extremeboy,
Thank you for your response, I've been tearing my hair out on this one.
Malwarebytes is one of the AS I used previously and had 8 or so problems it found and eliminated. I ran the gmer.exe with no issues and the log is as follows:GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2009-02-06 15:43:18
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
Code 8A127110 ZwEnumerateKey
Code 8A4D9010 ZwFlushInstructionCache
Code 89F0C068 ZwQueryValueKey
Code 8A4682E6 IofCallDriver
Code 8A5BF506 IofCompleteRequest
---- Kernel code sections - GMER 1.0.14 ----
.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 8A4682EB
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 8A5BF50B
PAGE ntoskrnl.exe!ZwQueryValueKey 80573037 5 Bytes JMP 89F0C06C
PAGE ntoskrnl.exe!ZwEnumerateKey 80578E14 5 Bytes JMP 8A127114
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80587BFB 5 Bytes JMP 8A4D9014
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs InCDrec.SYS (InCD File System Recognizer/Nero AG)
---- Modules - GMER 1.0.14 ----
Module \systemroot\system32\drivers\gaopdxtykltfea.sys (*** hidden *** ) ACC46000-ACC70000 (172032 bytes)
---- Services - GMER 1.0.14 ----
Service C:\WINDOWS\system32\drivers\gaopdxtykltfea.sys (*** hidden *** ) [SYSTEM] gaopdxserv.sys <-- ROOTKIT !!!
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxtykltfea.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@userdata -1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxtykltfea.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxbdjeavrg.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxtykltfea.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@userdata -1
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxtykltfea.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxbdjeavrg.dll
---- EOF - GMER 1.0.14 ----
The MBAM log is as follows:Malwarebytes' Anti-Malware 1.33
Database version: 1714
Windows 5.1.2600 Service Pack 3
2/6/2009 3:52:47 PM
mbam-log-2009-02-06 (15-52-47).txt
Scan type: Quick Scan
Objects scanned: 59701
Time elapsed: 2 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\RECYCLER\S-2-5-81-100022668-100012205-100013168-1696.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gaopdxbdjeavrg.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\gaopdxtykltfea.sys (Trojan.Agent) -> Quarantined and deleted successfully.
I really appreciate your help on this, and if you can respond before 5 PST I will be eternally grateful.
Cheers
istbar
Edited by istbar, 06 February 2009 - 06:57 PM.