InterviewSolution
Saved Bookmarks
| 1. |
Solve : application can not be executed - xy is infected - trojan horse? |
|
Answer» with web cure it same thing as last time: i could not open the page - server not found... and what about the two threats that were found by eset this time? since i pressed merely the 'scan archives' button and not the 'remove found threats'-one?Run the ESET scan again and, this time remove them please.this time i removed the threats (which amounted to 5 now...) and these are the results: C:\Windows\temp\37716533.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined C:\Windows\temp\5f9d0076.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined C:\Windows\temp\8d556260.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined C:\Windows\temp\a879b485.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined C:\Windows\temp\d7db9f3.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined web Cureit still does not work however... i don't know if it would work if i just didn't use the link you posted but would download it from here http://www.freedrweb.com/cureit/?lng=en -> is this the right thing? many thanks!Quote from: ekluever on July 13, 2010, 04:41:29 PM i don't know if it would work if i just didn't use the link you posted but would download it from here http://www.freedrweb.com/cureit/?lng=en -> is this the right thing?Yes, that's correct. We don't normally send users to websites; by clicking on the link you should get a download message.hello dave, i ran the dr.web cure it quick scan (while i was gone to work) and when i returned it said it didn't find any threats. in the meantime my friend said however, that i should have cut my internet connection, while doing the scan. i did not do the complete scan - cause i wasn't sure since it hadn't found anything in the first place. what do you recommend next? thanks, elisa ps: yes, i know, usually clicking your links always directly opened the download window, just this one tried to open a new tab and then said it couldn't find the server...Elisa, could you please give it a few days and then come back and tell how everything is working. If it's ok by then, we'll do some cleanup.hello dave malicious software removal tool today alerted me and said it found a Trojan:WinNT/Bubnix.gen!A which it partially removed. what keeps happening unfortunately, is that it won't properly start, it'll say a problem has been detected and windows has been shut down to prevent damage to your computer acpi.sys then it'll restart, come to the site i described before, where you can choose one of five start-options. the normal starting is the highlighted choice which will be chosen automatically after 30 sec. this cycle will be gone through a COUPLE of times, until eventually, with the automatic choice it'll start normally... i just wanted to describe this problem again. other than that, it seems to be working fine. i'll shut it down now and then run a complete antivir scan, as this is whast was suggested after finding the above mentioned file... else, i'll follow your advice and call back in a couple of days. many thanks! elisaoh, and something was found when i started another antivr-scan just now, i'll paste the log: Avira AntiVir Personal Report file date: Thursday, July 15, 2010 09:27 Scanning for 2346510 virus strains and unwanted programs. The program is running as an UNRESTRICTED full version. Online services are available: Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows Vista Windows version : (Service Pack 2) [6.0.6002] Boot mode : Normally booted Username : SYSTEM Computer name : ELISA-PC Version information: BUILD.DAT : 10.0.0.567 32097 Bytes 4/19/2010 15:07:00 AVSCAN.EXE : 10.0.3.0 433832 Bytes 4/1/2010 12:37:38 AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 12:57:04 LUKE.DLL : 10.0.2.3 104296 Bytes 3/7/2010 18:33:04 LUKERES.DLL : 10.0.0.1 12648 Bytes 2/10/2010 23:40:49 VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 09:05:36 VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 19:27:49 VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 17:37:42 VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 16:37:42 VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 