PDA

View Full Version : GMER has found system modification caused by ROOTKIT activity



vodanok
2009-01-29, 22:47
Hello

thanks for this fantastic resource. I decided to run GMER because I saw these occasional popup windows opening and disappearing (but they were always too fast to see what they were). It appears my suspicions may be proven correct as when I ran GMER I got the following message:

"GMER has found system modification caused by ROOTKIT activity".

Can anybody help me to understand if I have a problem and what to do about it?


The following 4 lines were highlighted in red:
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [284] 0x01CE0000
Library C:\Program (*** hidden *** ) @ C:\Program Files\iTunes\iTunes.exe [3252] 0x059A0000
Library C:\Program (*** hidden *** ) @ C:\Program Files\Mozilla Firefox\firefox.exe [3292] 0x042E0000
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\system32\rundll32.exe [5104] 0x10000000


Many thanks in advance.

Shaba
2009-01-30, 10:40
Hello vodanok

Please see this (http://forums.spybot.info/showthread.php?t=288) next

Please follow the instructions in the above thread and then start a fresh topic with the logs required.

Regards.