Mofogo
2010-05-01, 20:01
Sorry Blade81 for not getting back to you in a timely manner. I was in the process of getting married last weekend so I couldn't get the stuff up and running quickly.
My ultimate goal is to be able to get this computer basically back to factory settings without having the install CD. I can't run a recovery at this point and the dell restore partition does not exist.
Hi,
Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
* When done, DDS will open two (2) logs:
1. DDS.txt
2. Attach.txt
* Save both reports to your desktop. Post them back to your topic.
---
Download GMER here by clicking download exe -button and then saving it your desktop:
* Double-click .exe that you downloaded
* Click rootkit-tab, uncheck files option and then click scan.
* Don't check
Show All
box while scanning in progress!
* When scanning is ready, click Copy.
* This copies log to clipboard
* Post log (if the log is long, archive it into a zip file and attach instead of posting) in your reply.
====================================
D.D.S LOG
DDS (Ver_10-03-17.01) - NTFSx86
Run by Penny at 11:42:24.15 on Sat 05/01/2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.202 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Penny\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: c:\windows\system32\hs78344kjkfd.dll: {c5bf49a2-94f3-42bd-f434-3604812c8955} - c:\windows\system32\hs78344kjkfd.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll
uRun: [gls5764m8zbbhqqvtuo39ny8zy8vh51j] c:\docume~1\penny\locals~1\temp\xgwdga0.exe
uRun: [ol69ou5fzt7m7vz45nelmg4okduaj8s8] c:\docume~1\penny\locals~1\temp\t4gyaekw6t3.exe
uRun: [ebw6vrl4rzvo9i] c:\docume~1\penny\locals~1\temp\ka2h4zg.exe
uRun: [shutzpg3kb7kdiz] c:\docume~1\penny\locals~1\temp\qwf5z1osf3gck.exe
uRun: [t6hh4bq3n59npa2qm0vxs8r3eeg30yd89d35vnk60uz35i] c:\docume~1\penny\locals~1\temp\iiwyc9jn9u4yo.exe
uRun: [u55d1n0jy2] c:\docume~1\penny\locals~1\temp\pe85xl1thwqh.exe
uRun: [c825jropl1ubec5djr0hhwsy33nu0mqayhjjl7y07bv26gg4] c:\docume~1\penny\locals~1\temp\a5gzjydd.exe
uRun: [phmw5k7xcbih4u0j8jz7at4n8jcu8izb666on6g] c:\docume~1\penny\locals~1\temp\cgltkycli5s.exe
uRun: [v0xv9cmmolhfohmulc5] c:\docume~1\penny\locals~1\temp\v6b6pkzpktb.exe
uRun: [op5rbtzkedvvxo7q565sozu5nemtk4i] c:\docume~1\penny\locals~1\temp\n1po3x3zbpq7.exe
uRun: [rjmd4lrznub5cfjt92cdtyatjpiacy2hn97mb16] c:\docume~1\penny\locals~1\temp\irec25an.exe
uRun: [lx4nrbpuqv6dz47qqiiyzsrmk1upq2bxhe] c:\docume~1\penny\locals~1\temp\wuhm9x0w.exe
uRun: [xfujz5oe8gw9] c:\docume~1\penny\locals~1\temp\l38upsig.exe
uRun: [v4ngkgl44v1bnjtnyauoc1e39ep00hs44dw954] c:\docume~1\penny\locals~1\temp\uebdjnz0kn.exe
uRun: [vetypmkt4r4gkyb8lnbgb14i6] c:\docume~1\penny\locals~1\temp\z7vz41mq30kmo.exe
uRun: [i0l6050d0045p65ikob841d2g5ukc9bv2t3ofujrle370] c:\docume~1\penny\locals~1\temp\jmitfbse7zg.exe
mRun: [Kboqucocali] rundll32.exe "c:\windows\Kragus.dll",e
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
StartupFolder: c:\docume~1\penny\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-system: DisableTaskMgr = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Open Link Target in Firefox - file://c:\documents and settings\penny\application data\mozilla\firefox\profiles\op2ux18j.default\extensions\{5d558c43-550f-4b12-84ab-0d8abda9f975}\firefoxviewlink.html
IE: View This Page in Firefox - file://c:\documents and settings\penny\application data\mozilla\firefox\profiles\op2ux18j.default\extensions\{5d558c43-550f-4b12-84ab-0d8abda9f975}\firefoxviewpage.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: c:\docume~1\penny\locals~1\temp\ntdll64.dll
DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://site.ebrary.com.library.capella.edu/lib/capella/support/plugins/ebraryRdr.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} - hxxp://www.linkedin.com/cab/LinkedInContactFinderControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {BA11E984-66D3-11D3-9196-006008105FA5} - hxxps://remote.precysesolutions.com/SDClientTools.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: crypt - crypts.dll
Notify: winctrl32 - WinCtrl32.dll
AppInit_DLLs: sxedib.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: c:\windows\system32\hs78344kjkfd.dll: {c5bf49a2-94f3-42bd-f434-3604812c8955} - c:\windows\system32\hs78344kjkfd.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\yayxVoOf
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\penny\applic~1\mozilla\firefox\profiles\op2ux18j.default\
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&query=
FF - component: c:\documents and settings\penny\application data\mozilla\firefox\profiles\op2ux18j.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\documents and settings\penny\application data\mozilla\firefox\profiles\op2ux18j.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
============= SERVICES / DRIVERS ===============
R0 winrv61;winrv61;c:\windows\system32\drivers\Winrv61.sys [2007-8-6 31616]
R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [2003-10-23 76160]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-8-6 24652]
S3 DCALEXICO;DCALEXICO;c:\windows\system32\drivers\dcalexico.sys --> c:\windows\system32\drivers\DCalexico.sys [?]
S3 winwb50;winwb50;\??\c:\windows\system32\drivers\winwb50.sys --> c:\windows\system32\drivers\Winwb50.sys [?]
=============== Created Last 30 ================
2010-05-01 16:41:35 1026 ----a-w- c:\windows\irokicuhuhoneni.dll
2010-04-21 09:51:41 0 d-----w- c:\program files\Trend Micro
2010-04-20 23:43:27 1026 ----a-w- c:\windows\ecoranaw.dll
2010-04-20 22:32:29 1026 ----a-w- c:\windows\ojogidel.dll
2010-04-20 14:25:20 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-04-20 14:25:20 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-04-20 11:46:47 16896 ----a-w- c:\windows\system32\WinCtrl32.dll
==================== Find3M ====================
2010-05-01 16:42:37 100590 ----a-w- c:\windows\system32\drivers\d3c003b.sys
2004-08-04 10:00:00 94784 --sh--w- c:\windows\twain.dll
2004-08-04 10:00:00 50688 --sh--w- c:\windows\twain_32.dll
2006-02-17 04:33:10 1216 --sh--w- c:\windows\Twunk_16.dll
2006-02-17 04:33:10 1216 --sh--w- c:\windows\Twunk_32.dll
2009-02-22 17:11:10 2320 --sha-w- c:\windows\system32\fOoVxyay.ini2
2004-08-04 10:00:00 1028096 --sh--w- c:\windows\system32\mfc42.dll
2004-08-04 10:00:00 54784 --sh--w- c:\windows\system32\msvcirt.dll
2004-08-04 10:00:00 413696 --sh--w- c:\windows\system32\msvcp60.dll
2004-08-04 10:00:00 343040 --sh--w- c:\windows\system32\msvcrt.dll
2007-12-04 18:38:13 550912 --sh--w- c:\windows\system32\oleaut32.dll
2004-08-04 10:00:00 83456 --sh--w- c:\windows\system32\olepro32.dll
2004-08-04 10:00:00 11776 --sh--w- c:\windows\system32\regsvr32.exe
============= FINISH: 11:43:49.88 ===============
GMER OUTPUT
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-01 12:00:14
Windows 5.1.2600 Service Pack 2
Running: rm22663k.exe; Driver: C:\DOCUME~1\Penny\LOCALS~1\Temp\axnoapow.sys
---- System - GMER 1.0.15 ----
Code 83257E80 ZwEnumerateKey
Code 8322D4E0 ZwFlushInstructionCache
Code 8319046E IofCallDriver
Code 832272E6 IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!IofCallDriver 804E37C5 5 Bytes JMP 83190473
.text ntoskrnl.exe!IofCompleteRequest 804E3BF6 5 Bytes JMP 832272EB
PAGE ntoskrnl.exe!ZwEnumerateKey 8056F0B0 5 Bytes JMP 83257E84
PAGE ntoskrnl.exe!ZwFlushInstructionCache 8057882D 5 Bytes JMP 8322D4E4
? C:\WINDOWS\system32\drivers\Winrv61.sys Access is denied.