11:29:03 VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 11:09:48 VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 11:09:54 VBASE007.VDF : 7.10.7.219 2048 Bytes 6/2/2010 11:09:54 VBASE008.VDF : 7.10.7.220 2048 Bytes 6/2/2010 11:09:54 VBASE009.VDF : 7.10.7.221 2048 Bytes 6/2/2010 11:09:54 VBASE010.VDF : 7.10.7.222 2048 Bytes 6/2/2010 11:09:54 VBASE011.VDF : 7.10.7.223 2048 Bytes 6/2/2010 11:09:54 VBASE012.VDF : 7.10.7.224 2048 Bytes 6/2/2010 11:09:54 VBASE013.VDF : 7.10.8.37 270336 Bytes 6/10/2010 11:09:55 VBASE014.VDF : 7.10.8.69 138752 Bytes 6/14/2010 11:09:55 VBASE015.VDF : 7.10.8.102 130560 Bytes 6/16/2010 11:09:56 VBASE016.VDF : 7.10.8.135 152064 Bytes 6/21/2010 11:09:56 VBASE017.VDF : 7.10.8.163 432128 Bytes 6/23/2010 11:09:57 VBASE018.VDF : 7.10.8.194 133632 Bytes 6/27/2010 11:09:57 VBASE019.VDF : 7.10.8.220 134656 Bytes 6/29/2010 11:09:58 VBASE020.VDF : 7.10.8.252 171520 Bytes 7/4/2010 11:09:58 VBASE021.VDF : 7.10.9.19 131072 Bytes 7/6/2010 11:09:59 VBASE022.VDF : 7.10.9.36 297472 Bytes 7/7/2010 11:09:59 VBASE023.VDF : 7.10.9.60 150016 Bytes 7/11/2010 08:02:27 VBASE024.VDF : 7.10.9.79 113152 Bytes 7/13/2010 08:02:27 VBASE025.VDF : 7.10.9.80 2048 Bytes 7/13/2010 08:02:27 VBASE026.VDF : 7.10.9.81 2048 Bytes 7/13/2010 08:02:27 VBASE027.VDF : 7.10.9.82 2048 Bytes 7/13/2010 08:02:27 VBASE028.VDF : 7.10.9.83 2048 Bytes 7/13/2010 08:02:28 VBASE029.VDF : 7.10.9.84 2048 Bytes 7/13/2010 08:02:28 VBASE030.VDF : 7.10.9.85 2048 Bytes 7/13/2010 08:02:28 VBASE031.VDF : 7.10.9.90 95744 Bytes 7/14/2010 08:02:30 Engineversion : 8.2.4.10 AEVDF.DLL : 8.1.2.0 106868 Bytes 7/8/2010 11:10:09 AESCRIPT.DLL : 8.1.3.39 1335674 Bytes 7/8/2010 11:10:09 AESCN.DLL : 8.1.6.1 127347 Bytes 7/8/2010 11:10:08 AESBX.DLL : 8.1.3.1 254324 Bytes 7/8/2010 11:10:10 AERDL.DLL : 8.1.4.6 541043 Bytes 7/8/2010 11:10:08 AEPACK.DLL : 8.2.2.5 430453 Bytes 7/8/2010 11:10:08 AEOFFICE.DLL : 8.1.1.6 201081 Bytes 7/8/2010 11:10:07 AEHEUR.DLL : 8.1.1.38 2724214 Bytes 7/8/2010 11:10:07 AEHELP.DLL : 8.1.11.6 242038 Bytes 7/8/2010 11:10:04 AEGEN.DLL : 8.1.3.13 381300 Bytes 7/8/2010 11:10:04 AEEMU.DLL : 8.1.2.0 393588 Bytes 7/8/2010 11:10:03 AECORE.DLL : 8.1.15.3 192886 Bytes 7/8/2010 11:10:02 AEBB.DLL : 8.1.1.0 53618 Bytes 7/8/2010 11:10:00 AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 12:03:38 AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 12:03:35 AVREP.DLL : 10.0.0.8 62209 Bytes 2/18/2010 16:47:40 AVREG.DLL : 10.0.3.0 53096 Bytes 4/1/2010 12:35:46 AVSCPLR.DLL : 10.0.3.0 83816 Bytes 4/1/2010 12:39:51 AVARKT.DLL : 10.0.0.14 227176 Bytes 4/1/2010 12:22:13 AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 09:53:30 SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 12:57:58 AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 15:38:56 NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 14:41:00 RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 13:10:20 RCTEXT.DLL : 10.0.53.0 97128 Bytes 4/9/2010 14:14:29 Configuration settings for the scan: Jobname.............................: Complete system scan Configuration file..................: C:\program files\avira\antivir desktop\sysscan.avp Logging.............................: low Primary action......................: interactive Secondary action....................: ignore Scan master boot sector.............: on Scan boot sector....................: on Boot sectors........................: C:, D:, Process scan........................: on Extended process scan...............: on Scan registry.......................: on Search for rootkits.................: on Integrity checking of system files..: off Scan all files......................: All files Scan archives.......................: on Recursion depth.....................: 20 Smart extensions....................: on Macro heuristic.....................: on File heuristic......................: medium Start of the scan: Thursday, July 15, 2010 09:27 Starting search for hidden objects. The scan of running processes will be started Scan process 'winamp.exe' - '190' Module(s) have been scanned Scan process 'svchost.exe' - '30' Module(s) have been scanned Scan process 'vssvc.exe' - '49' Module(s) have been scanned Scan process 'avscan.exe' - '79' Module(s) have been