Thank you for your help.
- I can't connect to the internet from the infected PC so I had to download the GMER from a MacBook and use a flashdrive to transfer program to PC's desktop.
- When I ran GMER the first time, at the end of the run I got a blue screen. I'm sorry that I don't remember what the message was.
- After a reboot I ran GMER, saved the log to the desktop and ported it back to the MAC. (I hope I'm not infecting the MAC.)
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-12-17 21:15:19
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.12.0
Running: xyebs763.exe; Driver: C:\Users\Eddie\AppData\Local\Temp\ugloapod.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xA02CD7A0]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x920A1640]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xA02CD8E4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xA02CD980]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 3F1 81CE4B74 4 Bytes [A0, D7, 2C, A0]
.text ntkrnlpa.exe!KeSetEvent + 621 81CE4DA4 8 Bytes [40, 16, 0A, 92, E4, D8, 2C, ...] {INC EAX; PUSH SS; OR DL, [EDX-0x5fd3271c]}
.text ntkrnlpa.exe!KeSetEvent + 681 81CE4E04 4 Bytes [80, D9, 2C, A0]
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8EE0A000, 0x263A88, 0xE8000020]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{3FB84151-2050-4DF6-9310-477A826D54AC}
Reg HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\Tcpip_{3FB84151-2050-4DF6-9310-477A826D54AC}@NameServerList ?
Reg HKLM\SYSTEM\ControlSet003\Services\NetBT\Parameters\Interfaces\Tcpip_{3FB84151-2050-4DF6-9310-477A826D54AC} (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\NetBT\Parameters\Interfaces\Tcpip_{3FB84151-2050-4DF6-9310-477A826D54AC}@NameServerList ?
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB25802$\2784911124 0 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189 0 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\@ 2048 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\bckfg.tmp 851 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\cfg.ini 208 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\keywords 413 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\kwrd.dll 223744 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\L 0 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\L\qnbwvoto 185856 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\U 0 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\U\80000000.@ 1024 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB25802$\2868891189\U\80000032.@ 98304 bytes
---- EOF - GMER 1.0.15 ----