init C:\WINDOWS\system32\drivers\tiumflt.sys entry point in "init" section [0xF8CFCD00]
init C:\WINDOWS\system32\drivers\tiumfwl.sys entry point in "init" section [0xF8B324C0]
init C:\WINDOWS\system32\DRIVERS\gticard.sys entry point in "init" section [0xF2584B20]
? C:\WINDOWS\System32\drivers\d3c003b.sys The system cannot find the file specified.
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\rundll32.exe[204] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A8000A
.text C:\WINDOWS\system32\rundll32.exe[204] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A9000A
.text C:\WINDOWS\system32\winlogon.exe[484] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006A000A
.text C:\WINDOWS\system32\winlogon.exe[484] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006B000A
.text C:\WINDOWS\system32\services.exe[528] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006A000A
.text C:\WINDOWS\system32\services.exe[528] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006B000A
.text C:\WINDOWS\system32\lsass.exe[540] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0070000A
.text C:\WINDOWS\system32\lsass.exe[540] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0073000A
.text C:\WINDOWS\system32\SearchIndexer.exe[980] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A5000A
.text C:\WINDOWS\system32\SearchIndexer.exe[980] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A6000A
.text C:\WINDOWS\system32\SearchIndexer.exe[980] kernel32.dll!WriteFile 7C810D87 7 Bytes JMP 00E61B19 C:\WINDOWS\system32\mssrch.dll (mssrch.lib/Microsoft Corporation)
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1144] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1144] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009A000A
.text C:\WINDOWS\System32\bcmwltry.exe[1156] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00BD000A
.text C:\WINDOWS\System32\bcmwltry.exe[1156] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00BE000A
.text C:\WINDOWS\system32\userinit.exe[1236] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009B000A
.text C:\WINDOWS\system32\userinit.exe[1236] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009C000A
.text C:\WINDOWS\system32\spoolsv.exe[1284] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0099000A
.text C:\WINDOWS\system32\spoolsv.exe[1284] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009A000A
.text C:\WINDOWS\System32\SCardSvr.exe[1380] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0070000A
.text C:\WINDOWS\System32\SCardSvr.exe[1380] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0071000A
.text C:\WINDOWS\Explorer.EXE[1456] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00AB000A
.text C:\WINDOWS\Explorer.EXE[1456] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00AC000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1608] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0072000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1608] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0073000A
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[1656] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009E000A
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[1656] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009F000A
.text C:\WINDOWS\system32\nvsvc32.exe[1788] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 007B000A
.text C:\WINDOWS\system32\nvsvc32.exe[1788] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 007C000A
.text C:\WINDOWS\system32\HPZipm12.exe[1804] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0071000A
.text C:\WINDOWS\system32\HPZipm12.exe[1804] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0072000A
.text C:\WINDOWS\system32\notepad.exe[2092] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0098000A
.text C:\WINDOWS\system32\notepad.exe[2092] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\alg.exe[2296] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0070000A
.text C:\WINDOWS\System32\alg.exe[2296] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0071000A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2344] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0080000A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2344] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0083000A
.text C:\WINDOWS\system32\notepad.exe[2748] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0098000A
.text C:\WINDOWS\system32\notepad.exe[2748] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0099000A
.text C:\WINDOWS\system32\wscript.exe[2760] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A4000A
.text C:\WINDOWS\system32\wscript.exe[2760] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A5000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00CC000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00CD000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00CEFE90 \\?\globalroot\systemroot\system32\UACmnblycld.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00CF09A0 \\?\globalroot\systemroot\system32\UACmnblycld.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] WS2_32.dll!send 71AB428A 5 Bytes JMP 00CF0780 \\?\globalroot\systemroot\system32\UACmnblycld.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 00CF0110 \\?\globalroot\systemroot\system32\UACmnblycld.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00CF0B80 \\?\globalroot\systemroot\system32\UACmnblycld.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 10014B74 C:\WINDOWS\system32\sxedib.dll
.text C:\Documents and Settings\Penny\Desktop\rm22663k.exe[3236] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A6000A