scanned Scan process 'SkypeNames.exe' - '25' Module(s) have been scanned Scan process 'skypePM.exe' - '67' Module(s) have been scanned Scan process 'Skype.exe' - '123' Module(s) have been scanned Scan process 'firefox.exe' - '118' Module(s) have been scanned Scan process 'mobsync.exe' - '38' Module(s) have been scanned Scan process 'igfxsrvc.exe' - '30' Module(s) have been scanned Scan process 'FirewallGUI.exe' - '48' Module(s) have been scanned Scan process 'avgnt.exe' - '54' Module(s) have been scanned Scan process 'pctsTray.exe' - '59' Module(s) have been scanned Scan process 'winampa.exe' - '21' Module(s) have been scanned Scan process 'jusched.exe' - '24' Module(s) have been scanned Scan process 'OEM02Mon.exe' - '34' Module(s) have been scanned Scan process 'igfxpers.exe' - '26' Module(s) have been scanned Scan process 'hkcmd.exe' - '26' Module(s) have been scanned Scan process 'GrooveMonitor.exe' - '43' Module(s) have been scanned Scan process 'MSASCui.exe' - '40' Module(s) have been scanned Scan process 'taskeng.exe' - '47' Module(s) have been scanned Scan process 'RapportService.exe' - '72' Module(s) have been scanned Scan process 'Explorer.EXE' - '160' Module(s) have been scanned Scan process 'taskeng.exe' - '82' Module(s) have been scanned Scan process 'Dwm.exe' - '29' Module(s) have been scanned Scan process 'WUDFHost.exe' - '33' Module(s) have been scanned Scan process 'SearchIndexer.exe' - '60' Module(s) have been scanned Scan process 'svchost.exe' - '9' Module(s) have been scanned Scan process 'svchost.exe' - '44' Module(s) have been scanned Scan process 'avshadow.exe' - '33' Module(s) have been scanned Scan process 'pctsAuxs.exe' - '26' Module(s) have been scanned Scan process 'svchost.exe' - '40' Module(s) have been scanned Scan process 'IoctlSvc.exe' - '21' Module(s) have been scanned Scan process 'FWService.exe' - '61' Module(s) have been scanned Scan process 'avguard.exe' - '64' Module(s) have been scanned Scan process 'svchost.exe' - '62' Module(s) have been scanned Scan process 'sched.exe' - '56' Module(s) have been scanned Scan process 'spoolsv.exe' - '85' Module(s) have been scanned Scan process 'svchost.exe' - '91' Module(s) have been scanned Scan process 'svchost.exe' - '86' Module(s) have been scanned Scan process 'SLsvc.exe' - '23' Module(s) have been scanned Scan process 'svchost.exe' - '153' Module(s) have been scanned Scan process 'svchost.exe' - '115' Module(s) have been scanned Scan process 'svchost.exe' - '66' Module(s) have been scanned Scan process 'RapportMgmtService.exe' - '68' Module(s) have been scanned Scan process 'svchost.exe' - '54' Module(s) have been scanned Scan process 'svchost.exe' - '35' Module(s) have been scanned Scan process 'svchost.exe' - '40' Module(s) have been scanned Scan process 'lsm.exe' - '22' Module(s) have been scanned Scan process 'winlogon.exe' - '30' Module(s) have been scanned Scan process 'lsass.exe' - '60' Module(s) have been scanned Scan process 'services.exe' - '33' Module(s) have been scanned Scan process 'csrss.exe' - '14' Module(s) have been scanned Scan process 'wininit.exe' - '26' Module(s) have been scanned Scan process 'csrss.exe' - '14' Module(s) have been scanned Scan process 'smss.exe' - '2' Module(s) have been scanned Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Master boot sector HD1 [INFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Boot sector 'D:\' [INFO] No virus was found! Starting to scan executable files (registry). The registry was scanned ( '350' files ). Starting the file scan: BEGIN scan in 'C:\' C:\Program Files\7-Zip\Uninstall.exe [WARNING] Insufficient memory. The file was not scanned. C:\Users\Elisa\Downloads\7z465.exe [WARNING] Insufficient memory. The file was not scanned. C:\Windows\System32\drivers\igcmc.sys [DETECTION] Is the TR/Rootkit.Gen Trojan Begin scan in 'D:\' Beginning disinfection: C:\Windows\System32\drivers\igcmc.sys [DETECTION] Is the TR/Rootkit.Gen Trojan [NOTE] The file was moved to the quarantine directory under the name '48757dfe.qua'. End of the scan: Thursday, July 15, 2010 10:46 Used time: 1:14:10 Hour(s) The scan has been done completely. 17360 Scanned directories 274560 Files were scanned 1 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 1 Files were moved to quarantine 0 Files were renamed 0 Files cannot be scanned 274559 Files not concerned 1061 Archives were scanned 2 Warnings 1 Notes 462110 Objects were scanned with rootkit scan 0 Hidden objects were found cheersDownload the GMER Rootkit Scanner. Unzip it to your Desktop. Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan. Double-click gmer.exe. The program will begin to run. **Caution** These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised! If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
