Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Rootkit, Winsock Error, Redirected Searches, Task Bar color change  (Read 13620 times)

0 Members and 1 Guest are viewing this topic.

telegra1

    Topic Starter


    Rookie

    Re: Rootkit, Winsock Error, Redirected Searches, Task Bar color change
    « Reply #15 on: June 08, 2010, 09:16:48 PM »
    Here is the RootRepeal Log.

    ROOTREPEAL (c) AD, 2007-2009
    ==================================================
    Scan Start Time:      2010/06/08 20:16
    Program Version:      Version 1.3.5.0
    Windows Version:      Windows XP SP3
    ==================================================

    Drivers
    -------------------
    Name: ACPI.sys
    Image Path: ACPI.sys
    Address: 0xF75A8000   Size: 187776   File Visible: -   Signed: Yes
    Status: -

    Name: ACPI_HAL
    Image Path: \Driver\ACPI_HAL
    Address: 0x804D7000   Size: 2260992   File Visible: -   Signed: Yes
    Status: -

    Name: afd.sys
    Image Path: C:\WINDOWS\System32\drivers\afd.sys
    Address: 0xB6A40000   Size: 138496   File Visible: -   Signed: Yes
    Status: -

    Name: ASACPI.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\ASACPI.sys
    Address: 0xF79C5000   Size: 5152   File Visible: -   Signed: Yes
    Status: -

    Name: atapi.sys
    Image Path: atapi.sys
    Address: 0xF749A000   Size: 96512   File Visible: -   Signed: Yes
    Status: -

    Name: ati2cqag.dll
    Image Path: C:\WINDOWS\System32\ati2cqag.dll
    Address: 0xBF065000   Size: 626688   File Visible: -   Signed: Yes
    Status: -

    Name: ati2dvag.dll
    Image Path: C:\WINDOWS\System32\ati2dvag.dll
    Address: 0xBF012000   Size: 339968   File Visible: -   Signed: Yes
    Status: -

    Name: ati2mtag.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
    Address: 0xB8F4B000   Size: 3891200   File Visible: -   Signed: Yes
    Status: -

    Name: ati3duag.dll
    Image Path: C:\WINDOWS\System32\ati3duag.dll
    Address: 0xBF1CD000   Size: 3821568   File Visible: -   Signed: Yes
    Status: -

    Name: atikvmag.dll
    Image Path: C:\WINDOWS\System32\atikvmag.dll
    Address: 0xBF0FE000   Size: 540672   File Visible: -   Signed: Yes
    Status: -

    Name: atiok3x2.dll
    Image Path: C:\WINDOWS\System32\atiok3x2.dll
    Address: 0xBF182000   Size: 307200   File Visible: -   Signed: Yes
    Status: -

    Name: ativvaxx.dll
    Image Path: C:\WINDOWS\System32\ativvaxx.dll
    Address: 0xBF572000   Size: 2670592   File Visible: -   Signed: Yes
    Status: -

    Name: ATMFD.DLL
    Image Path: C:\WINDOWS\System32\ATMFD.DLL
    Address: 0xBFFA0000   Size: 286720   File Visible: -   Signed: Yes
    Status: -

    Name: audstub.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\audstub.sys
    Address: 0xF7A68000   Size: 3072   File Visible: -   Signed: Yes
    Status: -

    Name: Beep.SYS
    Image Path: C:\WINDOWS\System32\Drivers\Beep.SYS
    Address: 0xF79D7000   Size: 4224   File Visible: -   Signed: Yes
    Status: -

    Name: BOOTVID.dll
    Image Path: C:\WINDOWS\system32\BOOTVID.dll
    Address: 0xF7897000   Size: 12288   File Visible: -   Signed: Yes
    Status: -

    Name: Cdfs.SYS
    Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS
    Address: 0xF7517000   Size: 63744   File Visible: -   Signed: Yes
    Status: -

    Name: cdrom.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\cdrom.sys
    Address: 0xF76A7000   Size: 62976   File Visible: -   Signed: Yes
    Status: -

    Name: CLASSPNP.SYS
    Image Path: C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    Address: 0xF7637000   Size: 53248   File Visible: -   Signed: Yes
    Status: -

    Name: cmdguard.sys
    Image Path: C:\WINDOWS\System32\DRIVERS\cmdguard.sys
    Address: 0xB6B64000   Size: 222208   File Visible: -   Signed: Yes
    Status: -

    Name: cmdhlp.sys
    Image Path: C:\WINDOWS\System32\DRIVERS\cmdhlp.sys
    Address: 0xF777F000   Size: 18304   File Visible: -   Signed: Yes
    Status: -

    Name: disk.sys
    Image Path: disk.sys
    Address: 0xF7627000   Size: 36352   File Visible: -   Signed: Yes
    Status: -

    Name: dmio.sys
    Image Path: dmio.sys
    Address: 0xF74B2000   Size: 153344   File Visible: -   Signed: Yes
    Status: -

    Name: dmload.sys
    Image Path: dmload.sys
    Address: 0xF798D000   Size: 5888   File Visible: -   Signed: Yes
    Status: -

    Name: drmk.sys
    Image Path: C:\WINDOWS\system32\drivers\drmk.sys
    Address: 0xF7507000   Size: 61440   File Visible: -   Signed: Yes
    Status: -

    Name: Dxapi.sys
    Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys
    Address: 0xB6BAF000   Size: 12288   File Visible: -   Signed: Yes
    Status: -

    Name: dxg.sys
    Image Path: C:\WINDOWS\System32\drivers\dxg.sys
    Address: 0xBF000000   Size: 73728   File Visible: -   Signed: Yes
    Status: -

    Name: dxgthk.sys
    Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys
    Address: 0xB651D000   Size: 4096   File Visible: -   Signed: Yes
    Status: -

    Name: fdc.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\fdc.sys
    Address: 0xF77F7000   Size: 27392   File Visible: -   Signed: Yes
    Status: -

    Name: Fips.SYS
    Image Path: C:\WINDOWS\System32\Drivers\Fips.SYS
    Address: 0xBA750000   Size: 44544   File Visible: -   Signed: Yes
    Status: -

    Name: flpydisk.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    Address: 0xF7757000   Size: 20480   File Visible: -   Signed: Yes
    Status: -

    Name: fltmgr.sys
    Image Path: fltmgr.sys
    Address: 0xF747A000   Size: 129792   File Visible: -   Signed: Yes
    Status: -

    Name: Fs_Rec.SYS
    Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
    Address: 0xF79D5000   Size: 7936   File Visible: -   Signed: Yes
    Status: -

    Name: ftdisk.sys
    Image Path: ftdisk.sys
    Address: 0xF74D8000   Size: 125056   File Visible: -   Signed: Yes
    Status: -

    Name: hal.dll
    Image Path: C:\WINDOWS\system32\hal.dll
    Address: 0x806FF000   Size: 134400   File Visible: -   Signed: Yes
    Status: -

    Name: HDAudBus.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
    Address: 0xB8F0F000   Size: 163840   File Visible: -   Signed: Yes
    Status: -

    Name: HdAudio.sys
    Image Path: C:\WINDOWS\system32\drivers\HdAudio.sys
    Address: 0xB6CE2000   Size: 131072   File Visible: -   Signed: Yes
    Status: -

    Name: HIDCLASS.SYS
    Image Path: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
    Address: 0xBA710000   Size: 36864   File Visible: -   Signed: Yes
    Status: -

    Name: HIDPARSE.SYS
    Image Path: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
    Address: 0xB9341000   Size: 28672   File Visible: -   Signed: Yes
    Status: -

    Name: hidusb.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\hidusb.sys
    Address: 0xB8E0D000   Size: 10368   File Visible: -   Signed: Yes
    Status: -

    Name: HTTP.sys
    Image Path: C:\WINDOWS\System32\Drivers\HTTP.sys
    Address: 0xB2D37000   Size: 265728   File Visible: -   Signed: Yes
    Status: -

    Name: i8042prt.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    Address: 0xB9D73000   Size: 52480   File Visible: -   Signed: Yes
    Status: -

    Name: imapi.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\imapi.sys
    Address: 0xF7697000   Size: 42112   File Visible: -   Signed: Yes
    Status: -

    Name: inspect.sys
    Image Path: inspect.sys
    Address: 0xF743D000   Size: 80512   File Visible: -   Signed: Yes
    Status: -

    Name: intelide.sys
    Image Path: intelide.sys
    Address: 0xF798B000   Size: 5504   File Visible: -   Signed: Yes
    Status: -

    Name: intelppm.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\intelppm.sys
    Address: 0xB9D83000   Size: 36352   File Visible: -   Signed: Yes
    Status: -

    Name: ipnat.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\ipnat.sys
    Address: 0xB6AB2000   Size: 152832   File Visible: -   Signed: Yes
    Status: -

    Name: ipsec.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\ipsec.sys
    Address: 0xB6B31000   Size: 75264   File Visible: -   Signed: Yes
    Status: -

    Name: isapnp.sys
    Image Path: isapnp.sys
    Address: 0xF75F7000   Size: 37248   File Visible: -   Signed: Yes
    Status: -

    Name: kbdclass.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    Address: 0xF77FF000   Size: 24576   File Visible: -   Signed: Yes
    Status: -

    Name: KDCOM.DLL
    Image Path: C:\WINDOWS\system32\KDCOM.DLL
    Address: 0xF7987000   Size: 8192   File Visible: -   Signed: Yes
    Status: -

    Name: kmixer.sys
    Image Path: C:\WINDOWS\system32\drivers\kmixer.sys
    Address: 0xB280B000   Size: 172416   File Visible: -   Signed: Yes
    Status: -

    Name: ks.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\ks.sys
    Address: 0xB8E7D000   Size: 143360   File Visible: -   Signed: Yes
    Status: -

    Name: KSecDD.sys
    Image Path: KSecDD.sys
    Address: 0xF7451000   Size: 92928   File Visible: -   Signed: Yes
    Status: -

    Name: lknuhst.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\lknuhst.sys
    Address: 0xBA6F6000   Size: 12032   File Visible: -   Signed: No
    Status: -

    Name: lknuhub.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\lknuhub.sys
    Address: 0xF7547000   Size: 39424   File Visible: -   Signed: No
    Status: -

    Name: mfehidk.sys
    Image Path: C:\WINDOWS\system32\drivers\mfehidk.sys
    Address: 0xB2EF1000   Size: 164672   File Visible: -   Signed: Yes
    Status: -

    Name: mferkdk.sys
    Image Path: C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys
    Address: 0xF7787000   Size: 25088   File Visible: -   Signed: Yes
    Status: -

    Name: mfetdik.sys
    Image Path: C:\WINDOWS\system32\drivers\mfetdik.sys
    Address: 0xBA780000   Size: 45376   File Visible: -   Signed: Yes
    Status: -

    Name: mnmdd.SYS
    Image Path: C:\WINDOWS\System32\Drivers\mnmdd.SYS
    Address: 0xF79D9000   Size: 4224   File Visible: -   Signed: Yes
    Status: -

    Name: mouclass.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\mouclass.sys
    Address: 0xF7817000   Size: 23040   File Visible: -   Signed: Yes
    Status: -

    Name: mouhid.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\mouhid.sys
    Address: 0xB8E09000   Size: 12160   File Visible: -   Signed: Yes
    Status: -

    Name: MountMgr.sys
    Image Path: MountMgr.sys
    Address: 0xF7607000   Size: 42368   File Visible: -   Signed: Yes
    Status: -

    Name: mrxsmb.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    Address: 0xB69A5000   Size: 455680   File Visible: -   Signed: Yes
    Status: -

    Name: Msfs.SYS
    Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS
    Address: 0xF776F000   Size: 19072   File Visible: -   Signed: Yes
    Status: -

    Name: msgpc.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\msgpc.sys
    Address: 0xF76F7000   Size: 35072   File Visible: -   Signed: Yes
    Status: -

    Name: mssmbios.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    Address: 0xBA6FA000   Size: 15488   File Visible: -   Signed: Yes
    Status: -

    Name: Mup.sys
    Image Path: Mup.sys
    Address: 0xF787D000   Size: 105344   File Visible: -   Signed: Yes
    Status: -

    Name: NDIS.SYS
    Image Path: C:\WINDOWS\System32\DRIVERS\NDIS.SYS
    Address: 0xF7410000   Size: 182656   File Visible: -   Signed: Yes
    Status: -

    Name: ndistapi.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    Address: 0xBA7C0000   Size: 10112   File Visible: -   Signed: Yes
    Status: -

    Name: ndisuio.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    Address: 0xB40DC000   Size: 14592   File Visible: -   Signed: Yes
    Status: -

    Name: ndiswan.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    Address: 0xB8E66000   Size: 91520   File Visible: -   Signed: Yes
    Status: -

    Name: NDProxy.SYS
    Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS
    Address: 0xF7557000   Size: 40576   File Visible: -   Signed: Yes
    Status: -

    Name: netbios.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\netbios.sys
    Address: 0xBA760000   Size: 34688   File Visible: -   Signed: Yes
    Status: -

    Name: netbt.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\netbt.sys
    Address: 0xB6A62000   Size: 162816   File Visible: -   Signed: Yes
    Status: -

    Name: Npfs.SYS
    Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS
    Address: 0xF7777000   Size: 30848   File Visible: -   Signed: Yes
    Status: -

    Name: Ntfs.sys
    Image Path: Ntfs.sys
    Address: 0xF7B52000   Size: 574976   File Visible: -   Signed: Yes
    Status: -

    Name: ntoskrnl.exe
    Image Path: C:\WINDOWS\system32\ntoskrnl.exe
    Address: 0x804D7000   Size: 2260992   File Visible: -   Signed: Yes
    Status: -

    Name: Null.SYS
    Image Path: C:\WINDOWS\System32\Drivers\Null.SYS
    Address: 0xF7AAE000   Size: 2944   File Visible: -   Signed: Yes
    Status: -

    Name: parport.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\parport.sys
    Address: 0xB8EA0000   Size: 80128   File Visible: -   Signed: Yes
    Status: -

    Name: PartMgr.sys
    Image Path: PartMgr.sys
    Address: 0xF770F000   Size: 19712   File Visible: -   Signed: Yes
    Status: -

    Name: ParVdm.SYS
    Image Path: C:\WINDOWS\System32\Drivers\ParVdm.SYS
    Address: 0xF79B9000   Size: 6784   File Visible: -   Signed: Yes
    Status: -

    Name: pci.sys
    Image Path: pci.sys
    Address: 0xF7597000   Size: 68224   File Visible: -   Signed: Yes
    Status: -

    Name: pciide.sys
    Image Path: pciide.sys
    Address: 0xF7A4F000   Size: 3328   File Visible: -   Signed: Yes
    Status: -

    Name: PCIIDEX.SYS
    Image Path: C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    Address: 0xF7707000   Size: 28672   File Visible: -   Signed: Yes
    Status: -

    Name: pnarp.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\pnarp.sys
    Address: 0xB66E3000   Size: 18560   File Visible: -   Signed: Yes
    Status: -

    Name: PnpManager
    Image Path: \Driver\PnpManager
    Address: 0x804D7000   Size: 2260992   File Visible: -   Signed: Yes
    Status: -

    Name: portcls.sys
    Image Path: C:\WINDOWS\system32\drivers\portcls.sys
    Address: 0xB6CBE000   Size: 147456   File Visible: -   Signed: Yes
    Status: -

    Name: psched.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\psched.sys
    Address: 0xB8E55000   Size: 69120   File Visible: -   Signed: Yes
    Status: -

    Name: ptilink.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\ptilink.sys
    Address: 0xF7807000   Size: 17792   File Visible: -   Signed: Yes
    Status: -

    Name: purendis.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\purendis.sys
    Address: 0xB66DB000   Size: 19840   File Visible: -   Signed: Yes
    Status: -

    Name: rasacd.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\rasacd.sys
    Address: 0xBA7E4000   Size: 8832   File Visible: -   Signed: Yes
    Status: -

    Name: rasl2tp.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    Address: 0xF76C7000   Size: 51328   File Visible: -   Signed: Yes
    Status: -

    Name: raspppoe.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    Address: 0xF76D7000   Size: 41472   File Visible: -   Signed: Yes
    Status: -

    Name: raspptp.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\raspptp.sys
    Address: 0xF76E7000   Size: 48384   File Visible: -   Signed: Yes
    Status: -

    Name: raspti.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\raspti.sys
    Address: 0xF780F000   Size: 16512   File Visible: -   Signed: Yes
    Status: -

    Name: RAW
    Image Path: \FileSystem\RAW
    Address: 0x804D7000   Size: 2260992   File Visible: -   Signed: Yes
    Status: -

    Name: rdbss.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\rdbss.sys
    Address: 0xB6A15000   Size: 175744   File Visible: -   Signed: Yes
    Status: -

    Name: RDPCDD.sys
    Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
    Address: 0xF79DB000   Size: 4224   File Visible: -   Signed: Yes
    Status: -

    Name: rdpdr.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\rdpdr.sys
    Address: 0xB8E25000   Size: 196224   File Visible: -   Signed: Yes
    Status: -

    Name: redbook.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\redbook.sys
    Address: 0xF76B7000   Size: 57600   File Visible: -   Signed: Yes
    Status: -

    Name: rootrepeal.sys
    Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
    Address: 0xB3622000   Size: 49152   File Visible: No   Signed: No
    Status: -

    Name: serenum.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\serenum.sys
    Address: 0xBA7C8000   Size: 15744   File Visible: -   Signed: Yes
    Status: -

    Name: serial.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\serial.sys
    Address: 0xB9D63000   Size: 64512   File Visible: -   Signed: Yes
    Status: -

    Name: sr.sys
    Image Path: sr.sys
    Address: 0xF7468000   Size: 73472   File Visible: -   Signed: Yes
    Status: -

    Name: srv.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\srv.sys
    Address: 0xB369A000   Size: 353792   File Visible: -   Signed: Yes
    Status: -

    Name: STREAM.SYS
    Image Path: C:\WINDOWS\system32\DRIVERS\STREAM.SYS
    Address: 0xBA740000   Size: 53248   File Visible: -   Signed: Yes
    Status: -

    Name: swenum.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\swenum.sys
    Address: 0xF79C7000   Size: 4352   File Visible: -   Signed: Yes
    Status: -

    Name: sysaudio.sys
    Image Path: C:\WINDOWS\system32\drivers\sysaudio.sys
    Address: 0xB3FD8000   Size: 60800   File Visible: -   Signed: Yes
    Status: -

    Name: tcpip.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\tcpip.sys
    Address: 0xB6AD8000   Size: 361600   File Visible: -   Signed: Yes
    Status: -

    Name: TDI.SYS
    Image Path: C:\WINDOWS\System32\DRIVERS\TDI.SYS
    Address: 0xF7717000   Size: 20480   File Visible: -   Signed: Yes
    Status: -

    Name: termdd.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\termdd.sys
    Address: 0xF7587000   Size: 40704   File Visible: -   Signed: Yes
    Status: -

    Name: update.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\update.sys
    Address: 0xB8D9F000   Size: 384768   File Visible: -   Signed: Yes
    Status: -

    Name: usbaudio.sys
    Image Path: C:\WINDOWS\system32\drivers\usbaudio.sys
    Address: 0xBA730000   Size: 60032   File Visible: -   Signed: Yes
    Status: -

    Name: usbccgp.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\usbccgp.sys
    Address: 0xF778F000   Size: 32128   File Visible: -   Signed: Yes
    Status: -

    Name: USBD.SYS
    Image Path: C:\WINDOWS\system32\DRIVERS\USBD.SYS
    Address: 0xF79D1000   Size: 8192   File Visible: -   Signed: Yes
    Status: -

    Name: usbehci.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\usbehci.sys
    Address: 0xF77EF000   Size: 30208   File Visible: -   Signed: Yes
    Status: -

    Name: usbhub.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\usbhub.sys
    Address: 0xBA7A0000   Size: 59520   File Visible: -   Signed: Yes
    Status: -

    Name: USBPORT.SYS
    Image Path: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
    Address: 0xB8EB4000   Size: 147456   File Visible: -   Signed: Yes
    Status: -

    Name: usbuhci.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
    Address: 0xF77E7000   Size: 20608   File Visible: -   Signed: Yes
    Status: -

    Name: vga.sys
    Image Path: C:\WINDOWS\System32\drivers\vga.sys
    Address: 0xF7767000   Size: 20992   File Visible: -   Signed: Yes
    Status: -

    Name: VIDEOPRT.SYS
    Image Path: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
    Address: 0xB8F37000   Size: 81920   File Visible: -   Signed: Yes
    Status: -

    Name: VolSnap.sys
    Image Path: VolSnap.sys
    Address: 0xF7617000   Size: 52352   File Visible: -   Signed: Yes
    Status: -

    Name: VX6000Xp.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\VX6000Xp.sys
    Address: 0xB6798000   Size: 2068480   File Visible: -   Signed: Yes
    Status: -

    Name: VX6KCamd.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\VX6KCamd.sys
    Address: 0xB9349000   Size: 28672   File Visible: -   Signed: Yes
    Status: -

    Name: wanarp.sys
    Image Path: C:\WINDOWS\system32\DRIVERS\wanarp.sys
    Address: 0xBA770000   Size: 34560   File Visible: -   Signed: Yes
    Status: -

    Name: watchdog.sys
    Image Path: C:\WINDOWS\System32\watchdog.sys
    Address: 0xF7797000   Size: 20480   File Visible: -   Signed: Yes
    Status: -

    Name: wdmaud.sys
    Image Path: C:\WINDOWS\system32\drivers\wdmaud.sys
    Address: 0xB3E4B000   Size: 83072   File Visible: -   Signed: Yes
    Status: -

    Name: Win32k
    Image Path: \Driver\Win32k
    Address: 0xBF800000   Size: 1851392   File Visible: -   Signed: Yes
    Status: -

    Name: win32k.sys
    Image Path: C:\WINDOWS\System32\win32k.sys
    Address: 0xBF800000   Size: 1851392   File Visible: -   Signed: Yes
    Status: -

    Name: WMILIB.SYS
    Image Path: C:\WINDOWS\system32\DRIVERS\WMILIB.SYS
    Address: 0xF7989000   Size: 8192   File Visible: -   Signed: Yes
    Status: -

    Name: WMIxWDM
    Image Path: \Driver\WMIxWDM
    Address: 0x804D7000   Size: 2260992   File Visible: -   Signed: Yes
    Status: -



    [recovering disk space - old attachment deleted by admin]

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Rootkit, Winsock Error, Redirected Searches, Task Bar color change
    « Reply #16 on: June 09, 2010, 01:32:03 PM »
    How is your computer running now? Any more redirects?
    Windows 8 and Windows 10 dual boot with two SSD's

    telegra1

      Topic Starter


      Rookie

      Re: Rootkit, Winsock Error, Redirected Searches, Task Bar color change
      « Reply #17 on: June 09, 2010, 02:59:07 PM »
      No more redirects. Everything seems to be running fine. My gf said she had some pop ups yesterday. I wasn't home but it wasn't the fake security alerts. I have been able to update XP so overall I think I am in good shape.

      I wonder about IO Bit Advanced System Care and if it really helps or not and about switching McAfee for one of the anti virus products recommended here.

      I really appreciate your help and input, thanks.

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Rootkit, Winsock Error, Redirected Searches, Task Bar color change
      « Reply #18 on: June 09, 2010, 05:51:21 PM »
      Well, that sound good. Let's run one more scan and if that comes up clean, we'll do some clean-up. I'll have some more suggestions about how to keep your computer safe in the clean-up speech.

      I'd like us to scan your machine with ESET OnlineScan

      •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESET OnlineScan
      •Click the button.
      •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      • Click on to download the ESET Smart Installer. Save it to your desktop.
      • Double click on the icon on your desktop.
      •Check
      •Click the button.
      •Accept any security warnings from your browser.
      •Check
      •Push the Start button.
      •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      •When the scan completes, push
      •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
      •Push the button.
      •Push
      A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

      Windows 8 and Windows 10 dual boot with two SSD's

      telegra1

        Topic Starter


        Rookie

        Re: Rootkit, Winsock Error, Redirected Searches, Task Bar color change
        « Reply #19 on: June 10, 2010, 12:22:50 AM »
        Wow, 33 items found, was this expected?

        ESETSmartInstaller@High as CAB hook log:
        OnlineScanner.ocx - registred OK
        # version=7
        # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
        # OnlineScanner.ocx=1.0.0.6211
        # api_version=3.0.2
        # EOSSerial=a0d5c9e1b047ac48af0108484ba6a6e9
        # end=finished
        # remove_checked=true
        # archives_checked=true
        # unwanted_checked=true
        # unsafe_checked=false
        # antistealth_checked=true
        # utc_time=2010-06-10 05:13:14
        # local_time=2010-06-09 10:13:14 (-0800, Pacific Daylight Time)
        # country="United States"
        # lang=1033
        # osver=5.1.2600 NT Service Pack 3
        # compatibility_mode=512 16777215 100 0 4507239 4507239 0 0
        # compatibility_mode=3073 16777213 80 92 0 11094560 0 0
        # compatibility_mode=8192 67108863 100 0 0 0 0 0
        # scanned=77165
        # found=33
        # cleaned=33
        # scan_time=8895
        C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\ubxo.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\Documents and Settings\Default User\Start Menu\Programs\Startup\gyqig.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\Documents and Settings\Jon\Application Data\Kuyzwe\omzun.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\Documents and Settings\Jon\Application Data\Sun\Java\Deployment\cache\6.0\46\2ef6a5ae-29c19df4   a variant of Java/TrojanDownloader.Agent.NBE trojan (deleted - quarantined)   00000000000000000000000000000000   C
        C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\0\43120580-4af80629   a variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)   00000000000000000000000000000000   C
        C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\33\30feb821-6a642e70   a variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)   00000000000000000000000000000000   C
        C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\5473416c-2e86c9ca   a variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)   00000000000000000000000000000000   C
        C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\63\43e0867f-1c23f9a1   probably a variant of Win32/Agent trojan (deleted - quarantined)   00000000000000000000000000000000   C
        C:\Program Files\Unlocker\eBay_shortcuts_1016.exe   a variant of Win32/Adware.ADON application (deleted - quarantined)   00000000000000000000000000000000   C
        C:\Qoobox\Quarantine\C\WINDOWS\system32\mirepcmw.dll.vir   a variant of Win32/Agent.WQK trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\imapi.sys.vir   Win32/Olmarik.ZC trojan (cleaned - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP36\A0018169.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP46\A0022896.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP46\A0022906.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP48\A0026253.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP48\A0026255.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP48\A0026256.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP49\A0029852.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP49\A0029853.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP49\A0029883.dll   a variant of Win32/Agent.WQK trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0030305.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0030306.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0032444.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0032446.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0032447.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0035015.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP52\A0035016.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP55\A0036642.sys   Win32/Olmarik.ZC trojan (cleaned - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP55\A0036698.dll   a variant of Win32/Agent.WQK trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039289.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039290.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039291.exe   a variant of Win32/Kryptik.EMT trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
        C:\System Volume Information\_restore{CB71ABFF-714E-48BB-873E-6FB22EA024B9}\RP59\A0039292.exe   a variant of Win32/Adware.ADON application (deleted - quarantined)   00000000000000000000000000000000   C


        [recovering disk space - old attachment deleted by admin]

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Rootkit, Winsock Error, Redirected Searches, Task Bar color change
        « Reply #20 on: June 10, 2010, 12:54:04 PM »
        The most of these are duplicates and most were in System Restore.

        * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
        * Now type Combofix /uninstall in the runbox
        * Make sure there's a space between Combofix and /Uninstall
        * Then hit Enter

        * The above procedure will:
        * Delete the following:
        * ComboFix and its associated files and folders.
        * Reset the clock settings.
        * Hide file extensions, if required.
        * Hide System/Hidden files, if required.
        * Set a new, clean Restore Point.

        ==============================

        Download OTC by OldTimer and save it to your desktop.

        1. Double-click OTC to run it.
        2. Click the CleanUp! button.
        3. Select Yes when the "Begin cleanup Process?" prompt appears.
        4. If you are prompted to Reboot during the cleanup, select Yes
        5. OTC should delete itself once it finishes, if not delete it yourself.

        If there are any tools/programs left, install them or delete them.
        ==============================

        Clean out your temporary internet files and temp files.

        Download TFC by OldTimer to your desktop.

        Double-click TFC.exe to run it.

        Note: If you are running on Vista, right-click on the file and choose Run As Administrator

        TFC will close all programs when run, so make sure you have saved all your work before you begin.

        * Click the Start button to begin the cleaning process.
        * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
        * Please let TFC run uninterrupted until it is finished.

        Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

        =================================

        Use the Secunia Software Inspector to check for out of date software.

        •Click Start Now

        •Check the box next to Enable thorough system inspection.

        •Click Start

        •Allow the scan to finish and scroll down to see if any updates are needed.
        •Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

        SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
        Safe Surfing!
        Windows 8 and Windows 10 dual boot with two SSD's

        telegra1

          Topic Starter


          Rookie

          Re: Rootkit, Winsock Error, Redirected Searches, Task Bar color change
          « Reply #21 on: June 12, 2010, 11:19:10 PM »
          I have been away for a couple days. Just finished your last suggestions. Thank you so much. The computer is running really well and I am very happy with the results. You turned a source of frustration and anger into a workable and enjoyable experience. I learned as I went and really appreciate your help. 8)