.text C:\Documents and Settings\Penny\Desktop\rm22663k.exe[3236] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A7000A
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs d3c003b.sys
Device \Driver\Tcpip \Device\Ip d3c003b.sys
Device \FileSystem\MRxDAV \Device\WebDavRedirector Winrv61.sys
Device \Driver\Tcpip \Device\Tcp d3c003b.sys
Device \Driver\Tcpip \Device\Udp d3c003b.sys
Device \Driver\Tcpip \Device\RawIp d3c003b.sys
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver Winrv61.sys
Device \Driver\Tcpip \Device\IPMULTICAST d3c003b.sys
Device \FileSystem\MRxSmb \Device\LanmanRedirector Winrv61.sys
Device \FileSystem\Cdfs \Cdfs Winrv61.sys
---- Modules - GMER 1.0.15 ----
Module \systemroot\system32\drivers\UACrojbekmw.sys (*** hidden *** ) F2720000-F2733000 (77824 bytes)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\rundll32.exe [204] 0x00AA0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [328] 0x00710000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\winlogon.exe [484] 0x006C0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\services.exe [528] 0x006C0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\lsass.exe [540] 0x00740000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [764] 0x00710000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [820] 0x00710000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\SearchIndexer.exe [980] 0x00A70000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [992] 0x00710000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1028] 0x00710000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\System32\WLTRYSVC.EXE [1144] 0x009B0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\System32\bcmwltry.exe [1156] 0x00BF0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\userinit.exe [1236] 0x00B10000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [1284] 0x009B0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\System32\SCardSvr.exe [1380] 0x00720000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [1456] 0x00AF0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [1608] 0x00740000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe [1656] 0x00A00000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\nvsvc32.exe [1788] 0x007D0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\HPZipm12.exe [1804] 0x00730000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\notepad.exe [2092] 0x009A0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [2296] 0x00720000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\wbem\wmiprvse.exe [2344] 0x00840000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\notepad.exe [2748] 0x009A0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\wscript.exe [2760] 0x00A60000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\Program Files\Mozilla Firefox\firefox.exe [3204] 0x00CE0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\Documents and Settings\Penny\Desktop\rm22663k.exe [3236] 0x00BC0000
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\System32\drivers\d3c003b.sys (*** hidden *** ) [SYSTEM] d3c003b <-- ROOTKIT !!!
Service C:\WINDOWS\system32\drivers\UACrojbekmw.sys (*** hidden *** ) [SYSTEM] uacd.sys <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\d3c003b@ImagePath \SystemRoot\System32\drivers\d3c003b.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\d3c003b@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\d3c003b@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\d3c003b@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\d3c003b@F96ZK6nPB aHR0cDovL2VrYmFkLm1lOjgwLw==
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys@imagepath \systemroot\system32\drivers\UACrojbekmw.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACrojbekmw.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACfrmfadfe.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACpfofxhlm.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACnwelcsit.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UACxbnbelur.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACmnblycld.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UAClqrfnpkd.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACgkfdqhvk.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACsbobkayk.log
Reg HKLM\SYSTEM\ControlSet003\Services\d3c003b@ImagePath \SystemRoot\System32\drivers\d3c003b.sys
Reg HKLM\SYSTEM\ControlSet003\Services\d3c003b@Type 1
Reg HKLM\SYSTEM\ControlSet003\Services\d3c003b@Start 1
Reg HKLM\SYSTEM\ControlSet003\Services\d3c003b@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet003\Services\d3c003b@F96ZK6nPB aHR0cDovL2VrYmFkLm1lOjgwLw==
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys@imagepath \systemroot\system32\drivers\UACrojbekmw.sys
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACrojbekmw.sys
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACfrmfadfe.dll
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACpfofxhlm.dat
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACnwelcsit.dll
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UACxbnbelur.dll
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACmnblycld.dll
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UAClqrfnpkd.log
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACgkfdqhvk.log
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACsbobkayk.log
---- EOF - GMER 1.0.15 ----
My ultimate goal is to be able to get this computer basically back to factory settings without having the install CD. I can't run a recovery at this point and the dell restore partition does not exist.
