Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with a fake Windows Security Center and Trojans


  • This topic is locked This topic is locked
2 replies to this topic

#1 bcamp85

bcamp85

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:11:49 PM

Posted 11 December 2009 - 10:27 PM

This is very annoying. I get popups that I am infected with various Trojans from Security Center Alerts and get prompted to download "AntiMalware". All help is greatly appreciated. Thanks


DDS (Ver_09-12-01.01) - NTFSx86
Run by US30211 at 22:00:19.42 on Fri 12/11/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3050.2007 [GMT -5:00]

AV: AntiMalware *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
FW: McAfee Host Intrusion Prevention Firewall *enabled* {2F1275E3-2F4F-43E9-944B-3F63F9BDA5F5}

============== Running Processes ===============

C:\WINDOWS\system32\ADMonitor.exe
C:\WINDOWS\system32\DTS.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\AtService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\EMSService.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\CmgShieldSvc.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Iron Mountain\Connected BackupPC\AgentService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Documents and Settings\All Users\Application Data\Rpcnet\Bin\rpcld.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rpcnet.exe
C:\Program Files\Citrix\System Monitoring\Agent\Core\rscorsvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe
C:\WINDOWS\System32\CMGShieldUI.exe
C:\WINDOWS\system32\EmsServiceHelper.exe
C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe
C:\Program Files\Iron Mountain\Connected BackupPC\Agent.exe
C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\us30211\LOCALS~1\Temp\richtx64.exe
C:\WINDOWS\GTPicThis.EXE
C:\DOCUME~1\us30211\LOCALS~1\Temp\wscsvc32.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\us30211\Application Data\AntiMalware\antimalware.exe
C:\Documents and Settings\us30211\Desktop\hijackthis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\us30211\Desktop\dds.scr

