Patrick000
2011-01-24, 12:19
Would you help me remove a virus and rootkit?
Two days ago, Internet Explorer crashed and the error was this:
AppName: iexplore.exe AppVer: 6.0.2800.1106 ModName: mshtml.dll ModVer: 6.0.2800.1561 Offset: 00185c12
I ran avast! free anti-virus v5.0.677.
It discovered a trojan which I had avast! remove:
C:\program files\unlocker\ebay-shortcuts_1016.exe
Now I have problems with Internet Explorer and windows explorer.
I have run DDS and GMER.
GMER said it found evidence of possible rootkit activity.
Below is my DDS.txt and GMER log. I also attached the zipped attach.txt.
Thank you for any help you may give me.
**********************************************
DDS (Ver_10-12-12.02) - NTFSx86
Run by Lord at 1:41:35.35 on Tue 01/25/2011
Internet Explorer: 6.0.2800.1106 BrowserJavaVersion: 1.6.0_17
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.510.111 [GMT -8:00]
============== Running Processes ===============
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\ge security supra\syncservice.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\GE Security Supra\ProxyDaemon.exe
C:\SSL\stunnel-4.10.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\System32\dmadmin.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\CAPM1RSK.EXE
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Maxtor\OneTouch\utils\mspm.exe
C:\PROGRA~1\RETROS~1\RETROS~1.1\RetroExpress.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\system32\spool\drivers\w32x86\3\CAPM1LAK.EXE
C:\WINNT\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE
C:\Program Files\GE Security Supra\SyncInfoApp.exe
C:\Program Files\Microsoft Office 2000\Office\1033\MSOFFICE.EXE
C:\WINNT\system32\TASKMGR.EXE
C:\PROGRA~1\RETROS~1\RETROS~1.1\retrorun.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\Microsoft Office 2000\Office\EXCEL.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Adobe\Acrobat 7.0 Professional\Acrobat\Acrobat.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINNT\system32\msiexec.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - f:\program files\orbitdownloader\orbitcth.dll
BHO: BHO Class: {8b3868b4-eba8-48fa-a19b-e1dfb99066fa} - f:\program files\flashcapture\fcbho.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll
TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - f:\program files\orbitdownloader\GrabPro.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [NeroFilterCheck] c:\winnt\system32\NeroCheck.exe
mRun: [MaxtorOneTouch] c:\program files\maxtor\onetouch\utils\Onetouch.exe
mRun: [mspm] c:\program files\maxtor\onetouch\utils\mspm.exe
mRun: [RetroExpress] c:\progra~1\retros~1\retros~1.1\RetroExpress.exe /h
mRun: [Dit] Dit.exe
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office 2000\office\1033\MSOFFICE.EXE
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\MYNETW~1.LNK -
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\taskmg~1.lnk - c:\winnt\system32\TASKMGR.EXE
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\autoru~1\teatimer.lnk - c:\program files\spybot - search & destroy\TeaTimer.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\canonp~1.lnk - c:\winnt\system32\spool\drivers\w32x86\3\CAPM1LAK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\displa~1.lnk - c:\program files\ge security supra\SyncInfoApp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\scansn~1.lnk - c:\program files\pfu\scansnap\driver\PfuSsMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\adobea~1.lnk - c:\winnt\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\micros~1.lnk - c:\program files\microsoft office 2000\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\scansn~1.lnk - f:\program files\pfu\scansnap\driver\PfuSsMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
uPolicies-system: RunStartupScriptSync = 1 (0x1)
mPolicies-system: RunStartupScriptSync = 1 (0x1)
IE: &Download by Orbit - f:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - f:\program files\orbitdownloader\orbitmxt.dll/204
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Do&wnload selected by Orbit - f:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - f:\program files\orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Save F&lash with FlashCapture - f:\program files\flashcapture\fciext.dll/FCIEXT.htm
IE: {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - res://f:\program files\flashcapture\fciext.dll/FCIEXT.htm
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {41564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: NavLogon - c:\winnt\system32\NavLogon.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\b5wt98kq.default\
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\winnt\system32\drivers\Lbd.sys [2009-4-18 64160]
R0 ROFF;ROFF;c:\winnt\system32\drivers\roff.sys [2003-6-9 42455]
R1 aswSP;aswSP;c:\winnt\system32\drivers\aswSP.sys [2010-9-29 165584]
R1 bbcap;bbcap;c:\winnt\system32\drivers\bbcap.sys [2009-7-18 2432]
R2 aswFsBlk;aswFsBlk;c:\winnt\system32\drivers\aswFsBlk.sys [2010-9-29 17744]
R2 aswMon;aswMon;c:\winnt\system32\drivers\aswmon.sys [2010-9-29 94544]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-29 40384]
R2 RapidPortM1;RapidPortM1;c:\winnt\system32\drivers\CAPM1LP.SYS [2006-4-19 22912]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-29 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-29 40384]
R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;c:\winnt\system32\drivers\el90xbc5.sys [2006-3-16 61712]
R4 NAVAPEL;NAVAPEL;\??\c:\program files\navnt\navapel.sys --> c:\program files\navnt\NAVAPEL.SYS [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456]
S3 MV;MV;c:\docume~1\admini~1\locals~1\temp\mv.exe --> c:\docume~1\admini~1\locals~1\temp\MV.exe [?]
S3 pgusbmme;usb-audio.de MME-Adapter;c:\winnt\system32\drivers\pgusbmm3.sys [2005-7-19 23520]
S3 pgusbwdm;usb-audio.de driver (commercial V2.6.1);c:\winnt\system32\drivers\pgusbwdm.sys [2005-7-19 99200]
S3 SQLAgent$RETSDATA;SQLAgent$RETSDATA;c:\program files\microsoft sql server\mssql$retsdata\binn\sqlagent.exe -i retsdata --> c:\program files\microsoft sql server\mssql$retsdata\binn\sqlagent.EXE -i RETSDATA [?]
S4 MSSQL$RETSDATA;MSSQL$RETSDATA;c:\program files\microsoft sql server\mssql$retsdata\binn\sqlservr.exe -sretsdata --> c:\program files\microsoft sql server\mssql$retsdata\binn\sqlservr.exe -sRETSDATA [?]
=============== Created Last 30 ================
2011-01-25 07:56:15 -------- d-s---w- c:\documents and settings\administrator\UserData
2011-01-20 06:46:15 21872 -c--a-w- c:\winnt\system32\dllcache\usbprint.sys
2011-01-20 06:46:15 21872 ----a-w- c:\winnt\system32\drivers\usbprint.sys
==================== Find3M ====================
2010-12-22 00:07:04 1409 ----a-w- c:\winnt\QTFont.for
2005-05-14 00:12:00 217073 --sha-r- c:\winnt\meta4.exe
2005-10-24 18:13:58 66560 --sha-r- c:\winnt\MOTA113.exe
2005-10-14 04:27:00 422400 --sha-r- c:\winnt\x2.64.exe
2005-10-08 02:14:52 308224 --sha-r- c:\winnt\system32\avisynth.dll
2005-07-14 19:31:20 27648 --sha-r- c:\winnt\system32\AVSredirect.dll
2005-06-22 05:37:42 45568 --sha-r- c:\winnt\system32\cygz.dll
2004-01-25 07:00:00 70656 --sha-r- c:\winnt\system32\i420vfw.dll
2006-04-27 17:24:24 2945024 --sha-r- c:\winnt\system32\Smab.dll
2005-02-28 20:16:22 240128 --sha-r- c:\winnt\system32\x.264.exe
2004-01-25 07:00:00 70656 --sha-r- c:\winnt\system32\yv12vfw.dll
============= FINISH: 1:43:01.26 ===============
****************************************
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-25 02:25:51
Windows 5.0.2195 Service Pack 4 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-2 WDC_WD200BB-75CAA0 rev.16.06V16
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\agtdrpow.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwClose [0xBB3724B3]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwCreateKey [0xBB3723B3]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwDeleteKey [0xBB372502]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwDeleteValueKey [0xBB372596]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwDuplicateObject [0xBBAC3782]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwFlushKey [0xBB3727DE]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwOpenKey [0xBB3722E8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenProcess [0xBBAC36C2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenThread [0xBBAC3726]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwQueryValueKey [0xBBAC3DA6]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRestoreKey [0xBBAC3D66]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwSetValueKey [0xBB3726A5]
---- Kernel code sections - GMER 1.0.15 ----
? C:\Program Files\NavNT\NAVAPEL.SYS The system cannot find the file specified. !