Hi,
Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
* When done, DDS will open two (2) logs:
1. DDS.txt
2. Attach.txt
* Save both reports to your desktop. Post them back to your topic.
---
Download GMER here by clicking download exe -button and then saving it your desktop:
* Double-click .exe that you downloaded
* Click rootkit-tab, uncheck files option and then click scan.
* Don't check
Show All
box while scanning in progress!
* When scanning is ready, click Copy.
* This copies log to clipboard
* Post log (if the log is long, archive it into a zip file and attach instead of posting) in your reply.
====================================
D.D.S LOG
DDS (Ver_10-03-17.01) - NTFSx86
Run by Penny at 11:42:24.15 on Sat 05/01/2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.202 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Penny\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: c:\windows\system32\hs78344kjkfd.dll: {c5bf49a2-94f3-42bd-f434-3604812c8955} - c:\windows\system32\hs78344kjkfd.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll
uRun: [gls5764m8zbbhqqvtuo39ny8zy8vh51j] c:\docume~1\penny\locals~1\temp\xgwdga0.exe
uRun: [ol69ou5fzt7m7vz45nelmg4okduaj8s8] c:\docume~1\penny\locals~1\temp\t4gyaekw6t3.exe
uRun: [ebw6vrl4rzvo9i] c:\docume~1\penny\locals~1\temp\ka2h4zg.exe
uRun: [shutzpg3kb7kdiz] c:\docume~1\penny\locals~1\temp\qwf5z1osf3gck.exe
uRun: [t6hh4bq3n59npa2qm0vxs8r3eeg30yd89d35vnk60uz35i] c:\docume~1\penny\locals~1\temp\iiwyc9jn9u4yo.exe
uRun: [u55d1n0jy2] c:\docume~1\penny\locals~1\temp\pe85xl1thwqh.exe
uRun: [c825jropl1ubec5djr0hhwsy33nu0mqayhjjl7y07bv26gg4] c:\docume~1\penny\locals~1\temp\a5gzjydd.exe
uRun: [phmw5k7xcbih4u0j8jz7at4n8jcu8izb666on6g] c:\docume~1\penny\locals~1\temp\cgltkycli5s.exe
uRun: [v0xv9cmmolhfohmulc5] c:\docume~1\penny\locals~1\temp\v6b6pkzpktb.exe
uRun: [op5rbtzkedvvxo7q565sozu5nemtk4i] c:\docume~1\penny\locals~1\temp\n1po3x3zbpq7.exe
uRun: [rjmd4lrznub5cfjt92cdtyatjpiacy2hn97mb16] c:\docume~1\penny\locals~1\temp\irec25an.exe
uRun: [lx4nrbpuqv6dz47qqiiyzsrmk1upq2bxhe] c:\docume~1\penny\locals~1\temp\wuhm9x0w.exe
uRun: [xfujz5oe8gw9] c:\docume~1\penny\locals~1\temp\l38upsig.exe
uRun: [v4ngkgl44v1bnjtnyauoc1e39ep00hs44dw954] c:\docume~1\penny\locals~1\temp\uebdjnz0kn.exe
uRun: [vetypmkt4r4gkyb8lnbgb14i6] c:\docume~1\penny\locals~1\temp\z7vz41mq30kmo.exe
uRun: [i0l6050d0045p65ikob841d2g5ukc9bv2t3ofujrle370] c:\docume~1\penny\locals~1\temp\jmitfbse7zg.exe
mRun: [Kboqucocali] rundll32.exe "c:\windows\Kragus.dll",e
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
StartupFolder: c:\docume~1\penny\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-system: DisableTaskMgr = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Open Link Target in Firefox - file://c:\documents and settings\penny\application data\mozilla\firefox\profiles\op2ux18j.default\extensions\{5d558c43-550f-4b12-84ab-0d8abda9f975}\firefoxviewlink.html
IE: View This Page in Firefox - file://c:\documents and settings\penny\application data\mozilla\firefox\profiles\op2ux18j.default\extensions\{5d558c43-550f-4b12-84ab-0d8abda9f975}\firefoxviewpage.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: c:\docume~1\penny\locals~1\temp\ntdll64.dll
DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} - hxxp://site.ebrary.com.library.capella.edu/lib/capella/support/plugins/ebraryRdr.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} - hxxp://www.linkedin.com/cab/LinkedInContactFinderControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {BA11E984-66D3-11D3-9196-006008105FA5} - hxxps://remote.precysesolutions.com/SDClientTools.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: crypt - crypts.dll
Notify: winctrl32 - WinCtrl32.dll
AppInit_DLLs: sxedib.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: c:\windows\system32\hs78344kjkfd.dll: {c5bf49a2-94f3-42bd-f434-3604812c8955} - c:\windows\system32\hs78344kjkfd.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\yayxVoOf
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\penny\applic~1\mozilla\firefox\profiles\op2ux18j.default\
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&query=
FF - component: c:\documents and settings\penny\application data\mozilla\firefox\profiles\op2ux18j.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\documents and settings\penny\application data\mozilla\firefox\profiles\op2ux18j.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
============= SERVICES / DRIVERS ===============
R0 winrv61;winrv61;c:\windows\system32\drivers\Winrv61.sys [2007-8-6 31616]
R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [2003-10-23 76160]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-8-6 24652]
S3 DCALEXICO;DCALEXICO;c:\windows\system32\drivers\dcalexico.sys --> c:\windows\system32\drivers\DCalexico.sys [?]
S3 winwb50;winwb50;\??\c:\windows\system32\drivers\winwb50.sys --> c:\windows\system32\drivers\Winwb50.sys [?]
=============== Created Last 30 ================
2010-05-01 16:41:35 1026 ----a-w- c:\windows\irokicuhuhoneni.dll
2010-04-21 09:51:41 0 d-----w- c:\program files\Trend Micro
2010-04-20 23:43:27 1026 ----a-w- c:\windows\ecoranaw.dll
2010-04-20 22:32:29 1026 ----a-w- c:\windows\ojogidel.dll
2010-04-20 14:25:20 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-04-20 14:25:20 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-04-20 11:46:47 16896 ----a-w- c:\windows\system32\WinCtrl32.dll
==================== Find3M ====================
2010-05-01 16:42:37 100590 ----a-w- c:\windows\system32\drivers\d3c003b.sys
2004-08-04 10:00:00 94784 --sh--w- c:\windows\twain.dll
2004-08-04 10:00:00 50688 --sh--w- c:\windows\twain_32.dll
2006-02-17 04:33:10 1216 --sh--w- c:\windows\Twunk_16.dll
2006-02-17 04:33:10 1216 --sh--w- c:\windows\Twunk_32.dll
2009-02-22 17:11:10 2320 --sha-w- c:\windows\system32\fOoVxyay.ini2
2004-08-04 10:00:00 1028096 --sh--w- c:\windows\system32\mfc42.dll
2004-08-04 10:00:00 54784 --sh--w- c:\windows\system32\msvcirt.dll
2004-08-04 10:00:00 413696 --sh--w- c:\windows\system32\msvcp60.dll
2004-08-04 10:00:00 343040 --sh--w- c:\windows\system32\msvcrt.dll
2007-12-04 18:38:13 550912 --sh--w- c:\windows\system32\oleaut32.dll
2004-08-04 10:00:00 83456 --sh--w- c:\windows\system32\olepro32.dll
2004-08-04 10:00:00 11776 --sh--w- c:\windows\system32\regsvr32.exe
============= FINISH: 11:43:49.88 ===============
GMER OUTPUT
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-01 12:00:14
Windows 5.1.2600 Service Pack 2
Running: rm22663k.exe; Driver: C:\DOCUME~1\Penny\LOCALS~1\Temp\axnoapow.sys
---- System - GMER 1.0.15 ----
Code 83257E80 ZwEnumerateKey
Code 8322D4E0 ZwFlushInstructionCache
Code 8319046E IofCallDriver
Code 832272E6 IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!IofCallDriver 804E37C5 5 Bytes JMP 83190473
.text ntoskrnl.exe!IofCompleteRequest 804E3BF6 5 Bytes JMP 832272EB
PAGE ntoskrnl.exe!ZwEnumerateKey 8056F0B0 5 Bytes JMP 83257E84
PAGE ntoskrnl.exe!ZwFlushInstructionCache 8057882D 5 Bytes JMP 8322D4E4
? C:\WINDOWS\system32\drivers\Winrv61.sys Access is denied.
init C:\WINDOWS\system32\drivers\tiumflt.sys entry point in "init" section [0xF8CFCD00]
init C:\WINDOWS\system32\drivers\tiumfwl.sys entry point in "init" section [0xF8B324C0]
init C:\WINDOWS\system32\DRIVERS\gticard.sys entry point in "init" section [0xF2584B20]
? C:\WINDOWS\System32\drivers\d3c003b.sys The system cannot find the file specified.
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\rundll32.exe[204] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A8000A
.text C:\WINDOWS\system32\rundll32.exe[204] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A9000A
.text C:\WINDOWS\system32\winlogon.exe[484] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006A000A
.text C:\WINDOWS\system32\winlogon.exe[484] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006B000A
.text C:\WINDOWS\system32\services.exe[528] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 006A000A
.text C:\WINDOWS\system32\services.exe[528] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 006B000A
.text C:\WINDOWS\system32\lsass.exe[540] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0070000A
.text C:\WINDOWS\system32\lsass.exe[540] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0073000A
.text C:\WINDOWS\system32\SearchIndexer.exe[980] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A5000A
.text C:\WINDOWS\system32\SearchIndexer.exe[980] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A6000A
.text C:\WINDOWS\system32\SearchIndexer.exe[980] kernel32.dll!WriteFile 7C810D87 7 Bytes JMP 00E61B19 C:\WINDOWS\system32\mssrch.dll (mssrch.lib/Microsoft Corporation)
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1144] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\WLTRYSVC.EXE[1144] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009A000A
.text C:\WINDOWS\System32\bcmwltry.exe[1156] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00BD000A
.text C:\WINDOWS\System32\bcmwltry.exe[1156] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00BE000A
.text C:\WINDOWS\system32\userinit.exe[1236] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009B000A
.text C:\WINDOWS\system32\userinit.exe[1236] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009C000A
.text C:\WINDOWS\system32\spoolsv.exe[1284] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0099000A
.text C:\WINDOWS\system32\spoolsv.exe[1284] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009A000A
.text C:\WINDOWS\System32\SCardSvr.exe[1380] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0070000A
.text C:\WINDOWS\System32\SCardSvr.exe[1380] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0071000A
.text C:\WINDOWS\Explorer.EXE[1456] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00AB000A
.text C:\WINDOWS\Explorer.EXE[1456] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00AC000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1608] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0072000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1608] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0073000A
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[1656] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009E000A
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[1656] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 009F000A
.text C:\WINDOWS\system32\nvsvc32.exe[1788] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 007B000A
.text C:\WINDOWS\system32\nvsvc32.exe[1788] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 007C000A
.text C:\WINDOWS\system32\HPZipm12.exe[1804] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0071000A
.text C:\WINDOWS\system32\HPZipm12.exe[1804] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0072000A
.text C:\WINDOWS\system32\notepad.exe[2092] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0098000A
.text C:\WINDOWS\system32\notepad.exe[2092] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\alg.exe[2296] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0070000A
.text C:\WINDOWS\System32\alg.exe[2296] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0071000A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2344] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0080000A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2344] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0083000A
.text C:\WINDOWS\system32\notepad.exe[2748] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0098000A
.text C:\WINDOWS\system32\notepad.exe[2748] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0099000A
.text C:\WINDOWS\system32\wscript.exe[2760] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A4000A
.text C:\WINDOWS\system32\wscript.exe[2760] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A5000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00CC000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00CD000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00CEFE90 \\?\globalroot\systemroot\system32\UACmnblycld.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00CF09A0 \\?\globalroot\systemroot\system32\UACmnblycld.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] WS2_32.dll!send 71AB428A 5 Bytes JMP 00CF0780 \\?\globalroot\systemroot\system32\UACmnblycld.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 00CF0110 \\?\globalroot\systemroot\system32\UACmnblycld.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00CF0B80 \\?\globalroot\systemroot\system32\UACmnblycld.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[3204] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 10014B74 C:\WINDOWS\system32\sxedib.dll
.text C:\Documents and Settings\Penny\Desktop\rm22663k.exe[3236] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00A6000A
.text C:\Documents and Settings\Penny\Desktop\rm22663k.exe[3236] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A7000A
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs d3c003b.sys
Device \Driver\Tcpip \Device\Ip d3c003b.sys
Device \FileSystem\MRxDAV \Device\WebDavRedirector Winrv61.sys
Device \Driver\Tcpip \Device\Tcp d3c003b.sys
Device \Driver\Tcpip \Device\Udp d3c003b.sys
Device \Driver\Tcpip \Device\RawIp d3c003b.sys
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver Winrv61.sys
Device \Driver\Tcpip \Device\IPMULTICAST d3c003b.sys
Device \FileSystem\MRxSmb \Device\LanmanRedirector Winrv61.sys
Device \FileSystem\Cdfs \Cdfs Winrv61.sys
---- Modules - GMER 1.0.15 ----
Module \systemroot\system32\drivers\UACrojbekmw.sys (*** hidden *** ) F2720000-F2733000 (77824 bytes)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\rundll32.exe [204] 0x00AA0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [328] 0x00710000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\winlogon.exe [484] 0x006C0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\services.exe [528] 0x006C0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\lsass.exe [540] 0x00740000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [764] 0x00710000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [820] 0x00710000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\SearchIndexer.exe [980] 0x00A70000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [992] 0x00710000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1028] 0x00710000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\System32\WLTRYSVC.EXE [1144] 0x009B0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\System32\bcmwltry.exe [1156] 0x00BF0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\userinit.exe [1236] 0x00B10000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [1284] 0x009B0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\System32\SCardSvr.exe [1380] 0x00720000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [1456] 0x00AF0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [1608] 0x00740000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe [1656] 0x00A00000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\nvsvc32.exe [1788] 0x007D0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\HPZipm12.exe [1804] 0x00730000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\notepad.exe [2092] 0x009A0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [2296] 0x00720000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\wbem\wmiprvse.exe [2344] 0x00840000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\notepad.exe [2748] 0x009A0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\WINDOWS\system32\wscript.exe [2760] 0x00A60000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\Program Files\Mozilla Firefox\firefox.exe [3204] 0x00CE0000
Library \\?\globalroot\systemroot\system32\UACmnblycld.dll (*** hidden *** ) @ C:\Documents and Settings\Penny\Desktop\rm22663k.exe [3236] 0x00BC0000
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\System32\drivers\d3c003b.sys (*** hidden *** ) [SYSTEM] d3c003b <-- ROOTKIT !!!
Service C:\WINDOWS\system32\drivers\UACrojbekmw.sys (*** hidden *** ) [SYSTEM] uacd.sys <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\d3c003b@ImagePath \SystemRoot\System32\drivers\d3c003b.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\d3c003b@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\d3c003b@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\d3c003b@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\d3c003b@F96ZK6nPB aHR0cDovL2VrYmFkLm1lOjgwLw==
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys@imagepath \systemroot\system32\drivers\UACrojbekmw.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACrojbekmw.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACfrmfadfe.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACpfofxhlm.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACnwelcsit.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UACxbnbelur.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACmnblycld.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UAClqrfnpkd.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACgkfdqhvk.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\uacd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACsbobkayk.log
Reg HKLM\SYSTEM\ControlSet003\Services\d3c003b@ImagePath \SystemRoot\System32\drivers\d3c003b.sys
Reg HKLM\SYSTEM\ControlSet003\Services\d3c003b@Type 1
Reg HKLM\SYSTEM\ControlSet003\Services\d3c003b@Start 1
Reg HKLM\SYSTEM\ControlSet003\Services\d3c003b@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet003\Services\d3c003b@F96ZK6nPB aHR0cDovL2VrYmFkLm1lOjgwLw==
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys@imagepath \systemroot\system32\drivers\UACrojbekmw.sys
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACrojbekmw.sys
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACfrmfadfe.dll
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACpfofxhlm.dat
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACnwelcsit.dll
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UACxbnbelur.dll
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACmnblycld.dll
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UAClqrfnpkd.log
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACgkfdqhvk.log
Reg HKLM\SYSTEM\ControlSet003\Services\uacd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACsbobkayk.log
---- EOF - GMER 1.0.15 ----