Hi and thanks!
OS: XP Home SP3
IE7 and Firefox is the default browser
Here is ARK.txt
GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-06-25 05:38:52
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
ZwCreateKey [0xF8575C8E]
Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
ZwEnumerateKey [0xF8575D13]
Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
ZwOpenKey [0xF8575C10]
Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
ZwQueryDirectoryFile
[0xF8575999]
Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
IoCreateFile
Code 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
NtQueryDirectoryFile
---- Kernel code sections - GMER 1.0.15 ----
PAGE ntoskrnl.exe!ZwOpenKey
80568D59 3 Bytes JMP
F8575C14 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
PAGE ntoskrnl.exe!ZwOpenKey + 4
80568D5D 1 Byte [78]
PAGE ntoskrnl.exe!IoCreateFile
8056CC6B 5 Bytes JMP
F8575872 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
PAGE ntoskrnl.exe!ZwCreateKey
8057065D 3 Bytes JMP
F8575C92 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
PAGE ntoskrnl.exe!ZwCreateKey + 4
80570661 1 Byte [78]
PAGE ntoskrnl.exe!ZwEnumerateKey
80570D64 7 Bytes JMP
F8575D17 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
PAGE ntoskrnl.exe!NtQueryDirectoryFile
80572111 5 Bytes JMP
F857599D 4b63c2aff10254dae185d1bbe7c1a4a5.sys (ckmd/Noves Inc)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\AIM6\aim6.exe[1628] @
C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW]
[6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @
C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter]
[6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @
C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW]
[6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @
C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA]
[6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\RPCRT4.dll
[KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\RPCRT4.dll
[KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\RPCRT4.dll
[KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\Secur32.dll
[KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\Secur32.dll
[KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\Secur32.dll
[KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\MSVCRT.dll
[KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\MSVCRT.dll
[KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\USER32.dll
[KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\USER32.dll
[KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\USER32.dll
[KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\USER32.dll
[KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\GDI32.dll
[KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\GDI32.dll
[KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\GDI32.dll
[KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\GDI32.dll
[KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ole32.dll
[KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ole32.dll
[KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ole32.dll
[KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ole32.dll
[KERNEL32.dll!LoadLibraryExA] [6BFA9D54] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\ole32.dll
[KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\SHLWAPI.dll
[KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9E6E] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\SHLWAPI.dll
[KERNEL32.dll!LoadLibraryExA] [6BFA9D54] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\SHLWAPI.dll
[KERNEL32.dll!LoadLibraryExW] [6BFA9DE1] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\SHLWAPI.dll
[KERNEL32.dll!LoadLibraryW] [6BFA9CCD] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aim6.exe[1628] @ C:\WINDOWS\system32\SHLWAPI.dll
[KERNEL32.dll!LoadLibraryA] [6BFA9C46] C:\Program
Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW]
[6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter]
[6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW]
[6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA]
[6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA]
[6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW]
[6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter]
[6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter]
[6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA]
[6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW]
[6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!SetUnhandledExceptionFilter]
[6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!LoadLibraryA]
[6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]
[6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA]
[6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter]
[6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]
[6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter]
[6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]
[6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]
[6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]
[6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]
[6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]
[6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]
[6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA]
[6BFA9D54] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter]
[6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter]
[6BFA9E6E] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA]
[6BFA9D54] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]
[6BFA9DE1] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]
[6BFA9CCD] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
IAT C:\Program Files\AIM6\aolsoftware.exe[1972] @
C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]
[6BFA9C46] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL
Diagnostics/AOL LLC)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\099f7efc868878f48d536500a0e0000d.sys (*** hidden
*** ) [BOOT]
099f7efc868878f48d536500a0e0000d
<-- ROOTKIT !!!
Service C:\WINDOWS\system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys (*** hidden
*** ) [BOOT]
4b63c2aff10254dae185d1bbe7c1a4a5
<-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@c
®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\099f7efc868878f4
8d536500a0e0000d&download_period=846000&first_download_delay=180&version=2&ip_0
=586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&i
p_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails
_3=2&ips_count=4&name=099f7efc868878f48d536500a0e0000d&path=system32\099f7efc86
8878f48d536500a0e0000d.sys&wmid=Dnr001&idate=2009-02-21
12:18:44:953&last_download_time=2009-6-20
16:23:18.0&first_skip=1&last_update_ip_pos=0&fails_0=3
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@Type
1
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@Start
0
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@ErrorCo
ntrol 0
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@Tag
7
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@ImagePa
th
system32\099f7efc868878f48d536500a0e0000d.sys
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@Display
Name 099f7efc868878f48d536500a0e0000d
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d@Group
System Bus Extender
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d\Securit
y
Reg
HKLM\SYSTEM\CurrentControlSet\Services\099f7efc868878f48d536500a0e0000d\Securit
y@Security 0x01 0x00 0x14 0x80 ...
