![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#81 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Ohhhhhhhhhhh - you mean just do the gmer bit? lolol! I watched the whole vid and didn't understand what you said above. Yes I will undertake the gmer bit and come back shortly lol!
Ruth |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#82 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,329
OS: N/A
|
Lol...Gmer isall that's needed.
Run Gmer again & right click on the entry Service C:\WINDOWS\System32:18467 (*** hidden *** ) [SYSTEM] pe386 <-- ROOTKIT !!! Select 'Delete the Service' & agree to the prompts given Then reboot your machine & do another Gmer scan. Let me know if it's still there.
__________________
Question - what have you done for the community today? |
|
|
|
|
#83 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Haha! - you have to be gentle with me hehe!
Anyhow, I did what you and the vid said, re-ran the gmer scan (again I unselected the registry box) and the log is here: - ________________________________________________________________ GMER 1.0.10.10122 - http://www.gmer.net Rootkit 2006-06-19 16:31:56 Windows 5.1.2600 Service Pack 2 ---- System - GMER 1.0.10 ---- SSDT 855EE1F8 ZwConnectPort SSDT SSI.SYS ZwCreateKey SSDT SSI.SYS ZwCreateProcess SSDT SSI.SYS ZwCreateProcessEx SSDT SSI.SYS ZwDeleteKey SSDT SSI.SYS ZwDeleteValueKey SSDT 854FACF8 ZwOpenProcess SSDT 8550B400 ZwOpenThread SSDT SSI.SYS ZwRenameKey SSDT SSI.SYS ZwSetInformationKey SSDT SSI.SYS ZwSetValueKey ---- Devices - GMER 1.0.10 ---- Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSEIRP_MJ_READ [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_WRITE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSEIRP_MJ_READ [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSEIRP_MJ_READ [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_WRITE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_PNP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_PNP_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSEIRP_MJ_READ [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_PNP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_PNP_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_NAMED_PIPE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSEIRP_MJ_READ [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_WRITE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FLUSH_BUFFERS [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DIRECTORY_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FILE_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SHUTDOWN [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_LOCK_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_MAILSLOT [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CHANGE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_PNP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_PNP_POWER [F74BE1F8] SSI.SYS ---- Files - GMER 1.0.10 ---- File D:\System Volume Information\MountPointManagerRemoteDatabase File D:\System Volume Information\tracking.log File E:\System Volume Information\MountPointManagerRemoteDatabase File E:\System Volume Information\tracking.log File E:\System Volume Information\_restore{9C9ECE3F-D8F8-4C8A-BB40-13E01E1F18B5} ---- EOF - GMER 1.0.10 ---- ________________________________________________________________ So what does this all mean? Ruth |
|
|
|
|
#84 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,329
OS: N/A
|
Congratulations. Looks like you have successfully deleted the rootkit service.
Let's go after the hidden file. It may still be present Start HijackThis & Go to Config> Misc Tools > Open ADS Spy
PS..the entry looks like this C:\WINDOWS\System32:18467
__________________
Question - what have you done for the community today? |
|
|
|
|
#86 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,329
OS: N/A
|
Fix those. These are Alternate Data Streams. It allows files to be embedded within other files/folders, riding piggy back on it. You cant see these files with Windows. In my opinion, that makes all/any of them undesirable.
Please run a full Gmer scan & tell me if the BSODs persist.
__________________
Question - what have you done for the community today? |
|
|
|
|
#87 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Ok!!!!!!!!!!!!!! Deleted those 2 entries, rebooted and re-ran a full gmer scan with all areas checked, including the Registry and hey-presto it did not bomb with a BSOD hehe!! - Well done sUBs - you are now winning this battle lol!
Just on completion of the scan a box popped up saying Rootkit activity was detected. Here is the log: - ________________________________________________________________ GMER 1.0.10.10122 - http://www.gmer.net Rootkit 2006-06-19 17:19:42 Windows 5.1.2600 Service Pack 2 ---- System - GMER 1.0.10 ---- SSDT 863CCC70 ZwConnectPort SSDT SSI.SYS ZwCreateKey SSDT SSI.SYS ZwCreateProcess SSDT SSI.SYS ZwCreateProcessEx SSDT SSI.SYS ZwDeleteKey SSDT SSI.SYS ZwDeleteValueKey SSDT 861769B0 ZwOpenProcess SSDT 863F49E8 ZwOpenThread SSDT SSI.SYS ZwRenameKey SSDT SSI.SYS ZwSetInformationKey SSDT SSI.SYS ZwSetValueKey ---- Devices - GMER 1.0.10 ---- Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSEIRP_MJ_READ [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_WRITE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSEIRP_MJ_READ [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSEIRP_MJ_READ [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_WRITE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_PNP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\Udp IRP_MJ_PNP_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSEIRP_MJ_READ [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_PNP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\RawIp IRP_MJ_PNP_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_NAMED_PIPE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSEIRP_MJ_READ [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_WRITE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_EA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FLUSH_BUFFERS [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_VOLUME_INFORMATION [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DIRECTORY_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FILE_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SHUTDOWN [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_LOCK_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_MAILSLOT [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_SECURITY [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_POWER [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SYSTEM_CONTROL [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CHANGE [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_QUOTA [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_PNP [F74BE1F8] SSI.SYS Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_PNP_POWER [F74BE1F8] SSI.SYS ---- Modules - GMER 1.0.10 ---- Module \SystemRoot\system32\drivers\kmixer.sys (*** hidden *** ) B8786000 <-- ROOTKIT !!! ---- Files - GMER 1.0.10 ---- File D:\System Volume Information\MountPointManagerRemoteDatabase File D:\System Volume Information\tracking.log File E:\System Volume Information\MountPointManagerRemoteDatabase File E:\System Volume Information\tracking.log File E:\System Volume Information\_restore{9C9ECE3F-D8F8-4C8A-BB40-13E01E1F18B5} ---- EOF - GMER 1.0.10 ---- ________________________________________________________________ Please tell me where we are at the moment by way of update, I know you know where we are but I don't! lol! Ruth XXX Last edited by ruthy; 06-19-2006 at 10:30 AM. |
|
|
|
|
#89 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,329
OS: N/A
|
C:\Windows\system32\drivers\kmixer.sys is a valid Windows file.
That looks like a false positive. Let's test it by subjecting it to a comprehensive scan. Please visit this website - http://virusscan.jotti.org Submit the file for a comprehensive scan & then post the results back here.
__________________
Question - what have you done for the community today? |
|
|
|
|
#90 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Ok sUBs - did that the results are here: -
_______________________________________________________________ Service load: 0% 100% File: kmixer.sys Status: OK MD5 d93cad07c5683db066b0b2d2d3790ead Packers detected: - Scanner results AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing UNA Found nothing VirusBuster Found nothing VBA32 Found nothing ________________________________________________________________ Please update me now as to where we are in the whole process please Ruth |
|
|
|
|
#91 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,329
OS: N/A
|
It's legit then. No worry then.
Plug this machine to the router & let me know if the earlier symptoms persist.
__________________
Question - what have you done for the community today? |
|
|
|
|
#92 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
OK - Plugged it in 8 mins ago and so far so good! I'm now going to have some tea and see if the problems continue. I will report back within the hour. Could you please summarise though what you think caused these problems and say how they were encountered. Were the BSOD's as a direct result of the Rootkit activity? What will happen do you think once I start to update Windows once more? - do you think the Rootkit Activity had something to do with blocking this activity? Updating windows is all I need to do now to update my machine back to it's former glory!
I will wait for your thoughts before I have tea. Ruth XXX |
|
|
|
|
#93 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,329
OS: N/A
|
pe386 is a relative new rootkit infection. Not much is known about it yet. Someone probably used this machine to visit those sites & unwittingly got it infected.
It's creates a rookited malware driver to hides it's presence from the Windows API. It's highly probable that this driver causes conflicts within Windows & this has led to those BSODs. Now that it's gone, it's improbable that Windows Update would pose any issues.
__________________
Question - what have you done for the community today? |
|
|
|
|
#94 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Well it looks like all bad things have come to an end - no more BSOD's and Windows finally updated fully. No more emails being sent - just wish we could learn more about this thing. Anything further to add sUBs? - I need to do my chores around 19.30 though.
Ruth XXXXX |
|
|
|
|
#95 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,329
OS: N/A
|
Kindly follow these simple steps in order to keep your computer clean and secure:
Update all these programs regularly. Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released. Follow this list and your potential for being infected again will reduce dramatically. Here are some additional utilities that will further enhance your safety.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein After doing all these, your system will be optimised against future threats. It's okay to delete the Hijack This folder in a couple weeks if everything is working okay. Have a safe & happy computing day. ![]() Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Question - what have you done for the community today? |
|
|
|
|
#96 (permalink) |
|
Registered User
Join Date: Jun 2006
Posts: 72
OS: XP Pro (SP2)
|
Thanks for everything guys - especially you sUBs - you,ve been terrific and I think I have learned a great deal too. During the next few days I will be sending you a donation so you can carry on this marvellous work. Just one thing - this is the first post on this thread using my own pc!! lol
Many many many thanks again Ruth XXXXX |
|
|
| Thread Tools | |
|
|