============== Pseudo HJT Report ===============

uWindow Title = Microsoft Internet Explorer provided by Grant Thornton LLP
uStart Page = hxxp://www.gtus.com/
uDefault_Page_URL = hxxp://www.gtus.com
mDefault_Page_URL = hxxp://www.gtus.com
uInternet Settings,ProxyOverride = localhost;*.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: UserZoomBHO Class: {246e2928-34b8-48d9-be73-38ba37241e5b} - c:\windows\downloaded program files\UserZoom.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\program files\mcafee\siteadvisor enterprise\McIEPlg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\program files\mcafee\siteadvisor enterprise\McIEPlg.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [richtx64.exe] c:\docume~1\us30211\locals~1\temp\richtx64.exe
uRun: [AntiMalware] "c:\program files\antimalware\antimalware.exe" -noscan
mRun: [CmgShieldUI] c:\windows\system32\CMGShieldUI.exe
mRun: [EmsService] EmsServiceHelper.exe
mRun: [McAfee Host Intrusion Prevention Tray] "c:\program files\mcafee\host intrusion prevention\FireTray.exe"
mRun: [AgentUiRunKey] "c:\program files\iron mountain\connected backuppc\Agent.exe" -ni -sss -e http://localhost:16386/
mRun: [hpbdfawep] c:\program files\hp\dfawep\bin\hpbdfawep.exe 1
mRun: [Nitro PDF Printer Monitor] "c:\program files\nitro pdf\professional\NitroPDFPrinterMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [IEMultiTab] c:\windows\system32\IEMultiTab.exe
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe"
StartupFolder: c:\docume~1\us30211\startm~1\programs\startup\gtpict~1.lnk - c:\docume~1\us30211\applic~1\microsoft\installer\{1fc6cb91-c46e-4878-a086-13dd6ccf79ee}\Icon1FC6CB91.exe
uPolicies-system: HideLogonScripts = 0 (0x0)
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-system: MaxGPOScriptWait = 600 (0x258)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\thinkpad\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0\bin\npjpi150.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: ent-xhg-ow1
Trusted Zone: gt.com\surveys
Trusted Zone: gtus.com\www
Trusted Zone: sumtotalsystems.com
Trusted Zone: sumtotalsystems.com\rm72s3
Trusted Zone: sumtotalsystems.com\stage
Trusted Zone: siteadvisor.com\www
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {0DE70C1A-5136-45F6-95DA-B81CCF0DA5B3} - hxxps://gosystemrs.fasttax.com/OCX/RIARSDocumentum.cab
DPF: {13F71666-05F2-11D2-B2F6-00A0C9A08B64} - hxxps://gosystemrs.fasttax.com/OCX/comconv.cab
DPF: {227F25BE-BCDC-11D0-BA80-0000F6181652} - hxxps://gosystemrs.fasttax.com/OCX/RSLoginModule.cab
DPF: {455182EE-8F93-11D2-BA3C-00C04F7F6533} - hxxps://gosystemrs.fasttax.com/OCX/RSTabbedList.cab
DPF: {4E330863-6A11-11D0-BFD8-006097237877} - hxxps://gosystemrs.fasttax.com/OCX/iftwclix.cab
DPF: {7B640A40-EEC1-11D2-B526-00C04F8DEE99} - hxxps://gosystemrs.fasttax.com/OCX/WebAttachments.cab
DPF: {82BFFC8C-B4BD-11D4-9908-000102053AFB} - hxxps://gosystemrs.fasttax.com/OCX/webnotifier.cab
DPF: {86B092BC-7ABA-11D4-98E7-000102053AFB} - hxxps://gosystemrs.fasttax.com/OCX/Downloader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {973EA5BE-9ED6-11D3-AB1D-00C04F7468E4} - hxxps://gosystemrs.fasttax.com/OCX/DCParse.cab
DPF: {97A90946-2984-11D3-AAE7-00C04F7468E4} - hxxps://gosystemrs.fasttax.com/OCX/frmsrc.cab
DPF: {A3DC6843-BF91-437E-95F2-13F213E8CE68} - hxxps://otis.gt.com/SWiseWeb/ScreenCapture.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D9944C1C-C6BB-4E90-8E37-55F9FFABC6B8} - hxxps://server.userzoom.com/uz/UserZoom.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor enterprise\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor enterprise\McIEPlg.dll
Notify: ATFUS - c:\windows\system32\FpWinLogonNp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: CMGShieldNP - CmgShieldNP.dll
Notify: csma_ldr - csma_ldr.dll
Notify: igfxcui - igfxdev.dll
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
mASetup: Nitro PDF Professional - cscript //B "c:\program files\nitro pdf\professional\RemoveOldAddins.vbs"

============= SERVICES / DRIVERS ===============

R0 CmgShieldCEF;CmgShieldCEF;c:\windows\system32\drivers\CMGShCEF.sys [2008-8-22 362096]
R0 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2008-3-20 342960]
R0 rskcore;Citrix System Monitoring Kernel Core;c:\windows\system32\drivers\rskcore.sys [2009-3-19 37704]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2008-5-14 19496]
R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2009-1-27 31848]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R2 ADMonitor;AD Monitor;c:\windows\system32\ADMonitor.exe [2008-10-9 106496]
R2 AgentService;AgentService;c:\program files\iron mountain\connected backuppc\AgentService.exe [2008-8-1 6600000]
R2 ATService;AuthenTec Fingerprint Service;c:\windows\system32\AtService.exe [2008-10-9 1668344]
R2 CMGShield;CMGShield;c:\windows\system32\CmgShieldSvc.exe [2008-8-22 1979752]
R2 dtsvc;Data Transfer Service;c:\windows\system32\DTS.exe [2008-10-9 98304]
R2 EMS;EMS;c:\windows\system32\EmsService.exe [2008-8-22 664936]
R2 enterceptAgent;McAfee Host Intrusion Prevention Service;c:\program files\mcafee\host intrusion prevention\FireSvc.exe [2009-3-10 1471808]
R2 FirebirdServerCSMInstance;Firebird Server - CSMInstance;c:\program files\citrix\system monitoring\agent\core\firebird\bin\fbserver.exe [2009-3-19 2732032]
R2 McAfee SiteAdvisor Enterprise Service;McAfee SiteAdvisor Enterprise Service;c:\program files\mcafee\siteadvisor enterprise\McSACore.exe [2009-8-6 222528]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-11-10 103744]
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2009-1-27 144704]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2009-1-27 54608]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2009-4-27 68416]
R2 MSSQL$GTEXPLORERSERVER;SQL Server (GTEXPLORERSERVER);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2007-2-10 29178224]
R2 rpcld;Remote Procedure Call (RPC) LD;c:\documents and settings\all users\application data\rpcnet\bin\rpcld.exe --> c:\documents and settings\all users\application data\rpcnet\bin\rpcld.exe [?]
R2 RSCorSvc;Citrix System Monitoring Agent;c:\program files\citrix\system monitoring\agent\core\rscorsvc.exe [2009-3-19 148808]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\common files\intel\privacy icon\uns\UNS.exe [2008-8-19 2058776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-2-8 24652]
R2 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\drivers\ATSwpWDF.sys [2008-11-11 482176]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2008-3-27 244368]
R3 FirehkMP;FirehkMP;c:\windows\system32\drivers\firehk.sys [2009-4-27 44680]
R3 HIPK;McAfee Inc. HIPK;c:\windows\system32\drivers\HIPK.sys [2009-4-27 110384]
R3 HIPPSK;McAfee Inc. HIPPSK;c:\windows\system32\drivers\HIPPSK.sys [2009-4-27 38200]
R3 HIPQK;McAfee Inc. HIPQK;c:\windows\system32\drivers\HIPQK.sys [2009-4-27 35584]
R3 hips;McAfee HIPSCore Service;c:\program files\mcafee\host intrusion prevention\hipscore\HIPSvc.exe [2009-4-27 34408]
R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2008-3-20 73512]
R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2008-3-20 34408]
S3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2008-8-7 3592192]
S3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2008-8-7 48640]
S3 cgondis;CGO NDIS Usermode I/O Protocol;c:\windows\system32\drivers\cgondis.sys [2008-10-21 50487]
S3 CmgShieldNP;CmgShieldNP;c:\windows\system32\CmgShieldNP.dll [2008-8-22 161128]
S3 FingerprintServer;Fingerprint Server;c:\windows\system32\FpLogonServ.exe [2008-10-9 102400]
S3 Firehk;McAfee NDIS Intermediate Filter;c:\windows\system32\drivers\firehk.sys [2009-4-27 44680]
S3 LV_Tracker;LV_Tracker;c:\windows\system32\drivers\LV_Tracker.sys [2008-8-1 45384]
S3 PWSSvc;Colligo Admin;c:\program files\colligo networks\colligo workgroup edition\PWSSvc.exe [2008-10-21 225280]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-3 14336]

=============== Created Last 30 ================

2009-12-12 01:58:30 38528 ----a-w- c:\windows\system32\HIPIS0e011a2.dll
2009-12-12 01:58:30 113 ----a-w- c:\windows\system32\api_hook_list.dat
2009-12-12 01:55:27 1024 ----a-w- C:\.rnd
2009-12-12 01:51:32 0 d-----w- c:\docume~1\us30211\applic~1\AntiMalware
2009-12-10 16:04:51 0 d-----w- c:\windows\system32\winrm
2009-12-10 16:04:45 0 dc-h--w- c:\windows\$968930Uinstall_KB968930$
2009-12-09 22:14:08 1089593 -c----w- c:\windows\system32\dllcache\ntprint.cat
2009-12-09 21:49:52 0 d-----w- c:\windows\system32\XPSViewer
2009-11-26 18:57:48 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-11-26 18:57:48 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-11-26 18:56:40 0 d-----w- c:\program files\iPod
2009-11-26 18:56:29 0 d-----w- c:\program files\iTunes
2009-11-26 18:56:29 0 d-----w- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-26 18:56:07 0 d-----w- c:\program files\Bonjour
2009-11-26 18:54:33 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-11-26 18:54:33 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll

==================== Find3M ====================

2009-12-12 02:08:38 17408 ----a-w- c:\windows\system32\rpcnetp.exe
2009-12-12 02:08:17 56680 ----a-w- c:\windows\system32\rpcnet.dll
2009-12-11 14:39:31 56680 ----a-w- c:\windows\system32\rpcnet.exe
2009-12-11 14:36:25 17408 ----a-w- c:\windows\system32\rpcnetp.dll
2009-12-09 14:27:54 1722 ----a-w- c:\windows\system32\olsnapins.dat
2009-10-21 16:45:04 33792 ----a-w- c:\windows\system32\identprv.dll
2009-10-19 18:06:40 223232 ------w- c:\windows\system32\wksprt.exe
2009-10-19 18:06:38 46080 ------w- c:\windows\system32\TSWbPrxy.exe
2009-10-19 18:06:38 36864 ----a-w- c:\windows\system32\tsgQec.dll
2009-10-19 18:06:38 12800 ------w- c:\windows\system32\wksprtPS.dll
2009-10-19 18:06:38 1033728 ----a-w- c:\windows\system32\mstsc.exe
2009-10-19 18:06:36 2689024 ----a-w- c:\windows\system32\mstscax.dll
2009-10-19 18:06:34 44544 ------w- c:\windows\system32\MsRdpWebAccess.dll
2009-10-19 18:06:34 130560 ----a-w- c:\windows\system32\aaclient.dll
2009-10-09 21:23:10 1107456 ------w- c:\windows\system32\WsmSvc.dll
2009-10-09 21:23:08 178176 ------w- c:\windows\system32\wevtfwd.dll
2009-10-09 21:22:58 368640 ------w- c:\windows\system32\WsmRes.dll
2009-10-09 21:22:56 69632 ------w- c:\windows\system32\winrs.exe
2009-10-09 21:22:52 42496 ------w- c:\windows\system32\pwrshplugin.dll
2009-10-09 19:56:20 209408 ------w- c:\windows\system32\WsmWmiPl.dll
2009-10-09 19:56:18 14848 ------w- c:\windows\system32\wsmprovhost.exe
2009-10-09 19:56:16 22528 ------w- c:\windows\system32\winrshost.exe
2009-10-09 19:56:14 25088 ------w- c:\windows\system32\winrmprov.dll
2009-10-09 19:56:10 12288 ------w- c:\windows\system32\wsmplpxy.dll
2009-10-09 19:56:08 2048 ------w- c:\windows\system32\winrsmgr.dll
2009-10-09 19:56:06 233984 ------w- c:\windows\system32\winrscmd.dll
2009-10-09 19:56:04 225280 ------w- c:\windows\system32\wsmanhttpconfig.exe
2009-10-09 19:56:04 12288 ------w- c:\windows\system32\winrssrv.dll
2009-10-09 19:56:02 139776 ------w- c:\windows\system32\WsmAuto.dll
2009-10-08 19:57:02 611328 ------w- c:\windows\system32\uiautomationcore.dll
2009-10-08 19:57:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 19:56:56 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-02 17:05:35 38320 ----a-w- c:\windows\system32\pkgmgr.dll
2009-10-02 17:05:28 36272 ----a-w- c:\windows\system32\pkgslv.exe
2009-09-17 19:35:36 35840 ----a-w- c:\windows\system32\diag2.dll
2008-10-21 12:27:56 30002 ----a-w- c:\program files\INSTALL.LOG
2008-07-30 14:36:55 32768 --sha-w- c:\windows\system32\config\systemprofile\application data\microsoft\internet explorer\userdata\index.dat
2008-07-30 15:05:01 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008073020080731\index.dat

============= FINISH: 22:01:08.76 ===============

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/12/11 22:06
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: Cdfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Address: 0xAD9BC000 Size: 63744 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: DLAIFS_M.SYS
Image Path: C:\WINDOWS\System32\DLA\DLAIFS_M.SYS
Address: 0xAA69C000 Size: 86592 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xACA2B000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79D3000 Size: 8192 File Visible: No Signed: -
Status: -

Name: Fastfat.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Address: 0xA56AC000 Size: 143744 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: Fs_Rec.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Address: 0xF79B3000 Size: 7936 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: mrxsmb.sys
Image Path: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Address: 0xAD4FB000 Size: 455296 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: rdpdr.sys
Image Path: C:\WINDOWS\system32\DRIVERS\rdpdr.sys
Address: 0xB9BC7000 Size: 196224 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA69D8000 Size: 49152 File Visible: No Signed: -
Status: -

Name: uphcleanhlp.sys
Image Path: C:\WINDOWS\system32\Drivers\uphcleanhlp.sys
Address: 0xA72A6000 Size: 8960 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\CBEAM\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\gtlogs\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\WINDOWS\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Apps\CBED\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Apps\DVDPlay\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Apps\PRDCTR\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Arabic\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Bulgarian\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Catalan\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Croatian\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Czech\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Dansk\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Deutsch\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\English\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Espanol\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Estonian\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Greek\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Hebrew\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Francais\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Magyar\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Portuguese\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Italiano\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Kazakh\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Latvian\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Lithuanian\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Nederlands\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Norsk\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Polski\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Romanian\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Russian\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Serbian\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Slovak\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Slovenian\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Suomi\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Svenska\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Turkce\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Ukrainian\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Avago-HP\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Bonjour\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iPod\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Lenovo Fingerprint Software\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Microsoft Office Communicator\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Outlook Express\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Ticks COM Add-In\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\UPHClean\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Windows Media Player\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\WinZip\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Digital Line Detect\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Grant Thornton PowerPoint Add-In\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\IDEA\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\RECYCLER\S-1-5-21-507921405-362288127-725345543-169368\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\WINDOWS\inf\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Internet Logs\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\WINDOWS\SHELLNEW\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Downloaded Program Files\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Apps\CBED\CBE\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Administrator\Templates\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\All Users\Documents\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Default User\Cookies\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Default User\Templates\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\TEMP\Cookies\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\TEMP\Templates\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\US25141\Cookies\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\US25141\Templates\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\US25428\Cookies\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\US27821\Cookies\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us29544\Cookies\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Application Data\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Cookies\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Desktop\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Favorites\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Templates\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30245\Cookies\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\DRIVERS\CONWIZ\Tools\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\DRIVERS\TPWUSB\Win32\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\DRIVERS\TPWUSB\Win64\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Arabic\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Bulgarian\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Catalan\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Croatian\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Czech\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Dansk\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Deutsch\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\English\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Espanol\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Estonian\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Greek\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Hebrew\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Francais\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Magyar\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Portuguese\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Italiano\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Kazakh\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Latvian\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Lithuanian\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Nederlands\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Norsk\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Polski\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Romanian\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Russian\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Serbian\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Slovak\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Slovenian\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Suomi\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Svenska\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Turkce\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\hp_LJ_P1005_P1500_Full_Solution_ROW\Ukrainian\Manuals\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\AClient\Data\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Avago-HP\{8aa39bfd-3a23-4d06-b2e5-d76673a1382c}\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\CentraOne\logs\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Colligo Networks\Colligo Workgroup Edition\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Common Files\LightScribe\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Intel\InfInst\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Intel\Intel Trusted Platform Module\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\InterVideo\WinDVD\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Iron Mountain\Connected BackupPC\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Java\jre1.5.0\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Lenovo\System Update\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Microsoft WSE\v3.0\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Movie Maker\Shared\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\MSXML 6.0\EULA\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Multimedia Center for Think Offerings\DLA\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\QuickTime\QTSystem\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\RIA\RS2007\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Roxio\AudioCodecCommon 9\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Synaptics\SynTP\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\ThinkVantage\PrdCtr\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\ZANTAZ\EAS Client\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\ThinkPad\TPModem\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\DivX\DivX Codec\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Grant Thornton\AuditCARE\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Grant Thornton\BAS Engagement Acceptance\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Grant Thornton\Consultation\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Grant Thornton\GAAT ACL\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Grant Thornton\VoyagerV1_03\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Grant Thornton\VoyagerV1_04\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Grant Thornton PowerPoint Add-In\Layout Templates\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\HP\HP LaserJet P1000 Series\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\IDEA\Documentation\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\RECYCLER\S-1-5-21-507921405-362288127-725345543-169368\Dc3\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\RECYCLER\S-1-5-21-507921405-362288127-725345543-169368\Dc4\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP295\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP296\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP297\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP298\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP299\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP300\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP301\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP302\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP303\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP304\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP305\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP306\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP307\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP308\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP309\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP310\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP311\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP312\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP313\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP314\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP316\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP317\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP318\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP319\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP320\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP321\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP322\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP323\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP325\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP326\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP327\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP328\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP329\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP330\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP333\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP334\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP287\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP288\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP289\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP290\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP291\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP292\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP294\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\System Volume Information\_restore{41F0CC05-D8C4-46A6-AB8A-66404797CA07}\RP315\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\WINDOWS\setupupd\temp\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\WINDOWS\java\Packages\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\WINDOWS\ServicePackFiles\i386\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Apps\CBED\Drag2Disc\x64\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Apps\CBED\Drag2Disc\x86\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\All Users\Desktop\Office 2007 Guides\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\All Users\Documents\My Music\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\All Users\Documents\My Pictures\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\All Users\Documents\My Videos\CredDB.CEF
Status: Invisible to the Windows API!

Path: c:\documents and settings\networkservice\local settings\temp\perflib_perfdata_718.dat
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\networkservice\local settings\temp\perflib_perfdata_804.dat
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\networkservice\local settings\temp\perflib_perfdata_cd0.dat
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\networkservice\local settings\temp\perflib_perfdata_e40.dat
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\networkservice\local settings\temp\perflib_perfdata_f54.dat
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: C:\Documents and Settings\US25141\Local Settings\Temporary Internet Files\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\US25428\Local Settings\Temp\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\US25428\Local Settings\Temporary Internet Files\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\US27821\Local Settings\Application Data\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\US27821\Local Settings\Temp\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\US27821\Local Settings\Temporary Internet Files\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\US27821\NetHood\My Web Sites on MSN\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us29544\Local Settings\Temp\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us29544\Local Settings\Temporary Internet Files\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Application Data\GTTemplates_Melf\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Application Data\Move Networks\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Desktop\ESP\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Desktop\Expense Reports\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Desktop\Nintendo\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Desktop\Longview\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Desktop\LSAT Review\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Local Settings\Application Data\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Local Settings\Temp\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\Local Settings\Temporary Internet Files\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30211\NetHood\My Web Sites on MSN\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\us30245\Local Settings\Temporary Internet Files\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Adobe\Reader 9.0\Reader\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Adobe\Reader 9.0\Resource\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\ATI\CIM\Config\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Avago-HP\{8aa39bfd-3a23-4d06-b2e5-d76673a1382c}\English\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Common Files\Microsoft Shared\OFFICE12\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Common Files\Microsoft Shared\Smart Tag\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Common Files\Intel\Privacy Icon\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\Iron Mountain\Connected BackupPC\jre\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\da.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\de.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\en.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\en_GB.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\es.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\fi.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\fr.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\it.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\ja.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\ko.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\nb.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\nl.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\pl.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\pt.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\pt_PT.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:\Program Files\iTunes\iTunes.Resources\ru.lproj\CredDB.CEF
Status: Invisible to the Windows API!

Path: C:SSDT
-------------------
#: 053 Function Name: NtCreateThread
Status: Hooked by "C:\WINDOWS\system32\Drivers\FireTDI.sys" at address 0xad6a0e5a

#: 263 Function Name: NtUnloadKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\uphcleanhlp.sys" at address 0xa72a66d0

==EOF==

Attached Files


Edited by bcamp85, 11 December 2009 - 10:28 PM.


BC AdBot (Login to Remove)

 


#2 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:49 AM

Posted 23 December 2009 - 11:18 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#3 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:49 AM

Posted 28 December 2009 - 07:40 AM

Due to the lack of feedback, this topic is now closed.
If you need this topic reopened, please PM a staff member and we will reopen it for you (include the address of this thread in your request). This applies to the original topic starter only. Everyone else with similar problems, please start a new topic.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users