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@c
®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\4b63c2aff10254da
e185d1bbe7c1a4a5&download_period=846000&first_download_delay=180&version=2&ip_0
=586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&i
p_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails
_3=2&ips_count=4&name=4b63c2aff10254dae185d1bbe7c1a4a5&path=system32\4b63c2aff1
0254dae185d1bbe7c1a4a5.sys&wmid=Dep005&idate=2009-02-08
21:49:13:454&last_download_time=2009-6-20
16:23:18.15&first_skip=1&last_update_ip_pos=0&fails_0=2
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Type
1
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Start
0
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@ErrorCo
ntrol 0
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Tag
6
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@ImagePa
th
system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Display
Name 4b63c2aff10254dae185d1bbe7c1a4a5
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Group
System Bus Extender
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5\Securit
y
Reg
HKLM\SYSTEM\CurrentControlSet\Services\4b63c2aff10254dae185d1bbe7c1a4a5\Securit
y@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d
Reg HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@c
®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\099f7efc868878f4
8d536500a0e0000d&download_period=846000&first_download_delay=180&version=2&ip_0
=586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&i
p_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails
_3=2&ips_count=4&name=099f7efc868878f48d536500a0e0000d&path=system32\099f7efc86
8878f48d536500a0e0000d.sys&wmid=Dnr001&idate=2009-02-21
12:18:44:953&last_download_time=2009-6-20
16:23:18.0&first_skip=1&last_update_ip_pos=0&fails_0=3
Reg
HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@Type
1
Reg
HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@Start
0
Reg
HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@ErrorContro
l 0
Reg
HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@Tag
7
Reg
HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@ImagePath
system32\099f7efc868878f48d536500a0e0000d.sys
Reg
HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@DisplayName
099f7efc868878f48d536500a0e0000d
Reg
HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d@Group
System Bus Extender
Reg
HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d\Security
Reg
HKLM\SYSTEM\ControlSet002\Services\099f7efc868878f48d536500a0e0000d\Security@Se
curity 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5
Reg HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@c
®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\4b63c2aff10254da
e185d1bbe7c1a4a5&download_period=846000&first_download_delay=180&version=2&ip_0
=586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&i
p_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails
_3=2&ips_count=4&name=4b63c2aff10254dae185d1bbe7c1a4a5&path=system32\4b63c2aff1
0254dae185d1bbe7c1a4a5.sys&wmid=Dep005&idate=2009-02-08
21:49:13:454&last_download_time=2009-6-20
16:23:18.15&first_skip=1&last_update_ip_pos=0&fails_0=2
Reg
HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Type
1
Reg
HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Start
0
Reg
HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@ErrorContro
l 0
Reg
HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Tag
6
Reg
HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@ImagePath
system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys
Reg
HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@DisplayName
4b63c2aff10254dae185d1bbe7c1a4a5
Reg
HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5@Group
System Bus Extender
Reg
HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5\Security
Reg
HKLM\SYSTEM\ControlSet002\Services\4b63c2aff10254dae185d1bbe7c1a4a5\Security@Se
curity 0x01 0x00 0x14 0x80 ...
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\099f7efc868878f48d536500a0e0000d.sys
39936 bytes executable
<-- ROOTKIT !!!
File C:\WINDOWS\system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys
39936 bytes executable
<-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
===============================================================================
Here is the combofix
ComboFix 09-06-24.04 - KP 06/25/2009 5:45.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.261 [GMT -4:00]
Running from: c:\documents and settings\KP\Desktop\fixfix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\becfdefafbfbcebf.dll
c:\windows\system32\caeabaafbabae.dll
c:\windows\system32\fadbefdadd.dll
c:\windows\reged.exe
c:\windows\sys.com
c:\windows\system32\kdpini.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-06-25 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-25 00:25 . 2009-02-12 22:17 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-25 00:23 . 2009-02-12 22:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-07 03:46 . 2009-06-07 03:46 312847 ------w- c:\windows\system32\c545a1b00e143396eb1753fe738c832d.TMP
2009-06-06 23:19 . 2009-05-18 16:14 205840 ----a-w- c:\windows\system32\kusers.dll
2009-06-04 16:36 . 2009-02-12 22:17 -------- d-----w- c:\program files\SpywareBlaster
2009-05-11 20:34 . 2009-05-11 20:33 -------- d-----w- c:\program files\EsetOnlineScanner
2009-05-07 15:32 . 2001-08-23 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2001-08-23 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2001-08-23 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2008-11-09 00:27 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-17 09:14 . 2009-04-05 17:42 66576 ----a-w- c:\program files\mozilla firefox\components\fadbefdadd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingD7526"="del" [X]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/3/2008 10:33 PM 24652]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
BHO-{F70F6880-3A4B-11DE-8230-0B7C55D89593} - (no file)
HKCU-Run-DriverCure - c:\program files\ParetoLogic\DriverCure\DriverCure.exe
HKLM-Run-systemguard - c:\program files\System Guard 2009\systemguard.exe
Notify-caeabaafbabae - (no file)
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Search - ?p=ZKxdm021QUUS
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-25 05:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\099f7efc868878f48d536500a0e0000d.sys 39936 bytes executable
c:\windows\system32\_099f7efc868878f48d536500a0e0000d.sys_.vir 39936 bytes executable
c:\windows\system32\_4b63c2aff10254dae185d1bbe7c1a4a5.sys_.vir 39936 bytes executable
c:\windows\system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys 39936 bytes executable
scan completed successfully
hidden files: 4
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\099f7efc868878f48d536500a0e0000d]
"ImagePath"="system32\099f7efc868878f48d536500a0e0000d.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\4b63c2aff10254dae185d1bbe7c1a4a5]
"ImagePath"="system32\4b63c2aff10254dae185d1bbe7c1a4a5.sys"
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wscntfy.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-06-25 5:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-25 09:54
Pre-Run: 74,055,819,264 bytes free
Post-Run: 73,980,219,392 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
117 --- E O F --- 2009-06-25 09:10