Page 1 of 4 1234 LastLast
Results 1 to 10 of 34

Thread: Computer sending tons of spam behind the scenes

  1. #1
    Junior Member
    Join Date
    Sep 2007
    Posts
    28

    Default Computer sending tons of spam behind the scenes

    Hi I have been having trouble with my computer over this past summer. My personal email was blocked by spamcop about 3 times in the past few months (for about 24 hours) and currently I am blocked for a few days now.

    I have 2 computers on my network and I monitered the SMTP ports on both. One generated no log entries unless I sent mail manually, the other one (my computer) had a constant flow of SMTP activity, many of which noted random email addresses. I think its clear to see that my computer is the one with the issue here.


    I did a scan with spybot and nothing came up. I believe this issue is the only problem I have.



    Here is my report...

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:10:17 AM, on 9/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    X:\servers\xampp\apache\bin\apache.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\gearsec.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    X:\servers\xampp\mysql\bin\mysqld-nt.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\tcpsvcs.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
    X:\servers\xampp\apache\bin\apache.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Acronis\TrueImageEnterpriseServer\TrueImageMonitor.exe
    C:\Program Files\Acronis\TrueImageEnterpriseServer\TimounterMonitor.exe
    C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
    C:\WINDOWS\system32\nvraidservice.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
    C:\Program Files\TopDesk\topdesk.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
    C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {94C78B7B-AABB-4126-8036-2E1FF466C2D1} - C:\WINDOWS\system32\ddcca.dll (file missing)
    O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
    O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageEnterpriseServer\TrueImageMonitor.exe
    O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageEnterpriseServer\TimounterMonitor.exe
    O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
    O4 - HKLM\..\Run: [TopDesk] C:\Program Files\TopDesk\topdesk.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - .DEFAULT User Startup: CamTrack.lnk = C:\Program Files\DigitalPeers\CamTrack\camtrack.exe (User 'Default user')
    O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Shortcut to SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O4 - Global Startup: Yahoo! Widget Engine.lnk.disabled
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/.../GAME_UNO1.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1172507809890
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor...fo/webscan.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab57213.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5E9C637C-0A68-4E49-835E-95B60DEAEA59}: NameServer = 64.71.255.198
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C9F5821E-FF54-4F20-8018-2A2C8E54E5B2}: NameServer = 64.71.255.198
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O20 - Winlogon Notify: wingdm32 - wingdm32.dll (file missing)
    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apache2 - Apache Software Foundation - X:\servers\xampp\apache\bin\apache.exe
    O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: mysql - Unknown owner - X:\servers\xampp\mysql\bin\mysqld-nt.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

    --
    End of file - 11250 bytes

  2. #2
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hello and welcome to the forums

    You got infections there...
    We'll do some research...

    Please run a GMER Rootkit scan:

    Download GMER's application from here:
    http://www.gmer.net/gmer.zip

    Unzip it and start the GMER.exe
    Click the Rootkit tab and click the Scan button.

    Once done, click the Copy button.
    This will copy the results to your clipboard.
    Paste the results in your next reply.

    Warning ! Please, do not select the "Show all" checkbox during the scan.
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  3. #3
    Junior Member
    Join Date
    Sep 2007
    Posts
    28

    Default

    I tried to run the scan 4 times

    the first 2 times my computer restarted itself

    the 3rd time I only chose to scan my c drive (have 3 other drives) and it retarted

    4th time i went into safemode and tried to scan and it restarted. however as it scanned i copied the results and saved them in notepad every few seconds.

    this is what i was able to save before it restarted for the 4th time...


    GMER 1.0.13.12551 - http://www.gmer.net
    Rootkit scan 2007-09-12 16:40:06
    Windows 5.1.2600 Service Pack 2


    ---- System - GMER 1.0.13 ----

    SSDT \??\C:\WINDOWS\system32\xpdx.sys ZwCreateKey
    SSDT \??\C:\WINDOWS\system32\xpdx.sys ZwOpenKey
    SSDT \??\C:\WINDOWS\system32\xpdx.sys ZwTerminateProcess

    ---- Kernel code sections - GMER 1.0.13 ----

    ? C:\WINDOWS\system32\xpdx.sys The system cannot find the file specified.

    ---- Devices - GMER 1.0.13 ----

    Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F7825FB1] xpdx.sys

    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F7AF7A96] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F7AF7958] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F7AF7DA8] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F7AF7306] SiWinAcc.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE_NAMED_PIPE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLOSE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_QUERY_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SET_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_QUERY_EA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SET_EA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_QUERY_VOLUME_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SET_VOLUME_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DIRECTORY_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FILE_SYSTEM_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_LOCK_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE_MAILSLOT [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_QUERY_SECURITY [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SET_SECURITY [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CHANGE

  4. #4
    Junior Member
    Join Date
    Sep 2007
    Posts
    28

    Default

    [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_QUERY_QUOTA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SET_QUOTA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE_NAMED_PIPE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLOSE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_QUERY_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SET_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_QUERY_EA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SET_EA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_QUERY_VOLUME_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SET_VOLUME_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DIRECTORY_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FILE_SYSTEM_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_LOCK_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE_MAILSLOT [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_QUERY_SECURITY [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SET_SECURITY [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CHANGE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_QUERY_QUOTA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SET_QUOTA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE_NAMED_PIPE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLOSE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_QUERY_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SET_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_QUERY_EA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SET_EA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_QUERY_VOLUME_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SET_VOLUME_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DIRECTORY_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FILE_SYSTEM_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_LOCK_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE_MAILSLOT [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_QUERY_SECURITY [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SET_SECURITY [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CHANGE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_QUERY_QUOTA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SET_QUOTA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE_NAMED_PIPE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLOSE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_QUERY_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SET_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_QUERY_EA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SET_EA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_QUERY_VOLUME_INFORMATION

  5. #5
    Junior Member
    Join Date
    Sep 2007
    Posts
    28

    Default

    [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SET_VOLUME_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DIRECTORY_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FILE_SYSTEM_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_LOCK_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE_MAILSLOT [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_QUERY_SECURITY [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SET_SECURITY [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CHANGE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_QUERY_QUOTA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SET_QUOTA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE_NAMED_PIPE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLOSE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_QUERY_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SET_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_QUERY_EA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SET_EA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_QUERY_VOLUME_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SET_VOLUME_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DIRECTORY_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FILE_SYSTEM_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_LOCK_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE_MAILSLOT [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_QUERY_SECURITY [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SET_SECURITY [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER
    [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CHANGE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_QUERY_QUOTA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SET_QUOTA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE_NAMED_PIPE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLOSE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_QUERY_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SET_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_QUERY_EA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SET_EA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_QUERY_VOLUME_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SET_VOLUME_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DIRECTORY_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FILE_SYSTEM_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_LOCK_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE_MAILSLOT [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_QUERY_SECURITY [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SET_SECURITY [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CHANGE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_QUERY_QUOTA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SET_QUOTA

  6. #6
    Junior Member
    Join Date
    Sep 2007
    Posts
    28

    Default

    [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE_NAMED_PIPE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CLOSE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_READ [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_WRITE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_QUERY_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SET_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_QUERY_EA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SET_EA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_FLUSH_BUFFERS [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_QUERY_VOLUME_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SET_VOLUME_INFORMATION [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_DIRECTORY_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_FILE_SYSTEM_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_DEVICE_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_INTERNAL_DEVICE_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SHUTDOWN [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_LOCK_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CLEANUP [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE_MAILSLOT [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_QUERY_SECURITY [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SET_SECURITY [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_POWER [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SYSTEM_CONTROL [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_DEVICE_CHANGE [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_QUERY_QUOTA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SET_QUOTA [F742D380] snapman.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE_NAMED_PIPE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CLOSE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_READ [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_WRITE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_QUERY_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SET_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_QUERY_EA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SET_EA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_FLUSH_BUFFERS [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_QUERY_VOLUME_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SET_VOLUME_INFORMATION [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_DIRECTORY_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_FILE_SYSTEM_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_DEVICE_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_INTERNAL_DEVICE_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SHUTDOWN [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_LOCK_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CLEANUP [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE_MAILSLOT [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_QUERY_SECURITY [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SET_SECURITY [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_POWER [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SYSTEM_CONTROL [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_DEVICE_CHANGE [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_QUERY_QUOTA [F744C760] timntr.sys
    AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SET_QUOTA [F744C760] timntr.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [F7AF7A96] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [F7AF7958] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [F7AF7DA8] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [F7AF7306] SiWinAcc.sys
    AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [F7AF7306] SiWinAcc.sys