everything went a bit different from the description, i wasn't asked whether i wanted to perform any scan, so i just checked whether the boxes were all checked/unchecked and then started the scan, which seemed to have finished but again i didn't receive any notice. here is the log: GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-07-16 15:01:42 Windows 6.0.6002 Service Pack 2 Running: gmer.exe; Driver: C:\Users\Elisa\AppData\Local\Temp\uglcapoc.sys ---- System - GMER 1.0.15 ---- SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAllocateVirtualMemory [0xA82F5752] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAlpcConnectPort [0xA82F5388] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAssignProcessToJobObject [0xA82F5440] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwConnectPort [0xA82F5482] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateFile [0xA82F5530] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateProcess [0xA82F5DD8] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateProcessEx [0xA82F5E64] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateThread [0xA82F5EF4] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwDebugActiveProcess [0xA82F5580] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwDuplicateObject [0xA82F55C2] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwLoadDriver [0xA82F5606] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenKey [0xA82F5648] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenSection [0xA82F568A] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenThread [0xA82F56CC] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwProtectVirtualMemory [0xA82F579A] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwRequestWaitReplyPort [0xA82F570E] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwRestoreKey [0xA82F57DC] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwResumeThread [0xA82F5824] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSecureConnectPort [0xA82F58B4] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSetValueKey [0xA82F5866] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSuspendProcess [0xA82F5958] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSystemDebugControl [0xA82F599A] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwTerminateProcess [0xA82F59DC] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwWriteVirtualMemory [0xA82F5A2A] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateThreadEx [0xA82F5F96] SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateUserProcess [0xA82F5D68] INT 0x62 ? 854F6BF8 INT 0x72 ? 854F6BF8 INT 0x72 ? 854F6BF8 INT 0x72 ? 854F6BF8 INT 0x82 ? 854F6BF8 INT 0x82 ? 854F6BF8 INT 0x82 ? 854F6BF8 INT 0x82 ? 854F6BF8 INT 0xA2 ? 84606BF8 INT 0xB2 ? 84606BF8 INT 0xB2 ? 84606BF8 INT 0xB2 ? 84606BF8 ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!KeSetEvent + 131 81AEE894 4 Bytes [52, 57, 2F, A8] .text ntkrnlpa.exe!KeSetEvent + 13D 81AEE8A0 4 Bytes [88, 53, 2F, A8] .text ntkrnlpa.exe!KeSetEvent + 191 81AEE8F4 4 Bytes [40, 54, 2F, A8] .text ntkrnlpa.exe!KeSetEvent + 1C1 81AEE924 4 Bytes [82, 54, 2F, A8] .text ntkrnlpa.exe!KeSetEvent + 1D9 81AEE93C 4 Bytes [30, 55, 2F, A8] .text ... ? System32\Drivers\spxo.sys The system cannot find the path specified. ! .text USBPORT.SYS!DllUnload 8C5A341B 5 Bytes JMP 854F61D8 .text au8ydgj3.SYS 8BA35000 22 Bytes [82, 63, A1, 81, 6C, 62, A1, ...] .text au8ydgj3.SYS 8BA35017 181 Bytes [00, 32, B7, 79, 80, 3D, B5, ...] .text au8ydgj3.SYS 8BA350CE 10 Bytes [00, 00, 00, 00, 00, 00, 02, ...] .text au8ydgj3.SYS 8BA350DA 12 Bytes [00, 00, 02, 00, 00, 00, 24, ...] .text au8ydgj3.SYS 8BA350E7 714 Bytes [00, F0, 0E, 00, 00, 00, 00, ...] .text ... ? \ArcName\multi(0)disk(0)rdisk(0)partition(1)\Windows\system32\drivers\PctWfpFilter.sys The system cannot find the path specified. ! ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 00414A50 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.) .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] USER32.dll!InSendMessageEx + 3B1 76FAE6B0 6 Bytes JMP 0044C7F0 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.) .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] WS2_32.dll!getaddrinfo 77A2418A 5 Bytes JMP 71640022 .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] WS2_32.dll!gethostbyname 77A362D4 5 Bytes JMP 71670022 .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] ntdll.dll!LdrLoadDll 77819390 5 Bytes JMP 00B013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 02187B40 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.) .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] kernel32.dll!SetUnhandledExceptionFilter 76E4A84F 6 Bytes PUSH 71510022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!DdeInitializeW 76FA7921 6 Bytes PUSH 714E0022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!RegisterClassExW 76FADA30 6 Bytes PUSH 716E0022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!GetMessageW 76FBFEF7 6 Bytes PUSH 71480022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!TranslateMessage 76FC01AD 6 Bytes PUSH 71410022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!GetClipboardData 76FE715A 6 Bytes PUSH 714B0022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] GDI32.dll!BitBlt 76F070A6 6 Bytes PUSH 71540022; RET .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 00438CE0 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (RapportService/Trusteer Ltd.) .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] WS2_32.dll!getaddrinfo 77A2418A 5 Bytes JMP 71670022 .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] WS2_32.dll!gethostbyname 77A362D4 5 Bytes JMP 716E0022 .text C:\Program Files\Spyware Doctor\pctsTray.exe[3848] kernel32.dll!CreateThread + 1A 76E6C928 4 Bytes CALL 0044B8D9 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools) ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [806916D6] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80691042] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [80691800] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [806910C0] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8069113E] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806A0E9C] \SystemRoot\System32\Drivers\spxo.sys IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortNotification] CC358B04 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortUchar] 838BA5AF IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortUlong] 458B38C6 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetPhysicalAddress] A5A5A514 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 100D8BA5 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetScatterGatherList] 5F8BA580 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortUchar] 30810889 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortStallExecution] 54771129 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetParentBusType] 10C25D5E IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortRequestCallback] 8B55CC00 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 084D8BEC IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0CF0918B IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortCompleteRequest] 458B0000 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortMoveMemory] 8B108910 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 000CF491 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 04508900 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 053C7980 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortUshort] 560C558B IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortBufferUshort] C6127557 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortInitialize] B18D0502 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetDeviceBase] 00000CF8 IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortDeviceStateChange] A508788D ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 71670000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\GDI32.dll [USER32.dll!GetWindowRect] 71450000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ole32.dll [USER32.dll!GetWindowRect] 71450000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowRect] 71450000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WININET.dll [USER32.dll!GetWindowRect] 71450000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000 IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3848] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools) IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3848] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools) ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 8460C1F8 Device \Driver\volmgr \Device\VolMgrControl 846081F8 Device \Driver\usbuhci \Device\USBPDO-0 854F31F8 Device \Driver\sptd \Device\1136032336 spxo.sys Device \Driver\usbuhci \Device\USBPDO-1 854F31F8 Device \Driver\usbehci \Device\USBPDO-2 854E41F8 Device \Driver\usbuhci \Device\USBPDO-3 854F31F8 Device \Driver\usbuhci \Device\USBPDO-4 854F31F8 AttachedDevice \Driver\tdx \Device\Tcp pctgntdi.sys Device \Driver\usbuhci \Device\USBPDO-5 854F31F8 Device \Driver\usbehci \Device\USBPDO-6 854E41F8 Device \Driver\volmgr \Device\HarddiskVolume1 846081F8 Device \Driver\PCI_PNP0319 \Device\00000058 spxo.sys Device \Driver\volmgr \Device\HarddiskVolume2 846081F8 Device \Driver\cdrom \Device\CdRom0 8551E1F8 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8460A1F8 Device \Driver\atapi \Device\Ide\IdePort0 8460A1F8 Device \Driver\atapi \Device\Ide\IdePort1 8460A1F8 Device \Driver\atapi \Device\Ide\IdePort2 8460A1F8 Device \Driver\msahci \Device\Ide\PciIde1Channel0 8460B1F8 Device \Driver\msahci \Device\Ide\PciIde1Channel2 8460B1F8 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-2 8460A1F8 Device \Driver\cdrom \Device\CdRom1 8551E1F8 Device \Driver\netbt \Device\NetBT_Tcpip_{D1957ABD-6FAC-430A-98F1-B0F3C259C5C7} 85B68500 Device \Driver\netbt \Device\NetBt_Wins_Export 85B68500 Device \Driver\Smb \Device\NetbiosSmb 85C3F1F8 Device \Driver\iScsiPrt \Device\RaidPort0 855771F8 Device \Driver\usbuhci \Device\USBFDO-0 854F31F8 Device \Driver\usbuhci \Device\USBFDO-1 854F31F8 Device \Driver\netbt \Device\NetBT_Tcpip_{0C10FA32-146C-4B41-A940-8A06AA1733CB} 85B68500 Device \Driver\usbehci \Device\USBFDO-2 854E41F8 Device \Driver\usbuhci \Device\USBFDO-3 854F31F8 Device \Driver\usbuhci \Device\USBFDO-4 854F31F8 Device \Driver\usbuhci \Device\USBFDO-5 854F31F8 Device \Driver\usbehci \Device\USBFDO-6 854E41F8 Device \Driver\au8ydgj3 \Device\Scsi\au8ydgj31Port4Path0Target0Lun0 855621F8 Device \Driver\au8ydgj3 \Device\Scsi\au8ydgj31 855621F8 Device \FileSystem\cdfs \Cdfs 855111F8 ---- EOF - GMER 1.0.15 ---- many thanks!Quote malicious software removal tool today alerted me and said it found a Trojan:WinNT/Bubnix.gen!A which it partially removed.What do you mean by "partially removed"? Do you have your OS CD/DVD? If so, 1/ Click the Start button. 2/ From the Start Menu, Click All programs followed by Accessories. 3/ In the Accessories menu, Right Click on the Command Prompt option. 4/ From the drop down menu that appears, Click on the Run as administrator option. 5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc. 6/ In the Command Prompt window, type: sfc /scannow and then press Enter. 7/ A message will appear stating that the system scan will begin. 8/ Be patient because the scan may take some time. 9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue. 10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations. 11/ After the scan has completed, Close the command prompt window. Dear Dave I just wanted to thank you for all your help!!! You definitely got it working again and then I was really busy for a few days and always planning to eventually do all the last things you suggested and never got round to it. In the meantime my laptop entirely broke, but I just wanna thank you for all your efforts. I felt really lucky that there was a forum like this and someone out there who understood all these logs... Thank you!!! You're welcome. I will lock this thread. If you need it opened for any reason, please pm me. |
|