Hello,
Thanks for helping.
GMER log shown below -
I couldn't get DDS to run. CMD prompt flashes open for a second then disappears. New process called etPaths.exe is created but nothing else seems to happen.
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-03-06 13:14:30
Windows 6.0.6001 Service Pack 1
Running: lj4qsl2t.exe; Driver: C:\Users\SufIslam\AppData\Local\Temp\kflcquow.sys
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [8069A61A] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80699AD0] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [8069A744] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [80699B98] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [80699C16] \SystemRoot\System32\Drivers\sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806AF57E] \SystemRoot\System32\Drivers\sptd.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Internet Explorer\iexplore.exe[856] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\9675B89D.x86.dll
IAT C:\Program Files\Internet Explorer\iexplore.exe[856] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\9675B89D.x86.dll
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74AD7BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74B198C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [74ADD3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [74ACF527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74AD7599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74ACE43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74B0B33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [74ADD68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [74AD012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74AD0095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74AC71F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [74B5D802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [74AF75E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74ACDAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74AC668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74AC66BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1456] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74AD1E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2ec9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 86F031E8
AttachedDevice \FileSystem\Ntfs \Ntfs symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\volmgr \Device\VolMgrControl 86F001E8
Device \Driver\usbuhci \Device\USBPDO-0 8720C790
Device \Driver\usbuhci \Device\USBPDO-1 8720C790
Device \Driver\usbuhci \Device\USBPDO-2 8720C790
Device \Driver\usbuhci \Device\USBPDO-3 8720C790
Device \Driver\netbt \Device\NetBT_Tcpip_{6E3E763B-A776-4383-9FF1-83CC5DA71273} 89D75790
Device \Driver\usbehci \Device\USBPDO-4 87142790
Device \Driver\volmgr \Device\HarddiskVolume1 86F001E8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
Device \Driver\volmgr \Device\HarddiskVolume2 86F001E8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
Device \Driver\cdrom \Device\CdRom0 8725E1E8
Device \Driver\volmgr \Device\HarddiskVolume3 86F001E8
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 86F021E8
Device \Driver\atapi \Device\Ide\IdePort0 86F021E8
Device \Driver\atapi \Device\Ide\IdePort1 86F021E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-2 86F021E8
Device \Driver\netbt \Device\NetBt_Wins_Export 89D75790
Device \Driver\iScsiPrt \Device\RaidPort0 87265790
Device \Driver\usbuhci \Device\USBFDO-0 8720C790
Device \Driver\usbuhci \Device\USBFDO-1 8720C790
Device \Driver\usbuhci \Device\USBFDO-2 8720C790
Device \Driver\usbuhci \Device\USBFDO-3 8720C790
Device \Driver\usbehci \Device\USBFDO-4 87142790
Device \FileSystem\fastfat \Fat 8B5E51E8
Device \FileSystem\fastfat \Fat 9E29245E
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\Device\__max++>\9675B89D.x86.dll (*** hidden *** ) @ C:\Windows\system32\wininit.exe [576] 0x35670000
Library \\?\globalroot\Device\__max++>\9675B89D.x86.dll (*** hidden *** ) @ C:\Windows\system32\services.exe [652] 0x35670000
Library \\?\globalroot\Device\__max++>\9675B89D.x86.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\iexplore.exe [856] 0x35670000
Library \\?\globalroot\Device\__max++>\9675B89D.x86.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [872] 0x35670000
Library \\?\globalroot\Device\__max++>\9675B89D.x86.dll (*** hidden *** ) @ C:\Windows\System32\svchost.exe [1000] 0x35670000
Library \\?\globalroot\Device\__max++>\9675B89D.x86.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1068] 0x35670000
---- EOF - GMER 1.0.15 ----