Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Possible bug/virus

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Possible bug/virus
Reply
 
Thread Tools
Old 04-11-2009, 15:54   #16
Aragorn
Inactive
 
Aragorn's Avatar
 
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 60
Posts: 3,458
Aragorn has a nice shiny star
Aragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny star
Re: Possible bug/virus

Quote:
Originally Posted by tabatha View Post
Deleted ..clicked the wrong button....

Can download again if needed..

Can I do a "system restore"...go back about a week...??

Thanks for your help..
It would probably be best to download again.
Whilst a system restore might help, I would have though a rootkit capable of sticking itself in the restore directory as well.
Maybe run the GMER tool, save/post the log, do a restore and run GMER again?
Aragorn is offline   Reply With Quote
Advertisement
Old 04-11-2009, 17:11   #17
tabatha
Inactive
 
Join Date: Jun 2003
Location: winchester
Posts: 465
tabatha is a name known to alltabatha is a name known to alltabatha is a name known to alltabatha is a name known to alltabatha is a name known to alltabatha is a name known to alltabatha is a name known to alltabatha is a name known to all
Re: Possible bug/virus

Quote:
Originally Posted by Aragorn View Post
It would probably be best to download again.
Whilst a system restore might help, I would have though a rootkit capable of sticking itself in the restore directory as well.
Maybe run the GMER tool, save/post the log, do a restore and run GMER again?
Thanks...will do it later this evening, then post it here before trying a restore..



---------- Post added at 16:11 ---------- Previous post was at 14:58 ----------

I hope this is the correct log...I am a total newbie to this...



GMER 1.0.15.15163 - http://www.gmer.net
Rootkit scan 2009-11-04 16:06:02
Windows 5.1.2600 Service Pack 2
Running: ew81ik0q.exe; Driver: C:\DOCUME~1\WINDOW~1\LOCALS~1\Temp\kgtoipog.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB1C8D6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB1C8D574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB1C8DA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB1C8D14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB1C8D64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB1C8D08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB1C8D0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB1C8D76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB1C8D72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB1C8D8AE]

---- Kernel code sections - GMER 1.0.15 ----

.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF74B0380]

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[592] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[592] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\atapi \Device\Ide\IdePort0 [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdePort1 [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-18 [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-20 [F74A39F2] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xfc]}

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

---- Files - GMER 1.0.15 ----

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

---- EOF - GMER 1.0.15 ----
tabatha is offline   Reply With Quote
Old 04-11-2009, 17:19   #18
Aragorn
Inactive
 
Aragorn's Avatar
 
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 60
Posts: 3,458
Aragorn has a nice shiny star
Aragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny star
Re: Possible bug/virus

Quote:
C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section
That's the nasty - going by other threads on Bleeping Computers.

Go with the restore point / rescan plan.
If that doesn't work, a repair install from CD may do the trick, but try the restore first.
Aragorn is offline   Reply With Quote
Old 04-11-2009, 17:43   #19
tabatha
Inactive
 
Join Date: Jun 2003
Location: winchester
Posts: 465
tabatha is a name known to alltabatha is a name known to alltabatha is a name known to alltabatha is a name known to alltabatha is a name known to alltabatha is a name known to alltabatha is a name known to alltabatha is a name known to all
Re: Possible bug/virus

Quote:
Originally Posted by Aragorn View Post
That's the nasty - going by other threads on Bleeping Computers.

Go with the restore point / rescan plan.
If that doesn't work, a repair install from CD may do the trick, but try the restore first.
Thanks again...Will restore about 1 week back
tabatha is offline   Reply With Quote
Old 04-11-2009, 17:51   #20
Aragorn
Inactive
 
Aragorn's Avatar
 
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 60
Posts: 3,458
Aragorn has a nice shiny star
Aragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny star
Re: Possible bug/virus

Btw, looking at the GMER page, right clicking on the offending item in the screen should offer the option to fix it.
Might be worth trying first.
Aragorn is offline   Reply With Quote
Old 05-11-2009, 16:18   #21
Aragorn
Inactive
 
Aragorn's Avatar
 
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 60
Posts: 3,458
Aragorn has a nice shiny star
Aragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny star
Re: Possible bug/virus

How did you get on?
Aragorn is offline   Reply With Quote
Old 21-05-2010, 19:27   #22
inspectorweb
Inactive
 
Join Date: May 2010
Posts: 1
inspectorweb is an unknown quantity at this point
Re: Possible bug/virus

My suggestion. Download and install AnVir Task Manager. It also has free version. AnVir shows you all startup programs and Windows processes, so you’ll find harmful file within one minute. I always use it when I clean my PC. Sorry for the offtopic
inspectorweb is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 21:37.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum