExplorer2007-05-21 09:17 5,632 --a------ C:\XP\system32\71430B71.exe2007-05-21 08:57 <DIR> d-------- C:\RkUnhooker2007-05-21 01:33 3,968 --a------ C:\XP\system32\drivers\AvgArCln.sys2007-05-21 01:20 <DIR> d-------- C:\avenger2007-05-21 00:59 16 --a------ C:\chdir.bat2007-05-20 17:30 <DIR> d-------- C:\DOCUME~1\NETWOR~1.NTA\APPLIC~1\Webroot2007-05-20 17:18 3,968 --a------ C:\XP\system32\drivers\AvgAsCln.sys2007-05-20 14:53 60,416 --a------ C:\XP\system32\drivers\k^nymapg.sys2007-05-20 14:53 1,075 --a------ C:\xqsjepbn.bat2007-05-20 14:04 49,152 --a------ C:\XP\nircmd.exe2007-05-20 06:42 2,922 --a------ C:\XP\system32\IE_Backup.reg2007-05-20 06:42 2,846,854 --a------ C:\XP\system32\Windows_Backup.reg2007-05-20 06:42 2,588 --a------ C:\XP\system32\startupBackup.reg2007-05-20 02:27 123 --a------ C:\XP\system\SysSD.dll2007-05-20 02:26 63,192 --a------ C:\XP\system32\CloseAll.exe2007-05-20 02:26 270,336 --a------ C:\XP\system32\CheckDll.dll2007-05-20 02:26 1,019,904 --a------ C:\XP\system32\VchReg.dll2007-05-20 02:25 <DIR> d-------- C:\Program Files\SpywareDetector2007-05-19 18:15 22,080 --a------ C:\XP\system32\drivers\sshrmd.sys2007-05-19 18:15 21,056 --a------ C:\XP\system32\drivers\sskbfd.sys2007-05-19 18:15 20,544 --a------ C:\XP\system32\drivers\SSFS0509.sys2007-05-19 18:15 144,960 --a------ C:\XP\system32\drivers\ssidrv.sys2007-05-19 18:15 <DIR> d-------- C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\Webroot2007-05-19 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Webroot2007-05-19 18:08 164 --a------ C:\install.dat2007-05-19 18:08 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Webroot2007-05-18 11:43 <DIR> d--h----- C:\XP\system32\GroupPolicy2007-05-17 22:04 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Texture Maker2007-05-17 22:03 <DIR> d-------- C:\Program Files\Texture Maker2007-05-17 17:39 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Google2007-05-15 13:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Spybot - Search & Destroy2007-05-08 01:29 <DIR> d-------- C:\Program Files\Network Chemistry2007-05-08 01:17 <DIR> d-------- C:\Program Files\WinPcap2007-05-08 01:17 <DIR> d-------- C:\Program Files\Nmap2007-04-26 18:37 298,496 --a------ C:\XP\uninst.exe(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))2007-05-22 14:08:10 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\dvdcss2007-05-21 05:50:19 -------- d-----w C:\Program Files\Common Files\Merge Modules2007-05-17 22:39:02 -------- d-----w C:\Program Files\Google2007-05-16 04:57:49 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\WeatherBug2007-05-15 18:38:06 -------- d-----w C:\Program Files\MySpace2007-05-07 17:28:32 -------- d-----w C:\Program Files\EPSON Print CD2007-05-07 13:39:36 298,104 ----a-w C:\XP\system32\imon.dll2007-05-07 13:39:34 512,096 ----a-w C:\XP\system32\drivers\amon.sys2007-05-07 13:39:33 15,424 ----a-w C:\XP\system32\drivers\nod32drv.sys2007-05-03 05:49:55 -------- d-----w C:\Program Files\LeapFTP2007-04-30 15:46:10 745,600 ----a-w C:\XP\system32\aswBoot.exe2007-04-30 15:41:55 85,952 ----a-w C:\XP\system32\drivers\aswmon.sys2007-04-30 15:41:42 94,552 ----a-w C:\XP\system32\drivers\aswmon2.sys2007-04-30 15:39:41 23,416 ----a-w C:\XP\system32\drivers\aswRdr.sys2007-04-30 15:38:51 43,176 ----a-w C:\XP\system32\drivers\aswTdi.sys2007-04-30 15:37:23 26,888 ----a-w C:\XP\system32\drivers\aavmker4.sys2007-04-30 15:35:28 95,872 ----a-w C:\XP\system32\AVASTSS.scr2007-04-30 08:55:32 -------- d-----w C:\Program Files\ViceVersa Pro 22007-04-26 23:09:43 -------- d-----w C:\Program Files\IsoBuster2007-04-25 08:04:12 88,952 ----a-w C:\XP\system32\packet.dll2007-04-25 08:04:12 68,480 ----a-w