? C:\Program Files\Symantec\SYMEVENT.SYS The system cannot find the file specified. !
? C:\WINNT\system32\Drivers\PROCEXP100.SYS The system cannot find the file specified. !
? C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINNT\explorer.exe[2208] SHELL32.dll!SHFileOperationW 7CF800F5 5 Bytes JMP 10001102 C:\Program Files\Unlocker\UnlockerHook.dll
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
Device ftdisk.sys (FT Disk Driver/Microsoft Corporation)
AttachedDevice ROFF.sys (Retrospect Open File Filter/Dantz Development Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device Fs_Rec.SYS (File System Recognizer Driver/Microsoft Corporation)
---- Processes - GMER 1.0.15 ----
Library C:\Program (*** hidden *** ) @ C:\Program Files\Microsoft Office\Office10\WINWORD.EXE [2400] 0x049F0000
Library C:\Program (*** hidden *** ) @ C:\Program Files\Microsoft Office\Office10\WINWORD.EXE [2400] 0x04A90000
Library C:\Program (*** hidden *** ) @ C:\Program Files\Microsoft Office\Office10\WINWORD.EXE [2400] 0x05090000
Library C:\Program (*** hidden *** ) @ C:\Program Files\Microsoft Office\Office10\WINWORD.EXE [2400] 0x050A0000
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG04.00.00.01SERVER 3A2078B92014A5B4CADFF5E4B7F422A58EEEDB1A75EEBEB580A4C89D2C1C7B102ABC78ECDD962013CBE59E26EB70DFEA8E1E535552F60B784DDE0B7577C557886B98235F8CAD29DF3A807D727AE87D1070ADA394609DD72130848D07A034498C1DF16003817AFD8006F9D0AC5C9AE2FD94948753D8DCD53E9AD922003F3E6DEC667A39D65451C22C26917A4C48F8DBF26440D89BB66599B307183D20B0703ED16ED75AF3633BFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933BA7FD869164D67945D575E7D6A3B9808C038D530D6EB34522E68364DE22E87730B9ED2B760021749823AAEE139CA461B0CDC565E83538613A3279FF9798CAA47CB38BCF643AC09E22170E39BD19DA0947B8F090C49435E58A0189DF6FB07E9880A0A6D9571B98546B0EA04718844F726F5A0200A982A924192153C38355438FA1B33A4F0EFB87F3210AE20CE3AC4E2AE8398A0EF49A1F86748CC12A197444C95B72928DB6A4B321E8193CC12EAB3B9BE0FD590C958552E19F643350B3936A504FDB2BF1DACA899AF2B48250EC1BD1C1BE8897B976385115A37CD41C3D01F02256F6B38ECA919774518CBC50B0AA1EA3FC23B6ECD2F0743E00417D60CBB0AE58EF043627BF77CCF6EB5F351C23032CD5736C2FBD325C1AD96BF1F19177B1499854D7
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1BCB152E-00F5-17FC-ECC3-B84110A75B58}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1BCB152E-00F5-17FC-ECC3-B84110A75B58}@oalkbjgccjpjicbobncekkjgadjllp 0x6A 0x61 0x70 0x64 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1BCB152E-00F5-17FC-ECC3-B84110A75B58}@nablldnnhgnibjndhjbdpmobcifo 0x6A 0x61 0x70 0x64 ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
---- EOF - GMER 1.0.15 ----
Two days ago, Internet Explorer crashed and the error was this:
AppName: iexplore.exe AppVer: 6.0.2800.1106 ModName: mshtml.dll ModVer: 6.0.2800.1561 Offset: 00185c12
I ran avast! free anti-virus v5.0.677.
It discovered a trojan which I had avast! remove:
C:\program files\unlocker\ebay-shortcuts_1016.exe
Now I have problems with Internet Explorer and windows explorer.
I have run DDS and GMER.
GMER said it found evidence of possible rootkit activity.
Below is my DDS.txt and GMER log. I also attached the zipped attach.txt.
Thank you for any help you may give me.
**********************************************
DDS (Ver_10-12-12.02) - NTFSx86
Run by Lord at 1:41:35.35 on Tue 01/25/2011
Internet Explorer: 6.0.2800.1106 BrowserJavaVersion: 1.6.0_17
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.510.111 [GMT -8:00]
============== Running Processes ===============
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\ge security supra\syncservice.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\GE Security Supra\ProxyDaemon.exe
C:\SSL\stunnel-4.10.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\System32\dmadmin.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\CAPM1RSK.EXE
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Maxtor\OneTouch\utils\mspm.exe
C:\PROGRA~1\RETROS~1\RETROS~1.1\RetroExpress.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\system32\spool\drivers\w32x86\3\CAPM1LAK.EXE
C:\WINNT\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE
C:\Program Files\GE Security Supra\SyncInfoApp.exe
C:\Program Files\Microsoft Office 2000\Office\1033\MSOFFICE.EXE
C:\WINNT\system32\TASKMGR.EXE
C:\PROGRA~1\RETROS~1\RETROS~1.1\retrorun.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\Microsoft Office 2000\Office\EXCEL.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Adobe\Acrobat 7.0 Professional\Acrobat\Acrobat.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINNT\system32\msiexec.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - f:\program files\orbitdownloader\orbitcth.dll
BHO: BHO Class: {8b3868b4-eba8-48fa-a19b-e1dfb99066fa} - f:\program files\flashcapture\fcbho.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll
TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - f:\program files\orbitdownloader\GrabPro.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [NeroFilterCheck] c:\winnt\system32\NeroCheck.exe
mRun: [MaxtorOneTouch] c:\program files\maxtor\onetouch\utils\Onetouch.exe
mRun: [mspm] c:\program files\maxtor\onetouch\utils\mspm.exe
mRun: [RetroExpress] c:\progra~1\retros~1\retros~1.1\RetroExpress.exe /h
mRun: [Dit] Dit.exe
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office 2000\office\1033\MSOFFICE.EXE
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\MYNETW~1.LNK -
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\taskmg~1.lnk - c:\winnt\system32\TASKMGR.EXE
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\autoru~1\teatimer.lnk - c:\program files\spybot - search & destroy\TeaTimer.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\canonp~1.lnk - c:\winnt\system32\spool\drivers\w32x86\3\CAPM1LAK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\displa~1.lnk - c:\program files\ge security supra\SyncInfoApp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\scansn~1.lnk - c:\program files\pfu\scansnap\driver\PfuSsMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\adobea~1.lnk - c:\winnt\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\micros~1.lnk - c:\program files\microsoft office 2000\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\scansn~1.lnk - f:\program files\pfu\scansnap\driver\PfuSsMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
uPolicies-system: RunStartupScriptSync = 1 (0x1)
mPolicies-system: RunStartupScriptSync = 1 (0x1)
IE: &Download by Orbit - f:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - f:\program files\orbitdownloader\orbitmxt.dll/204
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0 professional\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Do&wnload selected by Orbit - f:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - f:\program files\orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Save F&lash with FlashCapture - f:\program files\flashcapture\fciext.dll/FCIEXT.htm
IE: {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - res://f:\program files\flashcapture\fciext.dll/FCIEXT.htm
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {41564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: NavLogon - c:\winnt\system32\NavLogon.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\b5wt98kq.default\
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\winnt\system32\drivers\Lbd.sys [2009-4-18 64160]
R0 ROFF;ROFF;c:\winnt\system32\drivers\roff.sys [2003-6-9 42455]
R1 aswSP;aswSP;c:\winnt\system32\drivers\aswSP.sys [2010-9-29 165584]
R1 bbcap;bbcap;c:\winnt\system32\drivers\bbcap.sys [2009-7-18 2432]
R2 aswFsBlk;aswFsBlk;c:\winnt\system32\drivers\aswFsBlk.sys [2010-9-29 17744]
R2 aswMon;aswMon;c:\winnt\system32\drivers\aswmon.sys [2010-9-29 94544]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-29 40384]
R2 RapidPortM1;RapidPortM1;c:\winnt\system32\drivers\CAPM1LP.SYS [2006-4-19 22912]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-29 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-29 40384]
R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;c:\winnt\system32\drivers\el90xbc5.sys [2006-3-16 61712]
R4 NAVAPEL;NAVAPEL;\??\c:\program files\navnt\navapel.sys --> c:\program files\navnt\NAVAPEL.SYS [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456]
S3 MV;MV;c:\docume~1\admini~1\locals~1\temp\mv.exe --> c:\docume~1\admini~1\locals~1\temp\MV.exe [?]
S3 pgusbmme;usb-audio.de MME-Adapter;c:\winnt\system32\drivers\pgusbmm3.sys [2005-7-19 23520]
S3 pgusbwdm;usb-audio.de driver (commercial V2.6.1);c:\winnt\system32\drivers\pgusbwdm.sys [2005-7-19 99200]
S3 SQLAgent$RETSDATA;SQLAgent$RETSDATA;c:\program files\microsoft sql server\mssql$retsdata\binn\sqlagent.exe -i retsdata --> c:\program files\microsoft sql server\mssql$retsdata\binn\sqlagent.EXE -i RETSDATA [?]
S4 MSSQL$RETSDATA;MSSQL$RETSDATA;c:\program files\microsoft sql server\mssql$retsdata\binn\sqlservr.exe -sretsdata --> c:\program files\microsoft sql server\mssql$retsdata\binn\sqlservr.exe -sRETSDATA [?]
=============== Created Last 30 ================
2011-01-25 07:56:15 -------- d-s---w- c:\documents and settings\administrator\UserData
2011-01-20 06:46:15 21872 -c--a-w- c:\winnt\system32\dllcache\usbprint.sys
2011-01-20 06:46:15 21872 ----a-w- c:\winnt\system32\drivers\usbprint.sys
==================== Find3M ====================
2010-12-22 00:07:04 1409 ----a-w- c:\winnt\QTFont.for
2005-05-14 00:12:00 217073 --sha-r- c:\winnt\meta4.exe
2005-10-24 18:13:58 66560 --sha-r- c:\winnt\MOTA113.exe
2005-10-14 04:27:00 422400 --sha-r- c:\winnt\x2.64.exe
2005-10-08 02:14:52 308224 --sha-r- c:\winnt\system32\avisynth.dll
2005-07-14 19:31:20 27648 --sha-r- c:\winnt\system32\AVSredirect.dll
2005-06-22 05:37:42 45568 --sha-r- c:\winnt\system32\cygz.dll
2004-01-25 07:00:00 70656 --sha-r- c:\winnt\system32\i420vfw.dll
2006-04-27 17:24:24 2945024 --sha-r- c:\winnt\system32\Smab.dll
2005-02-28 20:16:22 240128 --sha-r- c:\winnt\system32\x.264.exe
2004-01-25 07:00:00 70656 --sha-r- c:\winnt\system32\yv12vfw.dll
============= FINISH: 1:43:01.26 ===============
****************************************
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-25 02:25:51
Windows 5.0.2195 Service Pack 4 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-2 WDC_WD200BB-75CAA0 rev.16.06V16
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\agtdrpow.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwClose [0xBB3724B3]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwCreateKey [0xBB3723B3]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwDeleteKey [0xBB372502]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwDeleteValueKey [0xBB372596]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwDuplicateObject [0xBBAC3782]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwFlushKey [0xBB3727DE]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwOpenKey [0xBB3722E8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenProcess [0xBBAC36C2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwOpenThread [0xBBAC3726]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwQueryValueKey [0xBBAC3DA6]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRestoreKey [0xBBAC3D66]
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS ZwSetValueKey [0xBB3726A5]
---- Kernel code sections - GMER 1.0.15 ----
? C:\Program Files\NavNT\NAVAPEL.SYS The system cannot find the file specified. !
? C:\Program Files\Symantec\SYMEVENT.SYS The system cannot find the file specified. !
? C:\WINNT\system32\Drivers\PROCEXP100.SYS The system cannot find the file specified. !
? C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINNT\explorer.exe[2208] SHELL32.dll!SHFileOperationW 7CF800F5 5 Bytes JMP 10001102 C:\Program Files\Unlocker\UnlockerHook.dll
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
Device ftdisk.sys (FT Disk Driver/Microsoft Corporation)
AttachedDevice ROFF.sys (Retrospect Open File Filter/Dantz Development Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device Fs_Rec.SYS (File System Recognizer Driver/Microsoft Corporation)
---- Processes - GMER 1.0.15 ----
Library C:\Program (*** hidden *** ) @ C:\Program Files\Microsoft Office\Office10\WINWORD.EXE [2400] 0x049F0000
Library C:\Program (*** hidden *** ) @ C:\Program Files\Microsoft Office\Office10\WINWORD.EXE [2400] 0x04A90000
Library C:\Program (*** hidden *** ) @ C:\Program Files\Microsoft Office\Office10\WINWORD.EXE [2400] 0x05090000
Library C:\Program (*** hidden *** ) @ C:\Program Files\Microsoft Office\Office10\WINWORD.EXE [2400] 0x050A0000
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG04.00.00.01SERVER 3A2078B92014A5B4CADFF5E4B7F422A58EEEDB1A75EEBEB580A4C89D2C1C7B102ABC78ECDD962013CBE59E26EB70DFEA8E1E535552F60B784DDE0B7577C557886B98235F8CAD29DF3A807D727AE87D1070ADA394609DD72130848D07A034498C1DF16003817AFD8006F9D0AC5C9AE2FD94948753D8DCD53E9AD922003F3E6DEC667A39D65451C22C26917A4C48F8DBF26440D89BB66599B307183D20B0703ED16ED75AF3633BFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933BA7FD869164D67945D575E7D6A3B9808C038D530D6EB34522E68364DE22E87730B9ED2B760021749823AAEE139CA461B0CDC565E83538613A3279FF9798CAA47CB38BCF643AC09E22170E39BD19DA0947B8F090C49435E58A0189DF6FB07E9880A0A6D9571B98546B0EA04718844F726F5A0200A982A924192153C38355438FA1B33A4F0EFB87F3210AE20CE3AC4E2AE8398A0EF49A1F86748CC12A197444C95B72928DB6A4B321E8193CC12EAB3B9BE0FD590C958552E19F643350B3936A504FDB2BF1DACA899AF2B48250EC1BD1C1BE8897B976385115A37CD41C3D01F02256F6B38ECA919774518CBC50B0AA1EA3FC23B6ECD2F0743E00417D60CBB0AE58EF043627BF77CCF6EB5F351C23032CD5736C2FBD325C1AD96BF1F19177B1499854D7
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1BCB152E-00F5-17FC-ECC3-B84110A75B58}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1BCB152E-00F5-17FC-ECC3-B84110A75B58}@oalkbjgccjpjicbobncekkjgadjllp 0x6A 0x61 0x70 0x64 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1BCB152E-00F5-17FC-ECC3-B84110A75B58}@nablldnnhgnibjndhjbdpmobcifo 0x6A 0x61 0x70 0x64 ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
---- EOF - GMER 1.0.15 ----