Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

ahh stupid viruses


  • This topic is locked This topic is locked

#16
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Hmmm.. that's a new one for me. You shouldn't run more that one antivirus program and you already have avast.

Let's try a different approach. Download mwav:

http://www.mwti.net/...s/mwav/mwav.asp

Install and run it - copy and paste the report of all it finds. Also, please download AVG Anti-Rootkit Beta from here and save it to your desktop.

Double click the file to install it. Accept the licence and follow the prompts to install and reboot. After rebooting, you should see the icon for AVG Anti-Rootkit Beta on your desktop. Double click it to open the programme. You will see a window with 4 buttons at the bottom of it. Click Search For Rootkits and the programme will start a scan, you will see the progress bar moving from left to right. When the scan is complete, a small window will open alerting you to the result. If anything was found, click Save Result To File and post that in your reply.

If nothing was found, please click the Perform in-depth Search saving anything found to file as before.
  • 0

Advertisements


#17
Daniiel

Daniiel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 87 posts
I dont think ill be able to get Escan its 36mbs
Ill have to get the anti root kit on my other computer
mines going really slow
the internet got caped and the virus is using the internet alot aswell
ill have to wait becaues my parents want the internet
and there slowing it down alot also
but ill definatly get back to you tonight
if all goes well
  • 0

#18
Daniiel

Daniiel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 87 posts
heres what it says in the report
i cant upload it to the forum
but it says
C:\WINDOWS\system32:lzx32.sys,Hidden driver file

im doing an in depht scan now
i kinda think it might be fixed
my internets not loading non stop lets see if it cuts out
  • 0

#19
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Aha, we have found the problem. Use AVG AntiRootkit to remove that item. Reboot, rescan and let me know if anything is found now.
  • 0

#20
Daniiel

Daniiel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 87 posts
I deleted the thing and rebooted
then rescaned with deepscan and it didnt get anything
so far the internets perfect
rekon if its fine in 15 more minutes its fixed
do you know what the problem was?
thank you so much for your help
i wish i was old enough to own a credit card
you guys deserver a fair bit
not many people are this keen on helping others
there mostly selffish and tight
thanks you heaps
  • 0

#21
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Yes, you had a rootkit infection. Do one more scan for me. Download gmer rootkit detector from http://www.majorgeek...GMER_d5198.html

unzip it & double click the gmer.exe file

select rootkit tab & press scan

when it has finished press save & post back the log it makes.

Also see if you can complete that Panda scan now - I'd like to see what it found.

Edited by Daemon, 14 January 2007 - 07:44 AM.

  • 0

#22
Daniiel

Daniiel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 87 posts
ohhhh
i was so wraped up in the internet working i completely forgot about the panda viruses
ill get on that now
i might have to get back to you in a while though
cause itll take a while for it to scan
but ill do the gmer thing first
  • 0

#23
Daniiel

Daniiel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 87 posts
i did the scan but i couldnt find a save button anywhere so i tried fiddling with the settings but i ended up click ok and it got out of it
im scanning again now and i selected everything that says save to log in it

- - - - -- - - - - - - - - - - - - - - - - - - - - - - -

ohh i think i got it
that was pretty stupid of me i says copy
sorry

Edited by Daniiel, 14 January 2007 - 08:09 AM.

  • 0

#24
Daniiel

Daniiel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 87 posts
GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-15 00:55:17
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.12 ----

SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

---- User code sections - GMER 1.0.12 ----

.text C:\Program Files\MSN Messenger\msnmsgr.exe[1856] kernel32.dll!SetUnhandledExceptionFilter 7C84479D 5 Bytes JMP 004E12D0 C:\Program Files\MSN Messenger\MsnMsgr.Exe

---- Devices - GMER 1.0.12 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 82F99C78
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 82F99C78
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 82D4F0E8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 82D4F0E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 82F9A510
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 82F9A510
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 82F9A510
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 82F9A510
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 82F9A510
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 82F9A510
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 82F9A510
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 82F9A510
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 82F9A510
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 82F9A7C8
Device \Driver\NetBT \Device\NetBT_Tcpip_{37A0E20B-CF94-4839-8ADD-719454759C24} IRP_MJ_CREATE 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{37A0E20B-CF94-4839-8ADD-719454759C24} IRP_MJ_CLOSE 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{37A0E20B-CF94-4839-8ADD-719454759C24} IRP_MJ_DEVICE_CONTROL 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{37A0E20B-CF94-4839-8ADD-719454759C24} IRP_MJ_INTERNAL_DEVICE_CONTROL 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{37A0E20B-CF94-4839-8ADD-719454759C24} IRP_MJ_CLEANUP 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{37A0E20B-CF94-4839-8ADD-719454759C24} IRP_MJ_PNP 8298A290
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 82F9A7C8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 82F9A7C8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 82CFB230
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 82CFB230
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 82CFB230
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 82CFB230
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 82CFB230
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 82CFB230
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82CFB230
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 82CFB230
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 82CFB230
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 82CFB230
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 82CFB230
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_NAMED_PIPE 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLOSE 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_READ 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_WRITE 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_INFORMATION 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_INFORMATION 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_EA 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_EA 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FLUSH_BUFFERS 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_VOLUME_INFORMATION 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_VOLUME_INFORMATION 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DIRECTORY_CONTROL 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_FILE_SYSTEM_CONTROL 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CONTROL 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_INTERNAL_DEVICE_CONTROL 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SHUTDOWN 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_LOCK_CONTROL 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CLEANUP 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_CREATE_MAILSLOT 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_SECURITY 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_SECURITY 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_POWER 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SYSTEM_CONTROL 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_DEVICE_CHANGE 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_QUERY_QUOTA 82B58EB0
Device \FileSystem\Rdbss \Device\FsWrap IRP_MJ_SET_QUOTA 82B58EB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{3270F68D-5991-4A74-9CF2-83533B3603E0} IRP_MJ_CREATE 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{3270F68D-5991-4A74-9CF2-83533B3603E0} IRP_MJ_CLOSE 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{3270F68D-5991-4A74-9CF2-83533B3603E0} IRP_MJ_DEVICE_CONTROL 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{3270F68D-5991-4A74-9CF2-83533B3603E0} IRP_MJ_INTERNAL_DEVICE_CONTROL 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{3270F68D-5991-4A74-9CF2-83533B3603E0} IRP_MJ_CLEANUP 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{3270F68D-5991-4A74-9CF2-83533B3603E0} IRP_MJ_PNP 8298A290
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 82CFB230
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 82CFB230
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 82CFB230
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 82CFB230
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 82CFB230
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 82CFB230
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 82CFB230
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 82CFB230
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 82CFB230
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 82CFB230
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 82CFB230
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 82CFB230
Device \Driver\usbstor \Device\00000080 IRP_MJ_CREATE 82BD6EB0
Device \Driver\usbstor \Device\00000080 IRP_MJ_CLOSE 82BD6EB0
Device \Driver\usbstor \Device\00000080 IRP_MJ_READ 82BD6EB0
Device \Driver\usbstor \Device\00000080 IRP_MJ_WRITE 82BD6EB0
Device \Driver\usbstor \Device\00000080 IRP_MJ_DEVICE_CONTROL 82BD6EB0
Device \Driver\usbstor \Device\00000080 IRP_MJ_INTERNAL_DEVICE_CONTROL 82BD6EB0
Device \Driver\usbstor \Device\00000080 IRP_MJ_POWER 82BD6EB0
Device \Driver\usbstor \Device\00000080 IRP_MJ_SYSTEM_CONTROL 82BD6EB0
Device \Driver\usbstor \Device\00000080 IRP_MJ_PNP 82BD6EB0
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 8298A290
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 8298A290
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 8298A290
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 8298A290
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 8298A290
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 8298A290
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 8298A290
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 8298A290
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 8298A290
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 8298A290
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 8298A290
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 8298A290
Device \Driver\usbstor \Device\00000079 IRP_MJ_CREATE 82BD6EB0
Device \Driver\usbstor \Device\00000079 IRP_MJ_CLOSE 82BD6EB0
Device \Driver\usbstor \Device\00000079 IRP_MJ_READ 82BD6EB0
Device \Driver\usbstor \Device\00000079 IRP_MJ_WRITE 82BD6EB0
Device \Driver\usbstor \Device\00000079 IRP_MJ_DEVICE_CONTROL 82BD6EB0
Device \Driver\usbstor \Device\00000079 IRP_MJ_INTERNAL_DEVICE_CONTROL 82BD6EB0
Device \Driver\usbstor \Device\00000079 IRP_MJ_POWER 82BD6EB0
Device \Driver\usbstor \Device\00000079 IRP_MJ_SYSTEM_CONTROL 82BD6EB0
Device \Driver\usbstor \Device\00000079 IRP_MJ_PNP 82BD6EB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{4422D45B-3A4F-4F7A-A0AC-2B280BD63F57} IRP_MJ_CREATE 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{4422D45B-3A4F-4F7A-A0AC-2B280BD63F57} IRP_MJ_CLOSE 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{4422D45B-3A4F-4F7A-A0AC-2B280BD63F57} IRP_MJ_DEVICE_CONTROL 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{4422D45B-3A4F-4F7A-A0AC-2B280BD63F57} IRP_MJ_INTERNAL_DEVICE_CONTROL 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{4422D45B-3A4F-4F7A-A0AC-2B280BD63F57} IRP_MJ_CLEANUP 8298A290
Device \Driver\NetBT \Device\NetBT_Tcpip_{4422D45B-3A4F-4F7A-A0AC-2B280BD63F57} IRP_MJ_PNP 8298A290
Device \Driver\00000073 \Device\0000004e IRP_MJ_POWER [F8550F68] sptd.sys
Device \Driver\00000073 \Device\0000004e IRP_MJ_SYSTEM_CONTROL [F8565A70] sptd.sys
Device \Driver\00000073 \Device\0000004e IRP_MJ_PNP [F855E728] sptd.sys
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CREATE 82F99EB0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_CLOSE 82F99EB0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_READ 82F99EB0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_WRITE 82F99EB0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_FLUSH_BUFFERS 82F99EB0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SHUTDOWN 82F99EB0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_POWER 82F99EB0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_SYSTEM_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk0\DR0 IRP_MJ_PNP 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_CREATE 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_CLOSE 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_READ 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_WRITE 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_FLUSH_BUFFERS 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_SHUTDOWN 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_POWER 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_SYSTEM_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DR3 IRP_MJ_PNP 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_CREATE 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_CLOSE 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_READ 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_WRITE 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_FLUSH_BUFFERS 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_SHUTDOWN 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_POWER 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_SYSTEM_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 IRP_MJ_PNP 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_CREATE 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_CLOSE 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_READ 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_WRITE 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_FLUSH_BUFFERS 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_SHUTDOWN 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_POWER 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_SYSTEM_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DR4 IRP_MJ_PNP 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_CREATE 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_CLOSE 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_READ 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_WRITE 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_FLUSH_BUFFERS 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_SHUTDOWN 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_POWER 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_SYSTEM_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 IRP_MJ_PNP 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_CREATE 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_CLOSE 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_READ 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_WRITE 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_FLUSH_BUFFERS 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_SHUTDOWN 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_POWER 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_SYSTEM_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DR5 IRP_MJ_PNP 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_CREATE 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_CLOSE 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_READ 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_WRITE 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_FLUSH_BUFFERS 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_INTERNAL_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_SHUTDOWN 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_POWER 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_SYSTEM_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 IRP_MJ_PNP 82F99EB0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 82B5A0E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 82B5A0E8
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_CREATE 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_CLOSE 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_READ 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_WRITE 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_FLUSH_BUFFERS 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_INTERNAL_DEVICE_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_SHUTDOWN 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_POWER 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_SYSTEM_CONTROL 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a IRP_MJ_PNP 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DR6 IRP_MJ_CREATE 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DR6 IRP_MJ_CLOSE 82F99EB0
Device \Driver\Disk \Device\Harddisk4\DR6 IRP_MJ_READ

