Problem started with not being able to run Malawarebytes in safe mode. Now freezes at startup and shutdown. must start in safe mode then try regular boot. GMER scans but "not responding " when asked to save. Any suggections?
Forgot to add DDS log
DDS (Ver_11-03-05.01) - NTFSx86 NETWORK
Run by HP_Owner at 15:49:13.84 on Sun 04/24/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1471.1112 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\HP_Owner\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = http=127.0.0.1:1031
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: HP view: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\HPDTLK02.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: GuardedID: {cb7dc2da-d8c9-4004-8548-1e24aa7d46de} - c:\program files\sft\guardedid\GIDTB.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: {4E7BD74F-2B8D-469E-D1FB-EF7FB3D5FA7D} - No File
TB: {DE9C389F-3316-41A7-809B-AA305ED9D922} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [RunNarrator] Narrator.exe
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10e.exe
uPolicies-explorer: GreyMSIAds = 1 (0x1)
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326}
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxps://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} - hxxp://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {49232000-16E4-426C-A231-62846947304B} - hxxp://ipgweb.cce.hp.com/rdqcpqdktp/downloads/sysinfo.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/OnlineScanner.cab
DPF: {5BCC24A7-7D3F-4CC9-AC86-4380FCD68D1E} - hxxp://esupport.trendmicro.com/_layouts/1033/GetPCInfo.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://javadl.sun.com/webapps/download/AutoDL?BundleId=26688
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} - hxxp://www.trendsecure.com/easy_install/_activex/en-US/TSEasyInstallX.CAB
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E8F2FD65-4CA1-4E1E-BE81-A2D0A7C4D9CC} - hxxps://esupport.trendmicro.com/_layouts/1033/GetVBInfo.cab
Notify: GuardedID - WNPGID.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
mASetup: {ABE57277-678B-4A8A-9D0E-A25E285CCCE7}-1Reg - c:\windows\system32\regsvr32.exe /s /n /i "c:\program files\sft\guardedid\gidtb.dll"
mASetup: {ABE57277-678B-4A8A-9D0E-A25E285CCCE7}-2Help - c:\program files\sft\guardedid\gidhelp.bat "c:\program files\sft\guardedid\docs\setupcomplete.html" 1
mASetup: {ABE57277-678B-4A8A-9D0E-A25E285CCCE7}-3Reg - c:\program files\sft\guardedid\gidi.exe /v
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\hp_owner\applic~1\mozilla\firefox\profiles\4qmoegkk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=BABTDF&PC=BBLN&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=ZUGO&form=ZGAADF&q=
FF - prefs.js: browser.search.selectedEngine - Bing
FF - component: c:\program files\mozilla firefox\extensions\guardedid@sftnj.com\components\gidconnect.dll
FF - Ext: GuardedID Toolbar: guardedid@sftnj.com - c:\program files\mozilla firefox\extensions\guardedid@sftnj.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.
============= SERVICES / DRIVERS ===============
.
R0 IABFilt;Iomega Snapshot Volume Filter;c:\windows\system32\drivers\IABFilt.sys [2006-8-3 25344]
R1 GIDv2;GIDv2;c:\windows\system32\drivers\gidv2.sys [2010-10-30 26400]
R1 HMFAxCore9e7601803354626e599e36ff93023a2b;HMFAxCore9e7601803354626e599e36ff93023a2b;c:\windows\system32\drivers\HMFAxCore9e7601803354626e599e36ff93023a2b.sys [2007-4-15 15872]
S0 Partizan;Partizan;c:\windows\system32\drivers\partizan.sys --> c:\windows\system32\drivers\Partizan.sys [?]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
S1 MpKsl0b81759e;MpKsl0b81759e;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl0b81759e.sys [2011-4-24 28752]
S1 MpKsl13ff9887;MpKsl13ff9887;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\mpksl13ff9887.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl13ff9887.sys [?]
S1 MpKsl208f3dc3;MpKsl208f3dc3;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl208f3dc3.sys [2011-4-24 28752]
S1 MpKsl237f0818;MpKsl237f0818;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl237f0818.sys [2011-4-24 28752]
S1 MpKsl6be2aba2;MpKsl6be2aba2;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7baed38f-8ff8-4ece-b313-1c0a66af91c8}\mpksl6be2aba2.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7baed38f-8ff8-4ece-b313-1c0a66af91c8}\MpKsl6be2aba2.sys [?]
S1 MpKsl7dd33c6b;MpKsl7dd33c6b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\mpksl7dd33c6b.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl7dd33c6b.sys [?]
S1 MpKsl89cc6ef9;MpKsl89cc6ef9;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\mpksl89cc6ef9.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl89cc6ef9.sys [?]
S1 MpKsla1bf3da6;MpKsla1bf3da6;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\mpksla1bf3da6.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsla1bf3da6.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\superantispyware\sasdifsv.sys --> c:\program files\superantispyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\superantispyware\saskutil.sys --> c:\program files\superantispyware\SASKUTIL.sys [?]
S2 BCMNTIO;BCMNTIO;c:\progra~1\checkit\diagno~1\BCMNTIO.sys [2007-1-25 3744]
S2 MAPMEM;MAPMEM;c:\progra~1\checkit\diagno~1\MAPMEM.sys [2007-1-25 3904]
S3 cpuz132;cpuz132;\??\c:\docume~1\hp_owner\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\hp_owner\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-2-9 30192]
S3 mipsinf;mipsinf;\??\c:\windows\system32\mipsinf.sys --> c:\windows\system32\mipsinf.sys [?]
S3 SGUARD;SGUARD;c:\windows\system32\drivers\SGuard.sys [2005-4-30 17857]
S4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
.
=============== Created Last 30 ================
.
2011-04-24 19:15:27 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl208f3dc3.sys
2011-04-24 12:03:49 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl0b81759e.sys
2011-04-24 11:48:42 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl237f0818.sys
2011-04-24 11:45:00 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKslb926558e.sys
2011-04-24 10:48:34 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl5157a6b7.sys
2011-04-24 10:46:31 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl0b393e03.sys
2011-04-23 18:11:43 -------- d-----w- c:\documents and settings\hp_owner\DoctorWeb
2011-04-23 11:10:37 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKslb35322e9.sys
2011-04-23 11:08:04 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsleba0bcff.sys
2011-04-23 02:05:04 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl53ce05dd.sys
2011-04-23 00:33:34 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKslae469ed4.sys
2011-04-22 18:15:19 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl643f8125.sys
2011-04-22 18:13:29 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl6eda089b.sys
2011-04-22 17:54:36 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl3a133a5c.sys
2011-04-22 17:49:12 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl3a3967e0.sys
2011-04-22 10:55:19 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKslfc3c973f.sys
2011-04-21 19:50:14 -------- d-----w- C:\ComboFix
2011-04-21 19:43:43 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl572f49f7.sys
2011-04-21 19:37:28 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl4be8fc20.sys
2011-04-20 22:35:10 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKsl43b0e5e1.sys
2011-04-20 22:30:16 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\MpKslb1c2dbe2.sys
2011-04-20 21:58:14 6792528 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{43ba7212-39bf-4863-95e6-ee7f3214774b}\mpengine.dll
2011-04-20 21:55:48 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-04-20 21:55:48 -------- d-----w- c:\windows\system32\wbem\Repository
2011-04-20 00:29:33 160272 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-04-19 15:43:23 -------- d-----w- C:\5d07e1df884ff9e7c915f607c49a
2011-04-18 22:39:38 -------- d-----w- c:\program files\Setup Support for ShopToWin
2011-04-18 22:38:41 -------- d-----w- c:\program files\Quick Web Player
.
==================== Find3M ====================
.
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45:07 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-17 19:00:29 832512 ----a-w- c:\windows\system32\wininet.dll
2011-02-17 19:00:28 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-02-17 19:00:28 1830912 ------w- c:\windows\system32\inetcpl.cpl
2011-02-17 19:00:27 17408 ----a-w- c:\windows\system32\corpol.dll
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-17 11:44:16 389120 ----a-w- c:\windows\system32\html.iec
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-11 13:25:52 229888 ----a-w- c:\windows\system32\fxscover.exe
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 22:11:20 222080 -c----w- c:\windows\system32\MpSigStub.exe
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A7454F0]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a74b7d0]; MOV EAX, [0x8a74b84c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x8A72EAB8]
3 CLASSPNP[0xF7657FD7] -> nt!IofCallDriver[0x804E37D5] -> \Device\00000070[0x8A7A4990]
5 ACPI[0xF75AE620] -> nt!IofCallDriver[0x804E37D5] -> [0x8A76DD98]
\Driver\atapi[0x8A7565B0] -> IRP_MJ_CREATE -> 0x8A7454F0
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A74533B
user != kernel MBR !!!
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 15:51:24.01 ===============
Merged posts. ~ OB
This post has been edited by Orange Blossom: 26 April 2011 - 05:22 PM

Help
This topic is locked


Back to top