  7. #7
    Junior Member
    Join Date
    Sep 2007
    Posts
    28

    Default

    ---- Registry - GMER 1.0.13 ----

    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{18D6E519-4C27-E4AD-074C5D1F171B40FB}\{8D7A772B-93EE-6905-4C751BA1B544AFC9}\{7029C73E-0020-BA9C-F3FADF03D99AF0E6}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{AB53ABC9-60C7-8B2C-A2AB126EB1F03A59}\{6511FF0A-0202-CA71-9BBA47A5377501DE}\{CE12CB05-B8C7-0E6B-6DC342F04A20B600}@1D1OWFM6WKF6TLM3S2BGKKUUDG1 0x01 0x00 0x01 0x00 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{B3A3A58F-967E-A40A-C7DDFB524B0CDFB3}\{B28E8422-363F-1C4B-CC056478281B7FCE}\{569EFB20-10B3-C9F5-895B6A19B8852344}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version@Version 0x31 0x98 0xED 0xA2 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{C9E2B393-56C9-49A0-E9536816E76F722D}\{C3EAC204-1FBE-55E0-B9FAECEF4AC48E44}\{36C3AF1D-C1DF-E2E1-C86849C42C7FDBDC}@1D1OWFM6WKF6TLM3S2BGKKUUDG1 0x01 0x00 0x01 0x00 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{CD33F05B-57D8-EB8D-1C637C8E18479BDE}\{4B66B287-DF55-8BF6-0C7A245C073DF874}\{2B094E66-D192-13E4-CB3BD0799FCAC2FC}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{DCB42C02-2C7E-50EC-E2B5A792F7765BFB}\{38286259-1A12-EDE0-84E2CD6A1D76E8F7}\{2C2658AF-F73E-73C6-89D45D0D6FCCCFF2}@1D1OWFM6WKF6TLM3S2BGKKUUDG1 0x01 0x00 0x01 0x00 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{EEC79885-4786-49D7-ED36B6E7637E50FF}\{25B171C9-78C7-18E7-FBBA7E6592C7CB70}\{6B8ADD0A-85A7-C5B5-191A2895BD30C6E1}@1D1OWFM6WKF6TLM3S2BGKKUUDG1 0x01 0x00 0x01 0x00 ...
    Reg \Registry\MACHINE\SOFTWARE\Classes\CLSID\{FE8DBE89-D247-CDA0-331071706D351D5D}\{D7E03019-A44C-9829-6C33C3798CE56E87}\{A96D9761-82B1-07BB-8B5956B67D5931EC}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 ...


    the forum restricted how many characters i can post (as i'm sure you know)

  8. #8
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hello

    Ok the scan revealed that you have a rootkit infection there. This is sending all the spam...

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  9. #9
    Junior Member
    Join Date
    Sep 2007
    Posts
    28

    Default

    ComboFix 07-09-13.3 - "Edward J" 2007-09-13 21:09:50.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.199 [GMT -3:00]
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\system32\xpdx.sys
    E:\Autorun.inf

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


    -------\LEGACY_CORE
    -------\LEGACY_IPRIP
    -------\LEGACY_NTMLSVC
    -------\Iprip
    -------\NtmlSvc
    -------\xpdx


    ((((((((((((((((((((((((( Files Created from 2007-08-14 to 2007-09-14 )))))))))))))))))))))))))))))))
    .

