Repeal Scan:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/31 11:32
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
-------------------
Name: dump_diskdump.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_diskdump.sys
Address: 0xB6F25000 Size: 16384 File Visible: No Signed: -
Status: -
Name: dump_viasraid.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_viasraid.sys
Address: 0xB57A5000 Size: 77824 File Visible: No Signed: -
Status: -
Name: PCI_PNP7010
Image Path: \Driver\PCI_PNP7010
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xBA8E4000 Size: 49152 File Visible: No Signed: -
Status: -
Name: sphn.sys
Image Path: sphn.sys
Address: 0xF73DB000 Size: 1048576 File Visible: No Signed: -
Status: -
Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: C:\WINDOWS\system32\UACakklowalrw.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACbgppmysktp.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACgddpahvsvu.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\uacinit.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACjitjlntnxw.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACmjaegrrofr.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACpttokunpno.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\UACxnckyeebqg.db
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\UAC82a8.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\drivers\UACoiysrqdxgl.sys
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Khoan Quach\Local Settings\Temp\UACd771.tmp
Status: Invisible to the Windows API!
Path: c:\documents and settings\khoan quach\local settings\temp\etilqs_sfjgtukk6frb62qg2acl
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\khoan quach\local settings\temp\etilqs_wy7r5rwti1fxnjii70xb
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\khoan quach\local settings\temporary internet files\content.ie5\lio3dyxa\hp_flickr_content[1].htm
Status: Allocation size mismatch (API: 8192, Raw: 16384)
Stealth Objects
-------------------
Object: Hidden Module [Name: UAC82a8.tmpkunpno.dll]
Process: svchost.exe (PID: 920) Address: 0x10000000 Size: 217088
Object: Hidden Module [Name: UACbgppmysktp.dll]
Process: svchost.exe (PID: 920) Address: 0x009c0000 Size: 73728
Object: Hidden Module [Name: UACmjaegrrofr.dll]
Process: Explorer.EXE (PID: 1596) Address: 0x10000000 Size: 49152
Object: Hidden Module [Name: UACmjaegrrofr.dll]
Process: Iexplore.exe (PID: 4056) Address: 0x10000000 Size: 49152
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x8676b1f8 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x85ed0500 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x867db1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x867db1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x867db1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x867db1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x867db1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x867db1f8 Size: 121
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x867db1f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x865421f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x864bd1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x864bd1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x864bd1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x864bd1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x864bd1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x864bd1f8 Size: 121
Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x864bd1f8 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CREATE]
Process: System Address: 0x85f7b500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_CLOSE]
Process: System Address: 0x85f7b500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_READ]
Process: System Address: 0x85f7b500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_WRITE]
Process: System Address: 0x85f7b500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x85f7b500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x85f7b500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_POWER]
Process: System Address: 0x85f7b500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x85f7b500 Size: 121
Object: Hidden Code [Driver: USBSTOR, IRP_MJ_PNP]
Process: System Address: 0x85f7b500 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x8676d1f8 Size: 121
Object: Hidden Code [Driver: af3nyvqsȅఊ祓譐 夰, IRP_MJ_CREATE]
Process: System Address: 0x8639f1f8 Size: 121
Object: Hidden Code [Driver: af3nyvqsȅఊ祓譐 夰, IRP_MJ_CLOSE]
Process: System Address: 0x8639f1f8 Size: 121
Object: Hidden Code [Driver: af3nyvqsȅఊ祓譐 夰, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8639f1f8 Size: 121
Object: Hidden Code [Driver: af3nyvqsȅఊ祓譐 夰, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8639f1f8 Size: 121
Object: Hidden Code [Driver: af3nyvqsȅఊ祓譐 夰, IRP_MJ_POWER]
Process: System Address: 0x8639f1f8 Size: 121
Object: Hidden Code [Driver: af3nyvqsȅఊ祓譐 夰, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8639f1f8 Size: 121
Object: Hidden Code [Driver: af3nyvqsȅఊ祓譐 夰, IRP_MJ_PNP]
Process: System Address: 0x8639f1f8 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x85f65500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x85f65500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x85f65500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x85f65500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x85f65500 Size: 121
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x85f65500 Size: 121
Object: Hidden Code [Driver: viasraid, IRP_MJ_CREATE]
Process: System Address: 0x8676c1f8 Size: 121
Object: Hidden Code [Driver: viasraid, IRP_MJ_CLOSE]
Process: System Address: 0x8676c1f8 Size: 121
Object: Hidden Code [Driver: viasraid, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8676c1f8 Size: 121
Object: Hidden Code [Driver: viasraid, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8676c1f8 Size: 121
Object: Hidden Code [Driver: viasraid, IRP_MJ_POWER]
Process: System Address: 0x8676c1f8 Size: 121
Object: Hidden Code [Driver: viasraid, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8676c1f8 Size: 121
Object: Hidden Code [Driver: viasraid, IRP_MJ_PNP]
Process: System Address: 0x8676c1f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x864bb3f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x864bb3f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x864bb3f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x864bb3f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x864bb3f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x864bb3f8 Size: 121
Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x864bb3f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x85f841f8 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_CREATE]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_CLOSE]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_READ]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_SHUTDOWN]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_CLEANUP]
Process: System Address: 0x85f3a500 Size: 121
Object: Hidden Code [Driver: Cdfsȅ瑎䙦ȁ瑎䙦܂Èై, IRP_MJ_PNP]
Process: System Address: 0x85f3a500 Size: 121
Hidden Services
-------------------
Service Name: UACd.sys
Image Path: C:\WINDOWS\system32\drivers\UACoiysrqdxgl.sys
==EOF==
Malwarebytes' Anti-Malware:
Malwarebytes' Anti-Malware 1.40
Database version: 2688
Windows 5.1.2600 Service Pack 2
8/31/2009 1:21:44 PM
mbam-log-2009-08-31 (13-21-44).txt
Scan type: Quick Scan
Objects scanned: 116167
Time elapsed: 9 minute(s), 28 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot.
DDS:
DDS (Ver_09-07-30.01) - NTFSx86
Run by Khoan Quach at 13:32:23.17 on Mon 08/31/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.403 [GMT -4:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\libusbd-nt.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Malwarebytes' Anti-Malware\explorer.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Khoan Quach\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.comcast.net/
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uURLSearchHooks: H - No File
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
dRunOnce: [RunNarrator] Narrator.exe
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: wbsys.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\khoanq~1\applic~1\mozilla\firefox\profiles\a4gyu5ca.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
============= SERVICES / DRIVERS ===============
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2004-4-28 77312]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-18 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-10-18 27784]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2008-2-29 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-2-29 55024]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-10-18 297752]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R2 RVIEGVST;VSC VST Engine;c:\program files\roland\virtual sound canvas vst\RVIEg01VST.sys [2005-12-15 188276]
R3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\drivers\getnd5b.sys [2003-9-2 44032]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2009-5-4 33792]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-8-10 38160]
R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [2005-12-15 951284]
RUnknown yhkb;yhkb; [x]
S2 qdps;qdps;c:\windows\system32\drivers\eutvwthk.sys --> c:\windows\system32\drivers\eutvwthk.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-1-5 17792]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-1-5 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys --> c:\windows\system32\drivers\motport.sys [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096]
S4 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-12-13 33752]
=============== Created Last 30 ================
2009-08-29 16:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ALM
2009-08-29 14:37 230 a------- c:\windows\system32\spupdsvc.inf
2009-08-13 03:00 <DIR> --d----- c:\windows\ServicePackFiles
2009-08-10 08:54 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-10 08:54 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-10 08:54 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-09 23:50 <DIR> --d----- c:\docume~1\khoanq~1\applic~1\Antares
2009-08-09 23:50 <DIR> --d----- c:\program files\Antares Audio Technologies
2009-08-09 23:03 <DIR> --d----- c:\docume~1\khoanq~1\applic~1\Cakewalk
2009-08-09 22:56 <DIR> --d----- c:\program files\Cakewalk
2009-08-09 22:56 <DIR> --d----- C:\Cakewalk Projects
2009-08-09 22:16 21,504 ac------ c:\windows\system32\dllcache\hidserv.dll
2009-08-09 22:16 21,504 a------- c:\windows\system32\hidserv.dll
2009-08-09 19:37 <DIR> --d----- c:\windows\system32\XPSViewer
2009-08-09 19:36 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-09 19:36 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-09 19:36 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-09 19:36 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-08-09 19:36 117,760 -------- c:\windows\system32\prntvpt.dll
2009-08-09 19:36 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll
2009-08-09 19:36 <DIR> --d----- C:\b75bc5ab6ce96c097928c65b1ba5a9a7
2009-08-09 19:36 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-08-04 12:42 <DIR> --d----- c:\program files\ICCup
==================== Find3M ====================
2009-08-16 08:57 335,240 a------- c:\windows\system32\drivers\avgldx86.sys
2009-08-16 08:57 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-08-05 05:11 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-17 14:55 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-06-26 12:18 659,456 a------- c:\windows\system32\wininet.dll
2009-06-26 12:18 81,920 a------- c:\windows\system32\ieencode.dll
2009-06-16 10:55 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 10:55 82,432 a------- c:\windows\system32\fontsub.dll
2009-06-12 07:50 76,288 a------- c:\windows\system32\telnet.exe
2009-06-10 10:21 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 02:32 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-05 03:42 655,872 a------- c:\windows\system32\mstscax.dll
2009-06-03 15:27 1,290,752 a------- c:\windows\system32\quartz.dll
2008-11-17 14:14 38,040 ac------ c:\docume~1\khoanq~1\applic~1\GDIPFONTCACHEV1.DAT
2006-11-27 16:28 92,064 a------- c:\documents and settings\khoan quach\mqdmmdm.sys
2006-11-27 16:28 79,328 a------- c:\documents and settings\khoan quach\mqdmserd.sys
2006-11-27 16:28 66,656 a------- c:\documents and settings\khoan quach\mqdmbus.sys
2006-11-27 16:28 25,600 a------- c:\documents and settings\khoan quach\usbsermptxp.sys
2006-11-27 16:28 9,232 a------- c:\documents and settings\khoan quach\mqdmmdfl.sys
2006-11-27 16:28 6,208 a------- c:\documents and settings\khoan quach\mqdmcmnt.sys
2006-11-27 16:28 5,936 a------- c:\documents and settings\khoan quach\mqdmwhnt.sys
2006-11-27 16:28 4,048 a------- c:\documents and settings\khoan quach\mqdmcr.sys
2006-11-27 16:28 22,768 ac------ c:\documents and settings\khoan quach\usbsermpt.sys
2006-10-24 23:24 81,920 a------- c:\docume~1\khoanq~1\applic~1\ezpinst.exe
2006-10-24 23:24 47,360 a------- c:\docume~1\khoanq~1\applic~1\pcouffin.sys
2007-07-10 23:01 88 ---shr-- c:\windows\system32\1CC6CD6D7F.sys
2007-07-11 02:01 2,516 a--sh--- c:\windows\system32\KGyGaAvL.sys
============= FINISH: 13:33:33.01 ===============
The malware that malwarebytes finds reappears even after the reboot remove. The file I terminate to stop the audio ads is "iexplorer.exe". I don't think it's a hidden web browser because I uninstalled Internet Explorer. Also, the hits on my search engines are still being redirected.
Thanks for your consideration,
-Khoan