Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Making sure that I'm clear of a gasfky rootkit


  • Please log in to reply
3 replies to this topic

#1 Cactaco

Cactaco

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:01 AM

Posted 05 October 2009 - 08:05 PM

Yesterday I got infected with a gasfky rootkit (on a computer with Windows XP Professional, Version 2002, Service Pack 3), and while I seem to be clear, I was hoping to get some advice on any further steps I might take to be completely sure. The first thing I managed to get rid of was a file named either gasfkyvyevmpfn.sys or gasfkyivkboyot.sys, which I detected and deleted using Rootkit Detective. However, this program couldn't get rid of a few registry keys, so I ran MBAM, which detected and apparently managed to clean a few more files. Since then I have ran 2 MBAM scans, and both have come up clean. To get an idea of what I was dealing with, here is the MBAM log from right before I cleaned the files:

Malwarebytes' Anti-Malware 1.41
Database version: 2907
Windows 5.1.2600 Service Pack 3

10/5/2009 12:29:02 AM
mbam-log-2009-10-05 (00-29-02).txt

Scan type: Full Scan (C:\|)
Objects scanned: 170084
Time elapsed: 43 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gasfkyivkboyot (Rootkit.TDSS) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\drivers\gasfkyvyevmpfn.sys.REN (Rootkit.TDSS) -> Quarantined and deleted successfully.



And here are the registry keys that Rootkit Detective was showing (these no longer appear after I ran MBAM):

Object-Type: Registry-key
Object-Name: modules.REN.REN.REN.RENCONTROL
Object-Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gasfkyivkboyot\modules.REN.REN.REN.REN
Status: Hidden

Object-Type: Registry-key
Object-Name: modules.REN.REN.REN.REN.RENes\gasfkyivkboyot\modules.REN.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gasfkyivkboyot\modules.REN.REN.REN.REN.REN
Status: Hidden

Object-Type: Registry-key
Object-Name: modules.REN.REN.REN.RENrvices\sptd\Cfg\0D79C293C1ED61418462E24595C90D04.REN.REN\00000001.REN
Object-Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\gasfkyivkboyot\modules.REN.REN.REN.REN
Status: Hidden

Object-Type: Registry-key
Object-Name: modules.REN.REN.REN.REN.RENes\gasfkyivkboyot\modules.REN.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\gasfkyivkboyot\modules.REN.REN.REN.REN.REN
Status: Hidden

Object-Type: Registry-key
Object-Name: modules.REN.REN.REN.RENrvices\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gasfkyivkboyot\modules.REN.REN.REN.REN
Status: Hidden

Object-Type: Registry-key
Object-Name: modules.REN.REN.REN.REN.RENes\gasfkyivkboyot\modules.REN.REN.REN.REN
Object-Path: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gasfkyivkboyot\modules.REN.REN.REN.REN.REN
Status: Hidden


I'm really not familiar with this sort of thing, and since I understand that these can be really sneaky I'd appreciate any tips on what else I can do to be 100% sure that this thing is gone. Thanks in advance to anyone who can help me out with this.

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,323 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:06:01 AM

Posted 05 October 2009 - 08:18 PM

Hi,let's take another look with RootRepeal.
[*]Download RootRepeal from the following location and save it to your desktop.[*]Extract RootRepeal.exe from the archive (If you did not use the "Direct Download" mirror).
[*]Open Posted Image on your desktop.
[*]Click the Posted Image tab.
[*]Click the Posted Image button.
[*]Check all seven boxes: Posted Image
[*]Push Ok
[*]Check the box for your main system drive (Usually C:), and press Ok.
[*]Allow RootRepeal to run a scan of your system. This may take some time.
[*]Once the scan completes, push the Posted Image button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
[/list]
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Cactaco

Cactaco
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:06:01 AM

Posted 05 October 2009 - 10:50 PM

I appreciate your help, boopme, but unfortunately right before I did what you suggested I suffered a catastrophic system meltdown which ended up with me just formatting my C: drive and reinstalling Windows. Is there any chance that I'm still infected? Should I go through a process to make sure that I'm not just in case?


EDIT: Just in case, here is a RootRepeal log from my current install:

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/06 01:51
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF5E51000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7D45000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF1F7A000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\HIBERFIL.SYS
Status: Locked to the Windows API!

Path: C:\WINDOWS\INF\oem5.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\INF\oem5.PNF
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\Temp\HTT8D55.TMP
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\HTT8D7F.TMP
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\NOD8D80.TMP
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\NOD8D81.TMP
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Howard\Desktop\settings.dat
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB898461.cat
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\sp3_nt5inf.cat
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem5.CAT
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\susdl.rq0
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\download
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\smartnav.htm
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\fp40ext.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\xptht29w.htm
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\nettun.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\pclxl.gpd
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\ramdisk.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\odbcconf.rsp
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\netbeac.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\oeaccess.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\netrndis.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\dtcntwks.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\hidbth.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\bthprint.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\bthspp.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\tdibth.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\bth.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\mdmbtmdm.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msdxmlc.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt040d.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0419.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt040e.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0404.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\gpkrsrc.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\filelist.xml
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0414.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt041d.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0410.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0407.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0413.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt040c.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0415.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0408.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0406.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0405.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0416.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0816.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0411.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt041f.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0401.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0412.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0804.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\tcptsat.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wdma_via.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt040b.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agt0c0a.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\comntwks.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\medctrro.cmd
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\ttyres.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\atv06nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\agtctl15.tlb
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\adv01nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\adv02nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\adv05nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\adv09nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\adv08nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\adv11nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wdma_ali.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\adv07nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\obepopc.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\ch7xxnt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\sl_anet.acm
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\atv01nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\atv10nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\xptht38w.htm
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\siint5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\atv02nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\obemtllc.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\vchnt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\xptht40w.htm
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\migism.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\drvmain.sdb
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\odbcji32.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\atv04nt5.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\viaide.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\error.js
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\obelog.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\fpmmcsat.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msgslang.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wmp.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\l3codeca.acm
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msaud32.acm
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\evtgprov.mof
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\mscpx32r.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msaddsr.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msorc32r.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\sqlxmlx.rll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msadcor.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\odbcp32r.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msadcfr.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\asferror.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\cliconfg.rll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wmiapres.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msdatsrc.tlb
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\simpdata.tlb
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msdaprsr.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msdaremr.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\dsprpres.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msader15.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\sqloledb.rll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msado21.tlb
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msdasqlr.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msadcer.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msdaorar.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wmp.ocx
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msado20.tlb
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\ep9res.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\mshtmler.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\browselc.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\sqlsrv32.rll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msprivs.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msado25.tlb
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msado26.tlb
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\spgrmr.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msado27.tlb
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\odbcint.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\inetres.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wmm2res2.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wmm2eres.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\i2omp.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\perm2.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\mstee.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\mspqm.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wceusbsh.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\sonyait.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\dlttape.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\4mmdat.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\ltotape.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\swenum.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\avcstrm.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\intelide.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\drmkaud.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\mspclock.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\qmgr.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\ccdecode.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\perm3.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdno1.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\qic157.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\gameenum.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\framebuf.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdfi1.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\bdasup.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdmlt48.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdmlt47.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\mstape.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wmerror.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\nscirda.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdinbe1.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdukx.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\xpsp1res.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdinmal.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\slip.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\cfgmgr32.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdmaori.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdsmsno.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdsmsfi.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\vga.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\61883.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\odexl32.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msvcrt40.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\msafd.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\oddbse32.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\odpdx32.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\odfox32.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\odtext32.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\spra0424.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\fpexedll.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\avc.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\spra041b.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\moricons.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\icmp.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\tdc.ocx
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wab32res.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\fxsres.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wmi.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\dpnlobby.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\kbdinben.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\dpnaddr.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wstcodec.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\cmbatt.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\usbintel.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\mdmirmdm.inf
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\sonydcam.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\ndisip.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\gckernel.sys
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\wmpcd.dll
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\mpe.sys
Status: Visible to the Windows API, but not on disk.

P==EOF==

Edited by Cactaco, 06 October 2009 - 01:04 AM.


#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,323 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:06:01 AM

Posted 06 October 2009 - 09:11 AM

Hello,Not an unwise decision to make. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. Wiping your drive, reformatting, and performing a clean install of the OS or doing a factory restore removes everything and is the safest action.

Reformatting a hard disk deletes all data. If you decide to reformat, you can back up all your important documents, data files and photos. The safest practice is not to backup any autorun.ini or .exe files because they may be infected. Some types of malware may disguise itself by adding and hiding its extension to the existing extension of files so be sure you take a close look at the full name. After reformatting, as a precaution, make sure you scan these files with your anti-virus prior to copying them back to your hard drive.

The best proceedure is a low level format. This completely wipes the drive. Then reinstall the OS.
Use the free version of Active@ KillDisk.
Or Darik's Boot And Nuke

The best sources of Information on this are
Reformatting Windows XP
Michael Stevens Tech

I see no evidence of the rootkit in the log.

Edited by boopme, 06 October 2009 - 09:12 AM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users