Cable Forum

Cable Forum (https://www.cableforum.uk/board/index.php)
-   Security & Virus Discussion (https://www.cableforum.uk/board/forumdisplay.php?f=38)
-   -   Possible bug/virus (https://www.cableforum.uk/board/showthread.php?t=33657549)

Aragorn 04-11-2009 15:54

Re: Possible bug/virus
 
Quote:

Originally Posted by tabatha (Post 34903533)
Deleted :dunce:..clicked the wrong button..:o:..

Can download again if needed..

Can I do a "system restore"...go back about a week...??

Thanks for your help..:)

It would probably be best to download again.
Whilst a system restore might help, I would have though a rootkit capable of sticking itself in the restore directory as well.
Maybe run the GMER tool, save/post the log, do a restore and run GMER again?

tabatha 04-11-2009 17:11

Re: Possible bug/virus
 
Quote:

Originally Posted by Aragorn (Post 34903534)
It would probably be best to download again.
Whilst a system restore might help, I would have though a rootkit capable of sticking itself in the restore directory as well.
Maybe run the GMER tool, save/post the log, do a restore and run GMER again?

Thanks...will do it later this evening, then post it here before trying a restore..

:):)

---------- Post added at 16:11 ---------- Previous post was at 14:58 ----------

I hope this is the correct log...I am a total newbie to this...:dunce:



GMER 1.0.15.15163 - http://www.gmer.net
Rootkit scan 2009-11-04 16:06:02
Windows 5.1.2600 Service Pack 2
Running: ew81ik0q.exe; Driver: C:\DOCUME~1\WINDOW~1\LOCALS~1\Temp\kgtoipog.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB1C8D6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB1C8D574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB1C8DA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB1C8D14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB1C8D64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB1C8D08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB1C8D0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB1C8D76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB1C8D72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB1C8D8AE]

---- Kernel code sections - GMER 1.0.15 ----

.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF74B0380]

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[592] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[592] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\atapi \Device\Ide\IdePort0 [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdePort1 [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

---- Files - GMER 1.0.15 ----

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

---- EOF - GMER 1.0.15 ----

Aragorn 04-11-2009 17:19

Re: Possible bug/virus
 
Quote:

C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section
That's the nasty - going by other threads on Bleeping Computers.

Go with the restore point / rescan plan.
If that doesn't work, a repair install from CD may do the trick, but try the restore first.

tabatha 04-11-2009 17:43

Re: Possible bug/virus
 
Quote:

Originally Posted by Aragorn (Post 34903574)
That's the nasty - going by other threads on Bleeping Computers.

Go with the restore point / rescan plan.
If that doesn't work, a repair install from CD may do the trick, but try the restore first.

Thanks again...Will restore about 1 week back

Aragorn 04-11-2009 17:51

Re: Possible bug/virus
 
Btw, looking at the GMER page, right clicking on the offending item in the screen should offer the option to fix it.
Might be worth trying first.

Aragorn 05-11-2009 16:18

Re: Possible bug/virus
 
How did you get on?

inspectorweb 21-05-2010 19:27

Re: Possible bug/virus
 
My suggestion. Download and install AnVir Task Manager. It also has free version. AnVir shows you all startup programs and Windows processes, so you’ll find harmful file within one minute. I always use it when I clean my PC. Sorry for the offtopic


All times are GMT +1. The time now is 22:15.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum