Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google redirect - haven't found anything that can remove it


  • Please log in to reply
3 replies to this topic

#1 thecomputerplace0

thecomputerplace0

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:22 AM

Posted 15 November 2011 - 10:37 PM

Hello, i'm a computer tech, and usually pretty good at removing viruses, but this one has me stumped.
It appears to be rootkit of some kind (a zero access i think) that is causing google redirects on this PC.
I've scanned it with combofix, bitdefender remotely, GMER (which removed what it said was a zero access rootkit), and Hitman Pro. Combofix initially deleted a few files but currently comes out clean.
I've tried running TDSSkiller, but that or avast's awr rootkit scanner just won't run no matter what i do. I've tried those from safe mode, after running Rkill, and from safe mode- command prompt, which has solved this kind of issue for me in the past. In this case though, i cannot seem to get this infection removed.
Can you provide some advice on where to go next with this?

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:22 AM

Posted 15 November 2011 - 11:38 PM

Hello you will need to repost as it does appear to be a ZA rootkit.

Having run ComboFix we need to see that and a DDS log.

Please go here....
Preparation Guide ,do steps 6 - 9.

Create a DDS log and post it in the new topic explained in step 9 which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
Skip the GMER step and instead post the ComboFix log you posted earlier.

Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 thecomputerplace0

thecomputerplace0
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:22 AM

Posted 16 November 2011 - 02:16 PM

Hi boopme - thank you for the reply.
I will go through steps 6-9 on this but i was able to get the rootkit removed i believe. Redirecting has ceased.
I got TDSSkiller to run by downloading it anew from another pc and renaming it to abc.com BEFORE moving it to the infected PC, whereas i think i had moved it before and then renamed it.
Here are the logs from TDSSkiller:
I'll post the results of 6-9 in a bit here:
Thanks again

10:00:43.0046 0992 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50
10:00:43.0437 0992 ============================================================
10:00:43.0437 0992 Current date / time: 2011/11/16 10:00:43.0437
10:00:43.0437 0992 SystemInfo:
10:00:43.0437 0992
10:00:43.0437 0992 OS Version: 5.1.2600 ServicePack: 2.0
10:00:43.0437 0992 Product type: Workstation
10:00:43.0437 0992 ComputerName: CLERK2
10:00:43.0437 0992 UserName: Administrator
10:00:43.0437 0992 Windows directory: C:\WINDOWS
10:00:43.0437 0992 System windows directory: C:\WINDOWS
10:00:43.0437 0992 Processor architecture: Intel x86
10:00:43.0437 0992 Number of processors: 2
10:00:43.0437 0992 Page size: 0x1000
10:00:43.0437 0992 Boot type: Safe boot with network
10:00:43.0437 0992 ============================================================
10:00:44.0562 0992 Initialize success
10:00:45.0531 1024 ============================================================
10:00:45.0531 1024 Scan started
10:00:45.0531 1024 Mode: Manual;
10:00:45.0531 1024 ============================================================
10:00:46.0687 1024 Abiosdsk - ok
10:00:46.0734 1024 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
10:00:46.0734 1024 abp480n5 - ok
10:00:46.0781 1024 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:00:46.0781 1024 ACPI - ok
10:00:46.0812 1024 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
10:00:46.0812 1024 ACPIEC - ok
10:00:46.0859 1024 ADIHdAudAddService (307f5e03b02a3022d664c36d1ea25f2c) C:\WINDOWS\system32\drivers\ADIHdAud.sys
10:00:46.0859 1024 ADIHdAudAddService - ok
10:00:46.0921 1024 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
10:00:46.0921 1024 adpu160m - ok
10:00:46.0953 1024 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys
10:00:46.0953 1024 aec - ok
10:00:46.0984 1024 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINDOWS\System32\drivers\afd.sys
10:00:46.0984 1024 AFD - ok
10:00:47.0000 1024 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys
10:00:47.0000 1024 agp440 - ok
10:00:47.0015 1024 agpCPQ (67288b07d6aba6c1267b626e67bc56fd) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
10:00:47.0015 1024 agpCPQ - ok
10:00:47.0046 1024 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
10:00:47.0046 1024 Aha154x - ok
10:00:47.0078 1024 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
10:00:47.0078 1024 aic78u2 - ok
10:00:47.0109 1024 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
10:00:47.0109 1024 aic78xx - ok
10:00:47.0140 1024 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
10:00:47.0140 1024 AliIde - ok
10:00:47.0156 1024 alim1541 (f312b7cef21eff52fa23056b9d815fad) C:\WINDOWS\system32\DRIVERS\alim1541.sys
10:00:47.0156 1024 alim1541 - ok
10:00:47.0171 1024 amdagp (675c16a3c1f8482f85ee4a97fc0dde3d) C:\WINDOWS\system32\DRIVERS\amdagp.sys
10:00:47.0171 1024 amdagp - ok
10:00:47.0187 1024 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
10:00:47.0203 1024 amsint - ok
10:00:47.0218 1024 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
10:00:47.0218 1024 asc - ok
10:00:47.0234 1024 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
10:00:47.0234 1024 asc3350p - ok
10:00:47.0265 1024 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
10:00:47.0265 1024 asc3550 - ok
10:00:47.0343 1024 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:00:47.0343 1024 AsyncMac - ok
10:00:47.0390 1024 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
10:00:47.0390 1024 atapi - ok
10:00:47.0390 1024 Atdisk - ok
10:00:47.0437 1024 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:00:47.0453 1024 Atmarpc - ok
10:00:47.0484 1024 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
10:00:47.0484 1024 audstub - ok
10:00:47.0531 1024 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
10:00:47.0531 1024 Beep - ok
10:00:47.0593 1024 BrPar (2fe6d5be0629f706197b30c0aa05de30) C:\WINDOWS\System32\drivers\BrPar.sys
10:00:47.0593 1024 BrPar - ok
10:00:47.0703 1024 catchme - ok
10:00:47.0734 1024 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
10:00:47.0734 1024 cbidf - ok
10:00:47.0750 1024 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
10:00:47.0750 1024 cbidf2k - ok
10:00:47.0765 1024 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
10:00:47.0781 1024 cd20xrnt - ok
10:00:47.0812 1024 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
10:00:47.0812 1024 Cdaudio - ok
10:00:47.0828 1024 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
10:00:47.0828 1024 Cdfs - ok
10:00:47.0859 1024 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:00:47.0859 1024 Cdrom - ok
10:00:47.0906 1024 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys
10:00:47.0906 1024 cercsr6 - ok
10:00:47.0906 1024 Changer - ok
10:00:47.0968 1024 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
10:00:47.0968 1024 CmdIde - ok
10:00:48.0015 1024 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
10:00:48.0015 1024 Cpqarray - ok
10:00:48.0062 1024 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
10:00:48.0062 1024 dac2w2k - ok
10:00:48.0078 1024 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
10:00:48.0078 1024 dac960nt - ok
10:00:48.0125 1024 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
10:00:48.0125 1024 Disk - ok
10:00:48.0203 1024 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
10:00:48.0218 1024 dmboot - ok
10:00:48.0234 1024 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\DRIVERS\dmio.sys
10:00:48.0234 1024 dmio - ok
10:00:48.0250 1024 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
10:00:48.0265 1024 dmload - ok
10:00:48.0312 1024 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
10:00:48.0312 1024 DMusic - ok
10:00:48.0359 1024 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
10:00:48.0359 1024 dpti2o - ok
10:00:48.0375 1024 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
10:00:48.0390 1024 drmkaud - ok
10:00:48.0406 1024 e1kexpress (d60759140694150360bbefd9cab7c920) C:\WINDOWS\system32\DRIVERS\e1k5132.sys
10:00:48.0406 1024 e1kexpress - ok
10:00:48.0500 1024 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
10:00:48.0500 1024 Fastfat - ok
10:00:48.0546 1024 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys
10:00:48.0546 1024 Fdc - ok
10:00:48.0593 1024 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
10:00:48.0593 1024 Fips - ok
10:00:48.0609 1024 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys
10:00:48.0609 1024 Flpydisk - ok
10:00:48.0656 1024 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
10:00:48.0656 1024 FltMgr - ok
10:00:48.0687 1024 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:00:48.0687 1024 Fs_Rec - ok
10:00:48.0718 1024 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:00:48.0718 1024 Ftdisk - ok
10:00:48.0750 1024 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:00:48.0750 1024 Gpc - ok
10:00:48.0765 1024 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
10:00:48.0765 1024 HDAudBus - ok
10:00:48.0812 1024 HECI (88a67c34e37186665e916fd347b50d19) C:\WINDOWS\system32\DRIVERS\HECI.sys
10:00:48.0812 1024 HECI - ok
10:00:48.0859 1024 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:00:48.0859 1024 hidusb - ok
10:00:48.0921 1024 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
10:00:48.0921 1024 hpn - ok
10:00:48.0953 1024 HTTP (c19b522a9ae0bbc3293397f3055e80a1) C:\WINDOWS\system32\Drivers\HTTP.sys
10:00:48.0953 1024 HTTP - ok
10:00:49.0000 1024 i2omgmt (8f09f91b5c91363b77bcd15599570f2c) C:\WINDOWS\system32\drivers\i2omgmt.sys
10:00:49.0000 1024 i2omgmt - ok
10:00:49.0046 1024 i2omp (ed6bf9e441fdea13292a6d30a64a24c3) C:\WINDOWS\system32\DRIVERS\i2omp.sys
10:00:49.0046 1024 i2omp - ok
10:00:49.0203 1024 ialm (9acb03875cfe068d5cc0e98fb2cf7017) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
10:00:49.0312 1024 ialm - ok
10:00:49.0343 1024 iaStor (294110966cedd127629c5be48367c8cf) C:\WINDOWS\system32\drivers\iaStor.sys
10:00:49.0343 1024 iaStor - ok
10:00:49.0390 1024 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
10:00:49.0390 1024 Imapi - ok
10:00:49.0437 1024 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
10:00:49.0453 1024 ini910u - ok
10:00:49.0484 1024 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys
10:00:49.0484 1024 IntelIde - ok
10:00:49.0531 1024 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys
10:00:49.0531 1024 intelppm - ok
10:00:49.0562 1024 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
10:00:49.0562 1024 Ip6Fw - ok
10:00:49.0593 1024 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:00:49.0593 1024 IpFilterDriver - ok
10:00:49.0625 1024 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:00:49.0625 1024 IpInIp - ok
10:00:49.0640 1024 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:00:49.0640 1024 IpNat - ok
10:00:49.0687 1024 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:00:49.0687 1024 IPSec - ok
10:00:49.0734 1024 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
10:00:49.0734 1024 IRENUM - ok
10:00:49.0765 1024 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:00:49.0765 1024 isapnp - ok
10:00:49.0812 1024 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:00:49.0812 1024 Kbdclass - ok
10:00:49.0859 1024 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
10:00:49.0859 1024 kbdhid - ok
10:00:49.0906 1024 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys
10:00:49.0906 1024 kmixer - ok
10:00:49.0921 1024 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys
10:00:49.0937 1024 KSecDD - ok
10:00:49.0953 1024 lbrtfdc - ok
10:00:50.0109 1024 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\RaInfo.sys
10:00:50.0125 1024 LMIInfo - ok
10:00:50.0156 1024 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys
10:00:50.0156 1024 lmimirr - ok
10:00:50.0171 1024 LMIRfsClientNP - ok
10:00:50.0187 1024 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
10:00:50.0187 1024 LMIRfsDriver - ok
10:00:50.0234 1024 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
10:00:50.0234 1024 mnmdd - ok
10:00:50.0296 1024 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
10:00:50.0296 1024 Modem - ok
10:00:50.0328 1024 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:00:50.0343 1024 Mouclass - ok
10:00:50.0359 1024 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:00:50.0359 1024 mouhid - ok
10:00:50.0375 1024 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
10:00:50.0375 1024 MountMgr - ok
10:00:50.0421 1024 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
10:00:50.0421 1024 mraid35x - ok
10:00:50.0421 1024 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:00:50.0437 1024 MRxDAV - ok