Edited by Daniiel, 14 January 2007 - 09:00 AM.

  • 0

#25
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
There should be a bit more, I'm interested in this section:

---- Files - GMER 1.0.12 ----

ADS................
  • 0

Advertisements


#26
Daniiel

Daniiel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 87 posts
---- Files - GMER 1.0.12 ----

ADS C:\dbghelp.dll:KAVICHS
ADS C:\Documents and Settings\Daniel\Application Data\Azureus\torrents\The Road to Reality: A Complete Guide to the Laws of the Universe[1].torrent
ADS C:\Documents and Settings\Daniel\Desktop\Games\Battlefront.lnk:KAVICHS
ADS C:\Documents and Settings\Daniel\Desktop\Games\DC_Final.lnk:KAVICHS
ADS C:\Documents and Settings\Daniel\Desktop\Games\HeliCopterGame.swf:SummaryInformation
ADS C:\Documents and Settings\Daniel\Desktop\Games\HeliCopterGame.swf:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS C:\Documents and Settings\Daniel\Desktop\Games\Worms 3D.lnk:KAVICHS
ADS C:\Documents and Settings\Daniel\Desktop\Programs\Azureus.lnk:KAVICHS
ADS C:\Documents and Settings\Daniel\Desktop\Programs\Dvd Shrink.lnk:KAVICHS
ADS C:\Documents and Settings\Daniel\Desktop\Programs\FlashFXP.lnk:KAVICHS
ADS C:\Documents and Settings\Daniel\Desktop\Programs\Mirc.lnk:KAVICHS
ADS ...

---- EOF - GMER 1.0.12 ----

is that it?
i dont know why it didnt copy before
  • 0

#27
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Yes that's it, thanks. How is the Panda scan coming along?
  • 0

#28
Daniiel

Daniiel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 87 posts
its doing pretty well
its scanned around 300 thousand files
i think my computer has almost a million
maybe less i cant really remeber
hopfully itll be done tomorow
haha and hopfully it wont keep me up all night
  • 0

#29
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
OK. Is it still running better? After the Panda scan, could you try combo fix one last time. Normally it will pick up that rootkit you had, I'm curious to see if it will run now it's gone or whether you still get that message.
  • 0

#30
Daniiel

Daniiel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 87 posts
Yeh the computers pretty much perfect
Ill leave this on over night
So ill talk to you tomorow
Im planing on falling asleep to a movie called "the sex monster"
hahah
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP