Hi, I am running a Windows Vista laptop that has been hijacked by malware. Spybot S&D was disabled. I tried to repair this programme, no luck. Tried to reinstall, no luck becasue malware won't allow me to link to Safer-Networking webistes: 'Page Load Error - website not found'. Malware has also disabled TrendMicro 2008 by same process. Have downloaded 'HijackThis', but cant get it to run. Have downloaded and installed 'mbam' but can't get it to run. Have downloaded 'gmer' and run it with the following result:
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-29 21:22:02
Windows 6.0.6001 Service Pack 1
---- System - GMER 1.0.15 ----
SSDT 99455FC0 ZwCreateKey
SSDT 99455200 ZwCreateProcess
SSDT 994554C0 ZwCreateProcessEx
SSDT 99456E20 ZwCreateThread
SSDT 99456540 ZwDeleteKey
SSDT 99456800 ZwDeleteValueKey
SSDT 99457160 ZwLoadDriver
SSDT 99455A40 ZwOpenProcess
SSDT 99456280 ZwSetValueKey
SSDT 99455D00 ZwTerminateProcess
SSDT 99456C80 ZwWriteVirtualMemory
SSDT 99456FC0 ZwCreateThreadEx
SSDT 99455780 ZwCreateUserProcess
Code 8B087340 ZwEnumerateKey
Code 8B0DD2D8 ZwFlushInstructionCache
Code 8B0BF30D IofCallDriver
Code 8B0999CE IofCompleteRequest
Code 8B090305 ZwSaveKey
Code 8B08630D ZwSaveKeyEx
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCompleteRequest 81A55FE2 5 Bytes JMP 8B0999D3
.text ntkrnlpa.exe!ZwSaveKey 81A72664 5 Bytes JMP 8B09030A
.text ntkrnlpa.exe!ZwSaveKeyEx 81A72678 5 Bytes JMP 8B086312
.text ntkrnlpa.exe!KeSetTimerEx + 41C 81AD49E0 4 Bytes [C0, 5F, 45, 99] {RCR BYTE [EDI+0x45], 0x99}
.text ntkrnlpa.exe!KeSetTimerEx + 43C 81AD4A00 8 Bytes [00, 52, 45, 99, C0, 54, 45, ...]
.text ntkrnlpa.exe!KeSetTimerEx + 454 81AD4A18 4 Bytes [20, 6E, 45, 99] {AND [ESI+0x45], CH; CDQ }
.text ntkrnlpa.exe!KeSetTimerEx + 508 81AD4ACC 4 Bytes [40, 65, 45, 99]
.text ntkrnlpa.exe!KeSetTimerEx + 514 81AD4AD8 4 Bytes [00, 68, 45, 99] {ADD [EAX+0x45], CH; CDQ }
.text ...
.text ntkrnlpa.exe!IofCallDriver 81AD7F6F 5 Bytes JMP 8B0BF312
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 81BCE30B 5 Bytes JMP 8B0DD2DC
PAGE ntkrnlpa.exe!ZwEnumerateKey 81C23BA2 5 Bytes JMP 8B087344
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\tdx \Device\Udp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 01: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
---- EOF - GMER 1.0.15 ----
Grateful for any advice. Scotty D
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-29 21:22:02
Windows 6.0.6001 Service Pack 1
---- System - GMER 1.0.15 ----
SSDT 99455FC0 ZwCreateKey
SSDT 99455200 ZwCreateProcess
SSDT 994554C0 ZwCreateProcessEx
SSDT 99456E20 ZwCreateThread
SSDT 99456540 ZwDeleteKey
SSDT 99456800 ZwDeleteValueKey
SSDT 99457160 ZwLoadDriver
SSDT 99455A40 ZwOpenProcess
SSDT 99456280 ZwSetValueKey
SSDT 99455D00 ZwTerminateProcess
SSDT 99456C80 ZwWriteVirtualMemory
SSDT 99456FC0 ZwCreateThreadEx
SSDT 99455780 ZwCreateUserProcess
Code 8B087340 ZwEnumerateKey
Code 8B0DD2D8 ZwFlushInstructionCache
Code 8B0BF30D IofCallDriver
Code 8B0999CE IofCompleteRequest
Code 8B090305 ZwSaveKey
Code 8B08630D ZwSaveKeyEx
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCompleteRequest 81A55FE2 5 Bytes JMP 8B0999D3
.text ntkrnlpa.exe!ZwSaveKey 81A72664 5 Bytes JMP 8B09030A
.text ntkrnlpa.exe!ZwSaveKeyEx 81A72678 5 Bytes JMP 8B086312
.text ntkrnlpa.exe!KeSetTimerEx + 41C 81AD49E0 4 Bytes [C0, 5F, 45, 99] {RCR BYTE [EDI+0x45], 0x99}
.text ntkrnlpa.exe!KeSetTimerEx + 43C 81AD4A00 8 Bytes [00, 52, 45, 99, C0, 54, 45, ...]
.text ntkrnlpa.exe!KeSetTimerEx + 454 81AD4A18 4 Bytes [20, 6E, 45, 99] {AND [ESI+0x45], CH; CDQ }
.text ntkrnlpa.exe!KeSetTimerEx + 508 81AD4ACC 4 Bytes [40, 65, 45, 99]
.text ntkrnlpa.exe!KeSetTimerEx + 514 81AD4AD8 4 Bytes [00, 68, 45, 99] {ADD [EAX+0x45], CH; CDQ }
.text ...
.text ntkrnlpa.exe!IofCallDriver 81AD7F6F 5 Bytes JMP 8B0BF312
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 81BCE30B 5 Bytes JMP 8B0DD2DC
PAGE ntkrnlpa.exe!ZwEnumerateKey 81C23BA2 5 Bytes JMP 8B087344
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\tdx \Device\Udp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 01: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
---- EOF - GMER 1.0.15 ----
Grateful for any advice. Scotty D