10:00:50.0468 1024 MRxSmb (1fd607fc67f7f7c633c3da65bfc53d18) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:00:50.0468 1024 MRxSmb - ok
10:00:50.0500 1024 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
10:00:50.0500 1024 Msfs - ok
10:00:50.0546 1024 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:00:50.0546 1024 MSKSSRV - ok
10:00:50.0578 1024 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:00:50.0578 1024 MSPCLOCK - ok
10:00:50.0609 1024 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
10:00:50.0609 1024 MSPQM - ok
10:00:50.0640 1024 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:00:50.0640 1024 mssmbios - ok
10:00:50.0656 1024 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
10:00:50.0656 1024 Mup - ok
10:00:50.0703 1024 NAL (03ca886ba148b6b9996be1368ddc3fc0) C:\WINDOWS\system32\Drivers\iqvw32.sys
10:00:50.0703 1024 NAL - ok
10:00:50.0734 1024 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
10:00:50.0734 1024 NDIS - ok
10:00:50.0750 1024 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:00:50.0750 1024 NdisTapi - ok
10:00:50.0796 1024 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:00:50.0796 1024 Ndisuio - ok
10:00:50.0796 1024 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:00:50.0796 1024 NdisWan - ok
10:00:50.0843 1024 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
10:00:50.0843 1024 NDProxy - ok
10:00:50.0890 1024 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
10:00:50.0890 1024 NetBIOS - ok
10:00:50.0906 1024 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
10:00:50.0906 1024 NetBT - ok
10:00:50.0968 1024 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
10:00:50.0968 1024 Npfs - ok
10:00:51.0015 1024 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys
10:00:51.0015 1024 Ntfs - ok
10:00:51.0078 1024 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
10:00:51.0078 1024 Null - ok
10:00:51.0109 1024 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:00:51.0109 1024 NwlnkFlt - ok
10:00:51.0125 1024 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:00:51.0125 1024 NwlnkFwd - ok
10:00:51.0171 1024 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys
10:00:51.0171 1024 Parport - ok
10:00:51.0203 1024 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
10:00:51.0203 1024 PartMgr - ok
10:00:51.0234 1024 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
10:00:51.0234 1024 ParVdm - ok
10:00:51.0250 1024 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
10:00:51.0250 1024 PCI - ok
10:00:51.0265 1024 PCIDump - ok
10:00:51.0281 1024 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
10:00:51.0281 1024 PCIIde - ok
10:00:51.0343 1024 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys
10:00:51.0343 1024 Pcmcia - ok
10:00:51.0359 1024 PDCOMP - ok
10:00:51.0375 1024 PDFRAME - ok
10:00:51.0406 1024 PDRELI - ok
10:00:51.0421 1024 PDRFRAME - ok
10:00:51.0453 1024 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
10:00:51.0453 1024 perc2 - ok
10:00:51.0468 1024 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
10:00:51.0484 1024 perc2hib - ok
10:00:51.0546 1024 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:00:51.0546 1024 PptpMiniport - ok
10:00:51.0562 1024 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
10:00:51.0562 1024 PSched - ok
10:00:51.0593 1024 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:00:51.0593 1024 Ptilink - ok
10:00:51.0625 1024 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\WINDOWS\system32\Drivers\PxHelp20.sys
10:00:51.0625 1024 PxHelp20 - ok
10:00:51.0671 1024 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
10:00:51.0671 1024 ql1080 - ok
10:00:51.0687 1024 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
10:00:51.0687 1024 Ql10wnt - ok
10:00:51.0703 1024 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
10:00:51.0718 1024 ql12160 - ok
10:00:51.0734 1024 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
10:00:51.0734 1024 ql1240 - ok
10:00:51.0765 1024 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
10:00:51.0765 1024 ql1280 - ok
10:00:51.0812 1024 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:00:51.0812 1024 RasAcd - ok
10:00:51.0859 1024 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:00:51.0859 1024 Rasl2tp - ok
10:00:51.0875 1024 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:00:51.0875 1024 RasPppoe - ok
10:00:51.0906 1024 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
10:00:51.0906 1024 Raspti - ok
10:00:51.0937 1024 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:00:51.0953 1024 Rdbss - ok
10:00:51.0984 1024 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:00:51.0984 1024 RDPCDD - ok
10:00:52.0031 1024 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
10:00:52.0031 1024 rdpdr - ok
10:00:52.0062 1024 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys
10:00:52.0062 1024 RDPWD - ok
10:00:52.0078 1024 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
10:00:52.0078 1024 redbook - ok
10:00:52.0171 1024 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:00:52.0171 1024 Secdrv - ok
10:00:52.0203 1024 Serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
10:00:52.0203 1024 Serenum - ok
10:00:52.0203 1024 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys
10:00:52.0218 1024 Serial - ok
10:00:52.0281 1024 SFAUDIO (b6401608579b6431994425ba7653f774) C:\WINDOWS\system32\drivers\sfaudio.sys
10:00:52.0281 1024 SFAUDIO - ok
10:00:52.0296 1024 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
10:00:52.0296 1024 Sfloppy - ok
10:00:52.0328 1024 Simbad - ok
10:00:52.0359 1024 sisagp (732d859b286da692119f286b21a2a114) C:\WINDOWS\system32\DRIVERS\sisagp.sys
10:00:52.0359 1024 sisagp - ok
10:00:52.0390 1024 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
10:00:52.0390 1024 Sparrow - ok
10:00:52.0421 1024 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys
10:00:52.0421 1024 splitter - ok
10:00:52.0453 1024 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
10:00:52.0453 1024 sr - ok
10:00:52.0515 1024 Srv (20b7e396720353e4117d64d9dcb926ca) C:\WINDOWS\system32\DRIVERS\srv.sys
10:00:52.0515 1024 Srv - ok
10:00:52.0562 1024 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
10:00:52.0562 1024 swenum - ok
10:00:52.0593 1024 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
10:00:52.0593 1024 swmidi - ok
10:00:52.0625 1024 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
10:00:52.0625 1024 symc810 - ok
10:00:52.0640 1024 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
10:00:52.0640 1024 symc8xx - ok
10:00:52.0687 1024 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
10:00:52.0687 1024 sym_hi - ok
10:00:52.0718 1024 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
10:00:52.0718 1024 sym_u3 - ok
10:00:52.0734 1024 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
10:00:52.0734 1024 sysaudio - ok
10:00:52.0781 1024 Tcpip (9f4b36614a0fc234525ba224957de55c) C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:00:52.0781 1024 Tcpip - ok
10:00:52.0812 1024 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
10:00:52.0812 1024 TDPIPE - ok
10:00:52.0843 1024 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
10:00:52.0843 1024 TDTCP - ok
10:00:52.0875 1024 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
10:00:52.0875 1024 TermDD - ok
10:00:52.0921 1024 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
10:00:52.0921 1024 TosIde - ok
10:00:52.0968 1024 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
10:00:52.0968 1024 Udfs - ok
10:00:52.0984 1024 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
10:00:52.0984 1024 ultra - ok
10:00:53.0015 1024 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys
10:00:53.0015 1024 Update - ok
10:00:53.0078 1024 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:00:53.0078 1024 usbccgp - ok
10:00:53.0109 1024 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:00:53.0109 1024 usbehci - ok
10:00:53.0140 1024 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:00:53.0140 1024 usbhub - ok
10:00:53.0171 1024 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:00:53.0171 1024 USBSTOR - ok
10:00:53.0203 1024 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:00:53.0203 1024 usbuhci - ok
10:00:53.0250 1024 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
10:00:53.0250 1024 VgaSave - ok
10:00:53.0281 1024 viaagp (d92e7c8a30cfd14d8e15b5f7f032151b) C:\WINDOWS\system32\DRIVERS\viaagp.sys
10:00:53.0281 1024 viaagp - ok
10:00:53.0296 1024 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys
10:00:53.0296 1024 ViaIde - ok
10:00:53.0328 1024 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
10:00:53.0328 1024 VolSnap - ok
10:00:53.0390 1024 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:00:53.0390 1024 Wanarp - ok
10:00:53.0390 1024 WDICA - ok
10:00:53.0437 1024 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys
10:00:53.0437 1024 wdmaud - ok
10:00:53.0546 1024 WmiAcpi (ae2c8544e747c20062db27456ea2d67a) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
10:00:53.0546 1024 WmiAcpi - ok
10:00:53.0640 1024 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
10:00:53.0656 1024 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - infected
10:00:53.0656 1024 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.b (0)
10:00:53.0671 1024 MBR (0x1B8) (671b81004fdd1588fa9ed1331c9ceca9) \Device\Harddisk1\DR4
10:00:54.0281 1024 \Device\Harddisk1\DR4 - ok
10:00:54.0312 1024 Boot (0x1200) (d21742e65540500d57af2221a35e7482) \Device\Harddisk0\DR0\Partition0
10:00:54.0312 1024 \Device\Harddisk0\DR0\Partition0 - ok
10:00:54.0328 1024 Boot (0x1200) (70f6239f2bac3ab57fa78a9259233a45) \Device\Harddisk1\DR4\Partition0
10:00:54.0328 1024 \Device\Harddisk1\DR4\Partition0 - ok
10:00:54.0328 1024 ============================================================
10:00:54.0328 1024 Scan finished
10:00:54.0328 1024 ============================================================
10:00:54.0359 1008 Detected object count: 1
10:00:54.0359 1008 Actual detected object count: 1
10:00:58.0937 1008 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - will be cured on reboot
10:00:58.0937 1008 \Device\Harddisk0\DR0 - ok
10:00:58.0937 1008 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - User select action: Cure
10:01:03.0250 0988 Deinitialize success

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:22 AM

Posted 16 November 2011 - 04:31 PM

That does look like a fix... It was a Boot kit..
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users