Results of screen317's Security Check version 0.99.32
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check: Windows Firewall Enabled!
Symantec Endpoint Protection
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check: Spybot - Search & Destroy
Secunia PSI (2.0.0.4003)
Java 6 Update 31
Adobe Flash Player 10.3.183.16
Flash Player out of Date! Adobe Reader 9
Adobe Reader out of date! Mozilla Firefox (3.6.28)
Firefox out of Date! ````````````````````````````````
Process Check:
objlist.exe by Laurent Norton ccSvcHst.exe
``````````End of Log```````````` Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.30.07
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Estelle :: PHASEIII-G3TPW4 [administrator]
3/31/2012 12:11:40 AM
mbam-log-2012-03-31 (00-11-40).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 181553
Time elapsed: 3 minute(s), 14 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
GMER 1.0.15.15641 -
http://www.gmer.netRootkit scan 2012-03-31 04:01:26
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-16 WDC_WD1600AAJS-00L7A0 rev.01.03E01
Running: eu74zh08.exe; Driver: C:\DOCUME~1\Estelle\LOCALS~1\Temp\kfpiakow.sys
---- System - GMER 1.0.15 ----
SSDT 88F85008 ZwAlertResumeThread
SSDT 88F86650 ZwAlertThread
SSDT 8975EB28 ZwAllocateVirtualMemory
SSDT 88F61070 ZwAssignProcessToJobObject
SSDT 89C501F8 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xACE90980]
SSDT 88F5C2C8 ZwCreateMutant
SSDT 88F8ACF8 ZwCreateSymbolicLinkObject
SSDT 89040E18 ZwCreateThread
SSDT 88F61130 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xACE90C00]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xACE90F10]
SSDT 89713858 ZwDuplicateObject
SSDT 88F681B0 ZwFreeVirtualMemory
SSDT 88F85080 ZwImpersonateAnonymousToken
SSDT 88F85658 ZwImpersonateThread
SSDT 895129B8 ZwLoadDriver
SSDT 88F680D0 ZwMapViewOfSection
SSDT 88F18008 ZwOpenEvent
SSDT 891C30A0 ZwOpenProcess
SSDT 89376060 ZwOpenProcessToken
SSDT 88F53120 ZwOpenSection
SSDT 8913F0C0 ZwOpenThread
SSDT 88F728B8 ZwProtectVirtualMemory
SSDT 88F62670 ZwResumeThread
SSDT 88F68918 ZwSetContextThread
SSDT 88F6A0D8 ZwSetInformationProcess
SSDT 88F78138 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xACE91160]
SSDT 88F18D50 ZwSuspendProcess
SSDT 88F74758 ZwSuspendThread
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xA7E97640]
SSDT 88F68838 ZwTerminateThread
SSDT 88F6A1C8 ZwUnmapViewOfSection
SSDT 88F4F0A8 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2FE8 80504884 8 Bytes [40, 76, E9, A7, 38, 88, F6, ...]
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
.text C:\WINDOWS\System32\DRIVERS\ati2mtag.sys section is writeable [0xB9852000, 0x236D87, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[812] ntdll.dll!NtMapViewOfSection 7C90D51E 5 Bytes JMP 023A003A
.text C:\Program Files\Mozilla Firefox\firefox.exe[812] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 023A00F7
.text C:\Program Files\Mozilla Firefox\firefox.exe[812] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[812] kernel32.dll!VirtualProtectEx + 6E 7C801ACF 7 Bytes JMP 023A03D2
.text C:\Program Files\Mozilla Firefox\firefox.exe[812] kernel32.dll!ReadProcessMemory + 3E 7C80220E 7 Bytes JMP 023A01B0
.text C:\Program Files\Mozilla Firefox\firefox.exe[812] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 023A031C
.text C:\Program Files\Mozilla Firefox\firefox.exe[812] kernel32.dll!GetVersionExA + D3 7C812C51 7 Bytes JMP 023A0488
.text C:\Program Files\Mozilla Firefox\firefox.exe[812] kernel32.dll!GetProcessHandleCount + 35 7C86229F 7 Bytes JMP 023A0266
.text C:\WINDOWS\Explorer.EXE[896] SHELL32.dll!StrStrW 7C9CEE90 8 Bytes [E0, 10, 60, 19, 00, 11, 60, ...] {LOOPNZ 0x12; PUSHA ; SBB [EAX], EAX; ADC [EAX+0x19], ESP}
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3208] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 1040B7B0 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01EA.VBN 9135 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01F4 0 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01F4\4FFEA5D9.VBN 858146 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01FD.VBN 9135 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E5 0 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E5\4FFEA58D.VBN 858146 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E5.VBN 9135 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E6 0 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E6\4FFEA592.VBN 858074 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E6.VBN 9063 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E7 0 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E7\4FFEA597.VBN 858146 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E7.VBN 9135 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E8 0 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E8\4FFEA59C.VBN 858146 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E8.VBN 9135 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E9 0 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E9\4FFEA5A1.VBN 858074 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01E9.VBN 9063 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01EA 0 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\Data\Quarantine\09BC01EA\4FFEA5A6.VBN 858146 bytes
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\12.1.1000.157.105\SRTSP\Quarantine\AP685755AA.exe 865280 bytes
File C:\Documents and Settings\Estelle\Local Settings\Temp\dwhb05.exe 848896 bytes
File C:\Documents and Settings\Estelle\Local Settings\Temp\DWHB05.tmp 0 bytes
File C:\Documents and Settings\Estelle\Local Settings\Temp\dwhb09.exe 848896 bytes
File C:\Documents and Settings\Estelle\Local Settings\Temp\DWHB09.tmp 0 bytes
File C:\Documents and Settings\Estelle\Local Settings\Temp\dwhb0d.exe 848896 bytes
File C:\Documents and Settings\Estelle\Local Settings\Temp\DWHB0D.tmp 0 bytes
File C:\Documents and Settings\Estelle\Local Settings\Temp\dwhb13.exe 848896 bytes
File C:\Documents and Settings\Estelle\Local Settings\Temp\DWHB13.tmp 0 bytes
---- EOF - GMER 1.0.15 ----