C:\XP\system32\wanpacket.dll2007-04-25 08:04:12 42,000 ----a-w C:\XP\system32\drivers\npf.sys2007-04-25 08:04:12 240,496 ----a-w C:\XP\system32\wpcap.dll2007-04-21 03:30:35 -------- d-----w C:\Program Files\Speed Startup2007-04-20 03:28:54 1,040,384 ----a-w C:\XP\system32\libeay32.dll2007-04-20 03:27:57 196,608 ----a-w C:\XP\system32\ssleay32.dll2007-04-16 06:45:33 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\MySpace2007-04-09 04:37:55 -------- d-----w C:\Program Files\SlySoft2007-04-09 03:42:45 29,392 ----a-w C:\XP\system32\drivers\secdrv.sys2007-04-08 22:59:29 -------- d-----w C:\Program Files\PowerISO2007-04-06 21:14:04 542 ----a-w C:\hrlist.scr2007-04-06 20:32:08 371 ----a-w C:\getbilldirs.scr2007-04-06 20:31:54 371 ----a-w C:\gethbdirs.scr2007-04-06 20:28:28 139 ----a-w C:\tryftp.scr2007-04-06 05:46:37 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\Zeon2007-04-06 05:02:00 -------- d-----w C:\Program Files\G-Lock Software2007-04-05 15:31:07 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\G-Lock Software2007-04-04 10:33:04 -------- d-----w C:\Program Files\Yahoo!2007-03-18 17:28:30 5,885 ----a-w C:\XP\mozver.dat2007-03-17 13:43:01 292,864 ----a-w C:\XP\system32\winsrv.dll2007-03-15 19:35:33 -------- d-----w C:\Program Files\Tracker2007-03-15 10:52:51 -------- d-----w C:\Program Files\Registry Watch2007-03-15 10:14:59 720,896 ----a-w C:\XP\iun6002ev.exe2007-03-15 04:18:10 -------- d-----w C:\Program Files\Salive2007-03-15 04:17:28 -------- d--h--r C:\DOCUME~1\STAYPU~1\APPLIC~1\yahoo!2007-03-08 15:36:28 577,536 ----a-w C:\XP\system32\user32.dll2007-03-08 15:36:28 40,960 ----a-w C:\XP\system32\mf3216.dll2007-03-08 15:36:28 281,600 ----a-w C:\XP\system32\gdi32.dll2007-03-08 13:47:48 1,843,584 ----a-w C:\XP\system32\win32k.sys2007-03-08 04:59:59 -------- d-----w C:\Program Files\DirPrn2007-03-07 09:16:28 -------- d-----w C:\Program Files\'Net Monitor2007-03-07 09:13:15 -------- d-----w C:\Program Files\PTZone2007-03-07 09:10:26 -------- d-----w C:\Program Files\WinWatch2007-03-07 09:10:21 249,856 ------w C:\XP\Setup1.exe2007-03-07 09:10:09 -------- d-----w C:\Program Files\LanMon2007-03-07 09:09:11 73,216 ------w C:\XP\ST6UNST.EXE2007-02-28 08:59:01 26,000 ----a-w C:\XP\system32\E3TL.DLL2007-02-05 20:17:02 185,344 ----a-w C:\XP\system32\upnphost.dll(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21]{AE7CD045-E861-484f-8273-0445EE161910}=D:\Acrobat7\Acrobat\AcroIEFavClient.dll [2005-09-24 00:41][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"NvCplDaemon"="C:\XP\system32\NvCpl.dll" [2005-10-28 16:06][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SpeedStartup"="C:\Program Files\Speed Startup\speedstartup.exe" [2006-12-14 17:12][HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]"SpeedStartup"=C:\Program Files\Speed Startup\speedstartup.exe runonce[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="D:\Internet\eudora\EuShlExt.dll" [2005-11-14 16:15]"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 09:13][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]C:\Program Files\SpywareDetector\SDNotify.dll[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]Authentication Packages msv1_0 relog_ap[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Y]AutoRun\command- Y:\vfpstart.exe IE5="vfpstart.hta" IELess="vfpstart.htm"Contents of the 'Scheduled Tasks' folder2007-05-22 12:48:24 C:\XP\tasks\New Task 2.job2007-05-22 10:54:10 C:\XP\tasks\New Task.job2007-05-22 10:50:00 C:\XP\tasks\_viceversapr2_task_Bashful2Booby.job2007-05-22 11:30:00 C:\XP\tasks\_viceversapr2_task_batch.job2007-05-22 13:30:00 C:\XP\tasks\_viceversapr2_task_Bills.job2007-03-26 09:40:18 C:\XP\tasks\_viceversapr2_task_documents_and_settings.job2007-05-22 11:10:00 C:\XP\tasks\_viceversapr2_task_Eudora.job2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_hits prg to Tweetie D.job2007-05-22 06:00:00 C:\XP\tasks\_viceversapr2_task_HITSSOURCES.job2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_HITSVEN.job2007-05-22 13:15:00 C:\XP\tasks\_viceversapr2_task_Idisk.job2007-05-22 13:00:00 C:\XP\tasks\_viceversapr2_task_Links.job2007-03-26 09:33:37 C:\XP\tasks\_viceversapr2_task_madden.job2007-05-22 09:59:49 C:\XP\tasks\_viceversapr2_task_newag.job2007-05-22 10:30:00 C:\XP\tasks\_viceversapr2_task_OHITS.job2007-05-22 11:34:00 C:\XP\tasks\_viceversapr2_task_personal.job2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_ServersAlive.job2007-05-22 12:00:53 C:\XP\tasks\_viceversapr2_task_Steviebone.job2007-03-26 11:38:02 C:\XP\tasks\_viceversapr2_task_Torrents.job2007-05-22 14:15:00 C:\XP\tasks\_viceversapr2_task_txdot.job2007-05-22 11:20:00 C:\XP\tasks\_viceversapr2_task_visaversaprofiles.job********************************************************************catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.netRootkit scan 2007-05-22 09:31:21Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ...scanning hidden autostart entries ...scanning hidden files ...scan completed successfullyhidden files: 0********************************************************************Completion time: 2007-05-22 9:39:30 - machine was rebootedC:\ComboFix-quarantined-files.txt ... 2007-05-22 09:39C:\ComboFix2.txt ... 2007-05-20 14:38C:\ComboFix3.txt ... 2007-05-20 14:04 --- E O F ---here is the quarantine log:2006-04-26 00:31 775 --a------ C:\Qoobox\Quarantine\C\DOCUME~1\STAYPU~1\Desktop\Internet Explorer.lnk.vir2006-05-05 03:30 300 --a------ C:\Qoobox\Quarantine\C\Program Files\INSTALL.LOG.vir2007-05-20 10:22 77725 --a------ C:\Qoobox\Quarantine\catchme2007-05-20_135445.26.zip2007-05-22 09:27 500 --a------ C:\Qoobox\Quarantine\catchme.logFolder PATH listing for volume PrimaryCVolume serial number is 747C-9F49C:\QOOBOX\---Quarantine | catchme.log | catchme2007-05-20_135445.26.zip | +---C | +---DOCUME~1 | | \---STAYPU~1 | | \---Desktop | | Internet Explorer.lnk.vir | | | \---Program Files | INSTALL.LOG.vir | \---Registry_backupsI'm guessing I need to run another scan with the HIPS off? Quote Link to post Share on other sites
Steviebone Posted May 22, 2007 Author Report Share Posted May 22, 2007 oh and btw, fwiw, somewhere in this whole process my task scheduler got broke... always gives me an 0x80090016 error... tried all the published fixes for it to no avail the taskscheduler can no longer see or set credentials... Quote Link to post Share on other sites
jwbirdsong Posted May 22, 2007 Report Share Posted May 22, 2007 K Copy the following to a new notepad file and save to your desktop as "fix.reg". Make sure to INCLUDE the quotes as you are naming the file in Notepad.REGEDIT4[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Y]If done correctly it will have an icon like .Now right click fix.reg and choose Merge it should ask for confirmation then give a sucess msg.You MUST be connected to the internet for the next part 1. Download - rustbfix.exe from HERE ...and save it to your desktop. 2. Double click on rustbfix.exe to run the tool. 1. If a Rustock.b-infection is found, you will shortly hereafter be asked to reboot the computer. The reboot will probably take quite a while, and perhaps 2 reboots will be needed. But this will happen automatically. 2. After the reboot 2 logfiles will open (%root%\avenger.txt & %root%\rustbfix\pelog.txt). If needed (still infected), post the content of these logfiles along with a new Combofix log....I'll look into the taskscheduler issue.PS that file you uploaded was fine..as I figured..ust double checking. Quote Link to post Share on other sites
Steviebone Posted May 22, 2007 Author Report Share Posted May 22, 2007 ok, second combofix scan with all protective programs off did better (see below). Perhaps the combo was picking up on something in spydetector?Anyway it found no lzx32 this time... curious....As for the task manager thingy: 0x80090016: Keysey does not exist. I have googled the hell out of that one and tried every fix I could find including deletion of the RSA files, etc. There are no registry entries that MS talks about. I did find a few people complaining about this problem after applying updates. "Staypuffer" - 2007-05-22 9:58:48 Service Pack 2 ComboFix 07-05.20.9.V - Running from: "J:\Spywaredetector\"((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-22 ))))))))))))))))))))))))))))))))))2007-05-21 23:15 <DIR> d-------- C:\ProcessExplorer2007-05-21 09:17 5,632 --a------ C:\XP\system32\71430B71.exe2007-05-21 08:57 <DIR> d-------- C:\RkUnhooker2007-05-21 01:33 3,968 --a------ C:\XP\system32\drivers\AvgArCln.sys2007-05-21 01:20 <DIR> d-------- C:\avenger2007-05-21 00:59 16 --a------ C:\chdir.bat2007-05-20 17:30 <DIR> d-------- C:\DOCUME~1\NETWOR~1.NTA\APPLIC~1\Webroot2007-05-20 17:18 3,968 --a------ C:\XP\system32\drivers\AvgAsCln.sys2007-05-20 14:53 60,416 --a------ C:\XP\system32\drivers\k^nymapg.sys2007-05-20 14:53 1,075 --a------ C:\xqsjepbn.bat2007-05-20 14:04 49,152 --a------ C:\XP\nircmd.exe2007-05-20 06:42 2,922 --a------ C:\XP\system32\IE_Backup.reg2007-05-20 06:42 2,846,854 --a------ C:\XP\system32\Windows_Backup.reg2007-05-20 06:42 2,588 --a------ C:\XP\system32\startupBackup.reg2007-05-20 02:27 123 --a------ C:\XP\system\SysSD.dll2007-05-20 02:26 63,192 --a------ C:\XP\system32\CloseAll.exe2007-05-20 02:26 270,336 --a------ C:\XP\system32\CheckDll.dll2007-05-20 02:26 1,019,904 --a------ C:\XP\system32\VchReg.dll2007-05-20 02:25 <DIR> d-------- C:\Program Files\SpywareDetector2007-05-19 18:15 22,080 --a------ C:\XP\system32\drivers\sshrmd.sys2007-05-19 18:15 21,056 --a------ C:\XP\system32\drivers\sskbfd.sys2007-05-19 18:15 20,544 --a------ C:\XP\system32\drivers\SSFS0509.sys2007-05-19 18:15 144,960 --a------ C:\XP\system32\drivers\ssidrv.sys2007-05-19 18:15 <DIR> d-------- C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\Webroot2007-05-19 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Webroot2007-05-19 18:08 164 --a------ C:\install.dat2007-05-19 18:08 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Webroot2007-05-18 11:43 <DIR> d--h----- C:\XP\system32\GroupPolicy2007-05-17 22:04 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Texture Maker2007-05-17 22:03 <DIR> d-------- C:\Program Files\Texture Maker2007-05-17 17:39 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Google2007-05-15 13:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Spybot - Search & Destroy2007-05-08 01:29 <DIR> d-------- C:\Program Files\Network Chemistry2007-05-08 01:17 <DIR> d-------- C:\Program Files\WinPcap2007-05-08 01:17 <DIR> d-------- C:\Program Files\Nmap2007-04-26 18:37 298,496 --a------ C:\XP\uninst.exe(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))2007-05-22 14:08:10 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\dvdcss2007-05-21 05:50:19 -------- d-----w C:\Program Files\Common Files\Merge Modules2007-05-17 22:39:02 -------- d-----w C:\Program Files\Google2007-05-16 04:57:49 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\WeatherBug2007-05-15 18:38:06 -------- d-----w C:\Program Files\MySpace2007-05-07 17:28:32 -------- d-----w C:\Program Files\EPSON Print CD2007-05-07 13:39:36 298,104 ----a-w C:\XP\system32\imon.dll2007-05-07 13:39:34 512,096 ----a-w C:\XP\system32\drivers\amon.sys2007-05-07 13:39:33 15,424 ----a-w C:\XP\system32\drivers\nod32drv.sys2007-05-03 05:49:55 -------- d-----w C:\Program Files\LeapFTP2007-04-30 15:46:10 745,600 ----a-w C:\XP\system32\aswBoot.exe2007-04-30 15:41:55 85,952 ----a-w C:\XP\system32\drivers\aswmon.sys2007-04-30 15:41:42 94,552 ----a-w C:\XP\system32\drivers\aswmon2.sys2007-04-30 15:39:41 23,416 ----a-w C:\XP\system32\drivers\aswRdr.sys2007-04-30 15:38:51 43,176 ----a-w C:\XP\system32\drivers\aswTdi.sys2007-04-30 15:37:23 26,888 ----a-w C:\XP\system32\drivers\aavmker4.sys2007-04-30 15:35:28 95,872 ----a-w C:\XP\system32\AVASTSS.scr2007-04-30 08:55:32 -------- d-----w C:\Program Files\ViceVersa Pro 22007-04-26 23:09:43 -------- d-----w C:\Program Files\IsoBuster2007-04-25 08:04:12 88,952 ----a-w C:\XP\system32\packet.dll2007-04-25 08:04:12 68,480 ----a-w C:\XP\system32\wanpacket.dll2007-04-25 08:04:12 42,000 ----a-w C:\XP\system32\drivers\npf.sys2007-04-25 08:04:12 240,496 ----a-w C:\XP\system32\wpcap.dll2007-04-21 03:30:35 -------- d-----w C:\Program Files\Speed Startup2007-04-20 03:28:54 1,040,384 ----a-w C:\XP\system32\libeay32.dll2007-04-20 03:27:57 196,608 ----a-w C:\XP\system32\ssleay32.dll2007-04-16 06:45:33 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\MySpace2007-04-09 04:37:55 -------- d-----w C:\Program Files\SlySoft2007-04-09 03:42:45 29,392 ----a-w C:\XP\system32\drivers\secdrv.sys2007-04-08 22:59:29 -------- d-----w C:\Program Files\PowerISO2007-04-06 21:14:04 542 ----a-w C:\hrlist.scr2007-04-06 20:32:08 371 ----a-w C:\getbilldirs.scr2007-04-06 20:31:54 371 ----a-w C:\gethbdirs.scr2007-04-06 20:28:28 139 ----a-w C:\tryftp.scr2007-04-06 05:46:37 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\Zeon2007-04-06 05:02:00 -------- d-----w C:\Program Files\G-Lock Software2007-04-05 15:31:07 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\G-Lock Software2007-04-04 10:33:04 -------- d-----w C:\Program Files\Yahoo!2007-03-18 17:28:30 5,885 ----a-w C:\XP\mozver.dat2007-03-17 13:43:01 292,864 ----a-w C:\XP\system32\winsrv.dll2007-03-15 19:35:33 -------- d-----w C:\Program Files\Tracker2007-03-15 10:52:51 -------- d-----w C:\Program Files\Registry Watch2007-03-15 10:14:59 720,896 ----a-w C:\XP\iun6002ev.exe2007-03-15 04:18:10 -------- d-----w C:\Program Files\Salive2007-03-15 04:17:28 -------- d--h--r C:\DOCUME~1\STAYPU~1\APPLIC~1\yahoo!2007-03-08 15:36:28 577,536 ----a-w C:\XP\system32\user32.dll2007-03-08 15:36:28 40,960 ----a-w C:\XP\system32\mf3216.dll2007-03-08 15:36:28 281,600 ----a-w C:\XP\system32\gdi32.dll2007-03-08 13:47:48 1,843,584 ----a-w C:\XP\system32\win32k.sys2007-03-08 04:59:59 -------- d-----w C:\Program Files\DirPrn2007-03-07 09:16:28 -------- d-----w C:\Program Files\'Net Monitor2007-03-07 09:13:15 -------- d-----w C:\Program Files\PTZone2007-03-07 09:10:26 -------- d-----w C:\Program Files\WinWatch2007-03-07 09:10:21 249,856 ------w C:\XP\Setup1.exe2007-03-07 09:10:09 -------- d-----w C:\Program Files\LanMon2007-03-07 09:09:11 73,216 ------w C:\XP\ST6UNST.EXE2007-02-28 08:59:01 26,000 ----a-w C:\XP\system32\E3TL.DLL2007-02-05 20:17:02 185,344 ----a-w C:\XP\system32\upnphost.dll(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21]{AE7CD045-E861-484f-8273-0445EE161910}=D:\Acrobat7\Acrobat\AcroIEFavClient.dll [2005-09-24 00:41][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"NvCplDaemon"="C:\XP\system32\NvCpl.dll" [2005-10-28 16:06][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SpeedStartup"="C:\Program Files\Speed Startup\speedstartup.exe" [2006-12-14 17:12][HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]"SpeedStartup"=C:\Program Files\Speed Startup\speedstartup.exe runonce[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="D:\Internet\eudora\EuShlExt.dll" [2005-11-14 16:15]"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 09:13][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]C:\Program Files\SpywareDetector\SDNotify.dll[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]Authentication Packages msv1_0 relog_ap[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Y]AutoRun\command- Y:\vfpstart.exe IE5="vfpstart.hta" IELess="vfpstart.htm"Contents of the 'Scheduled Tasks' folder2007-05-22 12:48:24 C:\XP\tasks\New Task 2.job2007-05-22 10:54:10 C:\XP\tasks\New Task.job2007-05-22 10:50:00 C:\XP\tasks\_viceversapr2_task_Bashful2Booby.job2007-05-22 11:30:00 C:\XP\tasks\_viceversapr2_task_batch.job2007-05-22 15:00:00 C:\XP\tasks\_viceversapr2_task_Bills.job2007-03-26 09:40:18 C:\XP\tasks\_viceversapr2_task_documents_and_settings.job2007-05-22 11:10:00 C:\XP\tasks\_viceversapr2_task_Eudora.job2007-05-22 15:00:00 C:\XP\tasks\_viceversapr2_task_hits prg to Tweetie D.job2007-05-22 06:00:00 C:\XP\tasks\_viceversapr2_task_HITSSOURCES.job2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_HITSVEN.job2007-05-22 13:15:00 C:\XP\tasks\_viceversapr2_task_Idisk.job2007-05-22 13:00:00 C:\XP\tasks\_viceversapr2_task_Links.job2007-03-26 09:33:37 C:\XP\tasks\_viceversapr2_task_madden.job2007-05-22 09:59:49 C:\XP\tasks\_viceversapr2_task_newag.job2007-05-22 10:30:00 C:\XP\tasks\_viceversapr2_task_OHITS.job2007-05-22 11:34:00 C:\XP\tasks\_viceversapr2_task_personal.job2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_ServersAlive.job2007-05-22 12:00:53 C:\XP\tasks\_viceversapr2_task_Steviebone.job2007-03-26 11:38:02 C:\XP\tasks\_viceversapr2_task_Torrents.job2007-05-22 14:15:00 C:\XP\tasks\_viceversapr2_task_txdot.job2007-05-22 11:20:00 C:\XP\tasks\_viceversapr2_task_visaversaprofiles.job********************************************************************catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.netRootkit scan 2007-05-22 10:06:49Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ...scanning hidden autostart entries ...scanning hidden files ...scan completed successfullyhidden files: 0********************************************************************Completion time: 2007-05-22 10:08:30C:\ComboFix-quarantined-files.txt ... 2007-05-22 10:08C:\ComboFix2.txt ... 2007-05-22 09:39C:\ComboFix3.txt ... 2007-05-20 14:38 --- E O F ---2006-04-26 00:31 775 --a------ C:\Qoobox\Quarantine\C\DOCUME~1\STAYPU~1\Desktop\Internet Explorer.lnk.vir2006-05-05 03:30 300 --a------ C:\Qoobox\Quarantine\C\Program Files\INSTALL.LOG.vir2007-05-20 10:22 77725 --a------ C:\Qoobox\Quarantine\catchme2007-05-20_135445.26.zip2007-05-22 09:27 500 --a------ C:\Qoobox\Quarantine\catchme.logFolder PATH listing for volume PrimaryCVolume serial number is 747C-9F49C:\QOOBOX\---Quarantine | catchme.log | catchme2007-05-20_135445.26.zip | +---C | +---DOCUME~1 | | \---STAYPU~1 | | \---Desktop | | Internet Explorer.lnk.vir | | | \---Program Files | INSTALL.LOG.vir | \---Registry_backups Quote Link to post Share on other sites
Steviebone Posted May 22, 2007 Author Report Share Posted May 22, 2007 running the rustbfix thingy again next Quote Link to post Share on other sites
Steviebone Posted May 22, 2007 Author Report Share Posted May 22, 2007 ************************* Rustock.b-fix v. 1.01 -- By ejvindh *************************Tue 05/22/2007 13:56:46.09No Rustock.b-rootkits found******************************* End of Logfile ******************************** Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.