    2007-09-13 21:09 51,200 --a------ C:\WINDOWS\NirCmd.exe
    2007-09-13 01:41 <DIR> d-------- C:\WINDOWS\system32\NtmsData
    2007-09-13 00:30 <DIR> d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\gtk-2.0
    2007-09-10 10:53 <DIR> d-------- C:\Program Files\Trend Micro
    2007-09-10 10:41 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
    2007-09-10 10:41 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
    2007-09-10 10:40 <DIR> d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\Ethereal
    2007-09-10 09:56 <DIR> d-------- C:\Program Files\WinPcap
    2007-09-10 09:56 <DIR> d-------- C:\Program Files\Ethereal
    2007-09-10 09:50 <DIR> d-------- C:\Program Files\Microsoft Network Monitor 3
    2007-09-08 20:43 <DIR> d-------- C:\Program Files\EA SPORTS
    2007-09-05 01:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\pixelStorm
    2007-09-04 23:03 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
    2007-09-04 23:03 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
    2007-09-04 23:03 129,784 --------- C:\WINDOWS\system32\pxafs.dll
    2007-09-04 09:32 <DIR> d-------- C:\Program Files\Motorola
    2007-08-27 16:18 7,552 --a--c--- C:\WINDOWS\system32\dllcache\sonypvu1.sys
    2007-08-27 16:18 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
    2007-08-17 00:06 <DIR> d-------- C:\Program Files\Winamp
    2007-08-16 23:44 <DIR> d-------- C:\Program Files\SHOUTcast

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-09-13 21:20 0 --a------ C:\WINDOWS\system32\drivers\lvuvc.hs
    2007-09-04 09:35 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
    2007-09-04 09:35 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
    2007-08-26 22:47 --------- d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\Ahead
    2007-08-17 12:31 --------- d-------- C:\Program Files\Soulseek
    2007-08-12 17:27 --------- d-------- C:\Program Files\GML
    2007-08-09 11:19 --------- d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\Canon
    2007-08-09 11:06 --------- d--h----- C:\Program Files\InstallShield Installation Information
    2007-08-09 11:06 --------- d-------- C:\Program Files\Canon
    2007-08-09 11:03 --------- d-------- C:\Program Files\Common Files\ScanSoft Shared
    2007-08-09 11:03 --------- d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\ScanSoft
    2007-08-09 11:03 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanWizard
    2007-08-09 11:03 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SSScanAppDataDir
    2007-08-09 11:02 --------- d-------- C:\Program Files\ScanSoft
    2007-08-07 01:57 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
    2007-08-07 01:56 --------- d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\Ulead Systems
    2007-08-07 01:11 1731172 ---hs---- C:\WINDOWS\system32\yccdd.bak1
    2007-08-07 00:07 164787 --a------ C:\WINDOWS\system32\drivers\core.cache(2).dsk
    2007-08-05 16:17 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
    2007-08-05 16:14 --------- d-------- C:\Program Files\Common Files\Ulead Systems
    2007-08-02 12:19 --------- d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\U3
    2007-08-01 01:06 --------- d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\uTorrent
    2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
    2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
    2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
    2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
    2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
    2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
    2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
    2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
    2007-07-30 09:31 --------- d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\Paltalk
    2007-07-30 01:38 --------- d-------- C:\Program Files\Paltalk Messenger
    2007-07-28 20:36 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
    2007-07-24 11:39 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
    2007-07-23 02:58 --------- d-------- C:\Program Files\VirtualDJ
    2007-07-23 01:53 --------- d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\MySQL
    2007-07-22 23:43 --------- d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\Nero
    2007-07-21 10:38 --------- d-------- C:\Program Files\The Rosetta Stone
    2007-07-21 10:00 --------- d-------- C:\Program Files\Bonjour
    2007-07-21 09:49 --------- d-------- C:\Program Files\Common Files\Macrovision Shared
    2007-07-17 09:54 --------- d-------- C:\DOCUME~1\EDWARD~1\APPLIC~1\Thunderbird
    2007-06-27 11:34 823808 --a------ C:\WINDOWS\system32\wininet(2)(2).dll
    2007-06-27 11:34 267776 --a------ C:\WINDOWS\system32\iertutil(2)(2).dll
    2007-06-27 11:34 1152000 --a------ C:\WINDOWS\system32\urlmon(2)(2).dll
    2007-06-27 11:34 105984 --a------ C:\WINDOWS\system32\url(2)(2).dll
    2007-06-26 03:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
    2007-06-19 10:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
    2007-06-19 10:31 282112 --a------ C:\WINDOWS\system32\gdi32(2)(2).dll
    2007-06-13 07:23 1033216 --a------ C:\WINDOWS\explorer.exe
    2007-02-01 20:05 6176 --a------ C:\Program Files\uninstal.log
    2006-05-03 10:06:54 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
    2007-02-21 11:47:16 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .

    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94C78B7B-AABB-4126-8036-2E1FF466C2D1}]
    C:\WINDOWS\system32\ddcca.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 17:49]
    "TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageEnterpriseServer\TrueImageMonitor.exe" [2006-06-20 13:01]
    "AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageEnterpriseServer\TimounterMonitor.exe" [2006-06-20 13:02]
    "Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-06-20 13:01]
    "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 15:46 C:\WINDOWS\KHALMNPR.Exe]
    "NVRaidService"="C:\WINDOWS\system32\nvraidservice.exe" [2006-06-01 08:09]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-17 17:27]
    "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2006-12-22 13:27]
    "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2006-12-22 13:28]
    "TopDesk"="C:\Program Files\TopDesk\topdesk.exe" [2006-03-01 14:03]
    "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22]
    "nwiz"="nwiz.exe" [2006-10-22 13:22 C:\WINDOWS\system32\nwiz.exe]
    "Omnipage"="C:\Program Files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 11:38]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]
    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:54]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 09:00]

    C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
    Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 21:16:50]
    Shortcut to SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-02-02 04:47:10]
    Yahoo! Widget Engine.lnk.disabled [2007-02-27 05:06:06]

    C:\DOCUME~1\ADMINI~1\STARTM~1\Programs\Startup\
    CamTrack.lnk - C:\Program Files\DigitalPeers\CamTrack\camtrack.exe [2007-06-27 20:38:51]

    C:\DOCUME~1\DEFAUL~1\STARTM~1\Programs\Startup\
    CamTrack.lnk - C:\Program Files\DigitalPeers\CamTrack\camtrack.exe [2007-06-27 20:38:51]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoTrayItemsDisplay"=00000000

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wingdm32]
    wingdm32.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"= msv1_0 relog_ap

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "ResChanger 2005"=C:\Program Files\ResChanger 2005\ResChanger2005.exe
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    "NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    "nwiz"=nwiz.exe /install
    "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    "SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    "H2O"=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
    "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    "DeltTray"=DeltTray.exe
    "CoolSwitch"=C:\WINDOWS\system32\taskswitch.exe
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

    R0 SI3132;SiI-3132 SATALink Controller;C:\WINDOWS\system32\DRIVERS\SI3132.sys
    R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
    R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
    R2 gearsec;gearsec;C:\WINDOWS\system32\gearsec.exe
    R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe
    R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
    R3 ADIDTSFiltService;ADI DTS Filter Service;C:\WINDOWS\system32\drivers\adidts.sys
    R3 AmdLLD;AMD Low Level Device Driver;C:\WINDOWS\system32\DRIVERS\AmdLLD.sys
    R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys
    R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys
    S3 m4cxw2k3;NDIS5.1 Miniport Driver for D-Link PCI Express Ethernet Controller;C:\WINDOWS\system32\DRIVERS\m4cxw2k3.sys
    S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys
    S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys
    S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys
    S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys
    S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
    S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe -k p2psvc
    S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe -k p2psvc
    S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe -k p2psvc
    S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe -k p2psvc

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{14ee84a6-4041-11dc-8241-0015af0890ae}]
    AutoRun\command- I:\LaunchU3.exe -a

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{14ee84a7-4041-11dc-8241-0015af0890ae}]
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
    Open(0)\command- J:\Recycled\ctfmon.exe

    .
    Contents of the 'Scheduled Tasks' folder
    "2007-09-12 11:04:59 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
    - C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    .
    **************************************************************************

    catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-09-13 21:22:12
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-09-13 21:25:00 - machine was rebooted
    C:\ComboFix-quarantined-files.txt ... 2007-09-13 21:24
    .
    --- E O F ---

  10. #10
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hi we'll continue

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    File::
    C:\WINDOWS\system32\yccdd.bak1
    C:\WINDOWS\system32\drivers\core.cache(2).dsk
    C:\WINDOWS\system32\ddcca.dll
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94C78B7B-AABB-4126-8036-2E1FF466C2D1}]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wingdm32]
    Save this as "CFScript"



    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •