Posted 06 December 2009 - 04:54 PM
Posted 08 December 2009 - 09:43 PM
DIR /a/s %windir%\scecli.dll %windir%\netlogon.dll %windir%\eventlog.dll >Log.txt & START notepad Log.txtA file called log.txt should be created on your Desktop.
Posted 13 December 2009 - 12:58 PM
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/12/13 11:43
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x9C16A000 Size: 49152 File Visible: No Signed: -
Status: -
Name: uphcleanhlp.sys
Image Path: C:\WINDOWS\system32\Drivers\uphcleanhlp.sys
Address: 0x9CF5E000 Size: 8960 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\RootRepeal report 12-13-09 (11-43-03).txt
Status: Visible to the Windows API, but not on disk.
Path: C:\Program Files\games\Cubis Gold\CUBISG~1.EXE:{E946BA92-FC81-0103-F8AB-DC56DE9D7B30}
Status: Visible to the Windows API, but not on disk.
Path: C:\System Volume Information\_restore{9BF7186B-B058-4A97-A90E-9052C52AB95E}\RP4\A0000606.exe:{E46DA982-DB3E-E860-A957-CA816569B878}
Status: Visible to the Windows API, but not on disk.
Path: c:\documents and settings\rebecca rogers\local settings\temp\me_imptnhmdkkluyey
Status: Allocation size mismatch (API: 4096, Raw: 0)
SSDT
-------------------
#: 263 Function Name: NtUnloadKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\uphcleanhlp.sys" at address 0x9cf5e6d0
==EOF==
Running from: C:\Documents and Settings\Rebecca Rogers\My Documents\Downloads\Win32kDiag.exe
Log file at : C:\Documents and Settings\Rebecca Rogers\Desktop\Win32kDiag.txt
WARNING: Could not get backup privileges!
Searching 'C:\WINDOWS'...
Finished!
Volume in drive C has no label.
Volume Serial Number is 4414-7101
Directory of C:\WINDOWS\system32
04/14/2008 04:42 AM 181,248 scecli.dll
Directory of C:\WINDOWS\system32
04/14/2008 04:42 AM 407,040 netlogon.dll
Directory of C:\WINDOWS\system32
04/14/2008 04:41 AM 56,320 eventlog.dll
3 File(s) 644,608 bytes
Directory of C:\WINDOWS\system32\dllcache
04/14/2008 04:42 AM 181,248 scecli.dll
Directory of C:\WINDOWS\system32\dllcache
04/14/2008 04:42 AM 407,040 netlogon.dll
Directory of C:\WINDOWS\system32\dllcache
04/14/2008 04:41 AM 56,320 eventlog.dll
3 File(s) 644,608 bytes
Total Files Listed:
6 File(s) 1,289,216 bytes
0 Dir(s) 292,153,810,944 bytes free
Posted 13 December 2009 - 07:36 PM
Posted 13 December 2009 - 11:09 PM
Orange Blossom
An ounce of prevention is worth a pound of cure
SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript0 members, 0 guests, 0 anonymous users