I'm using winXP, A few days ago my avast system seemed to have caught the "virus check virus" which could only be opened in sandbox. I then had the system check pop up appear, fake scan my system and asking me to help fix the problem by purchasing a non existant cure.
Obviously I did not do that. I checked my firewall Macafee and I had several intrusions. Ran Avast scan then did an avast Reboot scan, which found only one infected file, which could not be deleted? Started to the desktop and everything had disappeared accept the start button and empy my documents folder etc,
It seems I can only connect online via in safe mode.
Found TechSpot and tried to follow the procedure that had already been outlined for others. But not as accurately as I should have. My Bad!
Ran - 1) Malwarebytes' Anti-Malware,
2) Unhide - which helped restore some files and applications
3)aswMBR.exe
4) attempted to run Combo Fix, which seems to crash while scanning, I had disabled Avast and nothing else is running, so I was at a loss. Looked at TechSpot in more detail (what I should have done in the first place) So below will be my listed logs.
Any help would be greatly appreciated. Thanks
My First Malwarebytes Scan
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.07.04
Windows XP Service Pack 3 x86 FAT32 (Safe Mode/Networking)
Internet Explorer 6.0.2900.5512
Administrator :: [administrator]
07/01/2012 23:44:19
mbam-log-2012-01-07 (23-44-19).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 313899
Time elapsed: 57 minute(s), 16 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|AWteuGLwTAOiU.exe (Rogue.FakeHDD) -> Data: C:\Documents and Settings\All Users\Application Data\AWteuGLwTAOiU.exe -> Quarantined and deleted successfully.
Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 8
C:\Documents and Settings\All Users\Application Data\AWteuGLwTAOiU.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\rvn4Uw7wiU5Dge.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
C:\Documents and Settings\wayne\Local Settings\Temp\wera0.7797335485655679.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\wayne\Application Data\Sun\Java\Deployment\cache\6.0\47\4567146f-3699d291 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\wayne\Application Data\Sun\Java\Deployment\cache\6.0\47\4567146f-785d2ed6 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Alcohol Soft\Alcohol 120\keymaker.exe (Password.Stealer) -> Quarantined and deleted successfully.
C:\Program Files\Alcohol Soft\Alcohol 120\Langs\AX_RU.dll (Malware.Packer.GenX) -> Quarantined and deleted successfully.
D:\stuff\keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
(end)
---------------------
My last Malwarebytes Scan
Database version: v2012.01.07.04
Windows XP Service Pack 3 x86 FAT32 (Safe Mode/Networking)
Internet Explorer 6.0.2900.5512
Administrator :: [administrator]
11/01/2012 19:49:45
mbam-log-2012-01-11 (19-49-45).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204486
Time elapsed: 9 minute(s), 55 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
----------------
GMER Log
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-11 20:08:12
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 IC25N060ATMR04-0 rev.MO3OAD4A
Running: 2xdyqh4m[1].exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\kxldqpob.sys
---- System - GMER 1.0.15 ----
SSDT spxl.sys ZwCreateKey [0xF87250E0]
SSDT spxl.sys ZwEnumerateKey [0xF8742CA2]
SSDT spxl.sys ZwEnumerateValueKey [0xF8743030]
SSDT spxl.sys ZwOpenKey [0xF87250C0]
SSDT spxl.sys ZwQueryKey [0xF8743108]
SSDT spxl.sys ZwQueryValueKey [0xF8742F88]
SSDT spxl.sys ZwSetValueKey [0xF874319A]
INT 0x62 ? 83373BF8
INT 0x73 ? 83333BF8
INT 0xA4 ? 83333BF8
INT 0xB4 ? 83333BF8
---- Kernel code sections - GMER 1.0.15 ----
? spxl.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F852F8AC 5 Bytes JMP 833331D8
.text anoojwv9.SYS F8121384 1 Byte [20]
.text anoojwv9.SYS F8121384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text anoojwv9.SYS F81213AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text anoojwv9.SYS F81213C4 3 Bytes [00, 00, 00]
.text anoojwv9.SYS F81213C9 1 Byte [00]
.text ...
init C:\WINDOWS\system32\Drivers\FireTDI.sys entry point in "init" section [0xF7EED000]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 833E22D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F874B6D0] spxl.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F874F708] spxl.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F8726046] spxl.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F8726142] spxl.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F87260C4] spxl.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F87267CE] spxl.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F87266A4] spxl.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 833332D8
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F8731D7A] spxl.sys
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlInitUnicodeString] 0000004C
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!swprintf] 00000095
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeSetEvent] 0000000B
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 00000042
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 000000FA
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 000000C3
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmFreeMappingAddress] 0000004E
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 00000008
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 0000002E
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmUnmapIoSpace] 000000A1
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 00000066
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IofCompleteRequest] 00000028
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 000000D9
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IofCallDriver] 00000024
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 000000B2
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 00000076
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoConnectInterrupt] 0000005B
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoDetachDevice] 000000A2
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeWaitForSingleObject] 00000049
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInitializeEvent] 0000006D
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeCancelTimer] 0000008B
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 000000D1
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlInitAnsiString] 00000025
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 00000072
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoQueueWorkItem] 000000F8
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmMapIoSpace] 000000F6
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 00000064
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoReportDetectedDevice] 00000086
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoReportResourceForDetection] 00000068
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 00000098
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!NlsMbCodePageTag] 00000016
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!PoRequestPowerIrp] 000000D4
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 000000A4
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 0000005C
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!sprintf] 000000CC
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 0000005D
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ObfDereferenceObject] 00000065
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 000000B6
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 00000092
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ZwClose] 0000006C
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 00000070
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 00000048
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 00000050
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 000000FD
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoCreateDevice] 000000ED
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 000000B9
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 000000DA
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 0000005E
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ZwOpenKey] 00000015
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 00000046
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoStartTimer] 00000057
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInitializeTimer] 000000A7
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoInitializeTimer] 0000008D
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInitializeDpc] 0000009D
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInitializeSpinLock] 00000084
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoInitializeIrp] 00000090
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ZwCreateKey] 000000D8
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 000000AB
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 00000000
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ZwSetValueKey] 0000008C
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInsertQueueDpc] 000000BC
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 000000D3
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoStartPacket] 0000000A
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 000000F7
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000E4
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoFreeMdl] 00000058
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmUnlockPages] 00000005
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 000000B8
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 000000B3
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 00000045
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 00000006
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeSynchronizeExecution] 000000D0
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoStartNextPacket] 0000002C
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeBugCheckEx] 0000001E
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 0000008F
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeSetTimer] 000000CA
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!_allmul] 0000003F
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmProbeAndLockPages] 0000000F
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!_except_handler3] 00000002
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!PoSetPowerState] 000000C1
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 000000AF
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 000000BD
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlDeleteRegistryValue] 00000003
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!_aulldiv] 00000001
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!strstr] 00000013
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!_strupr] 0000008A
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeQuerySystemTime] 0000006B
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 0000003A
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeTickCount] 00000091
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 00000011
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoDeleteDevice] 00000041
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 0000004F
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAllocateWorkItem] 00000067
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAllocateIrp] 000000DC
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAllocateMdl] 000000EA
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 00000097
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000F2
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 000000CF
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 000000CE
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ExFreePoolWithTag] 000000F0
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoFreeIrp] 000000B4
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoFreeWorkItem] 000000E6
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!InitSafeBootMode] 00000073
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlCompareMemory] 00000096
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!PoCallDriver] 000000AC
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!memmove] 00000074
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmHighestUserAddress] 00000022
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KfAcquireSpinLock] 00000034
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!READ_PORT_UCHAR] 0000008E
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KeGetCurrentIrql] 00000043
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KfRaiseIrql] 00000044
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KfLowerIrql] 000000C4
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!HalGetInterruptVector] 000000DE
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!HalTranslateBusAddress] 000000E9
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KeStallExecutionProcessor] 000000CB
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KfReleaseSpinLock] 00000054
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 0000007B
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!READ_PORT_USHORT] 00000094
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000032
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!WRITE_PORT_UCHAR] 000000A6
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[WMILIB.SYS!WmiSystemControl] 00000023
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[WMILIB.SYS!WmiCompleteRequest] 0000003D
Obviously I did not do that. I checked my firewall Macafee and I had several intrusions. Ran Avast scan then did an avast Reboot scan, which found only one infected file, which could not be deleted? Started to the desktop and everything had disappeared accept the start button and empy my documents folder etc,
It seems I can only connect online via in safe mode.
Found TechSpot and tried to follow the procedure that had already been outlined for others. But not as accurately as I should have. My Bad!
Ran - 1) Malwarebytes' Anti-Malware,
2) Unhide - which helped restore some files and applications
3)aswMBR.exe
4) attempted to run Combo Fix, which seems to crash while scanning, I had disabled Avast and nothing else is running, so I was at a loss. Looked at TechSpot in more detail (what I should have done in the first place) So below will be my listed logs.
Any help would be greatly appreciated. Thanks
My First Malwarebytes Scan
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.07.04
Windows XP Service Pack 3 x86 FAT32 (Safe Mode/Networking)
Internet Explorer 6.0.2900.5512
Administrator :: [administrator]
07/01/2012 23:44:19
mbam-log-2012-01-07 (23-44-19).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 313899
Time elapsed: 57 minute(s), 16 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|AWteuGLwTAOiU.exe (Rogue.FakeHDD) -> Data: C:\Documents and Settings\All Users\Application Data\AWteuGLwTAOiU.exe -> Quarantined and deleted successfully.
Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 8
C:\Documents and Settings\All Users\Application Data\AWteuGLwTAOiU.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\rvn4Uw7wiU5Dge.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
C:\Documents and Settings\wayne\Local Settings\Temp\wera0.7797335485655679.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\wayne\Application Data\Sun\Java\Deployment\cache\6.0\47\4567146f-3699d291 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\wayne\Application Data\Sun\Java\Deployment\cache\6.0\47\4567146f-785d2ed6 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Alcohol Soft\Alcohol 120\keymaker.exe (Password.Stealer) -> Quarantined and deleted successfully.
C:\Program Files\Alcohol Soft\Alcohol 120\Langs\AX_RU.dll (Malware.Packer.GenX) -> Quarantined and deleted successfully.
D:\stuff\keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
(end)
---------------------
My last Malwarebytes Scan
Database version: v2012.01.07.04
Windows XP Service Pack 3 x86 FAT32 (Safe Mode/Networking)
Internet Explorer 6.0.2900.5512
Administrator :: [administrator]
11/01/2012 19:49:45
mbam-log-2012-01-11 (19-49-45).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204486
Time elapsed: 9 minute(s), 55 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
----------------
GMER Log
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-11 20:08:12
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 IC25N060ATMR04-0 rev.MO3OAD4A
Running: 2xdyqh4m[1].exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\kxldqpob.sys
---- System - GMER 1.0.15 ----
SSDT spxl.sys ZwCreateKey [0xF87250E0]
SSDT spxl.sys ZwEnumerateKey [0xF8742CA2]
SSDT spxl.sys ZwEnumerateValueKey [0xF8743030]
SSDT spxl.sys ZwOpenKey [0xF87250C0]
SSDT spxl.sys ZwQueryKey [0xF8743108]
SSDT spxl.sys ZwQueryValueKey [0xF8742F88]
SSDT spxl.sys ZwSetValueKey [0xF874319A]
INT 0x62 ? 83373BF8
INT 0x73 ? 83333BF8
INT 0xA4 ? 83333BF8
INT 0xB4 ? 83333BF8
---- Kernel code sections - GMER 1.0.15 ----
? spxl.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F852F8AC 5 Bytes JMP 833331D8
.text anoojwv9.SYS F8121384 1 Byte [20]
.text anoojwv9.SYS F8121384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text anoojwv9.SYS F81213AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text anoojwv9.SYS F81213C4 3 Bytes [00, 00, 00]
.text anoojwv9.SYS F81213C9 1 Byte [00]
.text ...
init C:\WINDOWS\system32\Drivers\FireTDI.sys entry point in "init" section [0xF7EED000]
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 833E22D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F874B6D0] spxl.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F874F708] spxl.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F8726046] spxl.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F8726142] spxl.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F87260C4] spxl.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F87267CE] spxl.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F87266A4] spxl.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 833332D8
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F8731D7A] spxl.sys
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlInitUnicodeString] 0000004C
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!swprintf] 00000095
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeSetEvent] 0000000B
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 00000042
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 000000FA
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 000000C3
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmFreeMappingAddress] 0000004E
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 00000008
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 0000002E
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmUnmapIoSpace] 000000A1
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 00000066
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IofCompleteRequest] 00000028
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 000000D9
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IofCallDriver] 00000024
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 000000B2
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 00000076
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoConnectInterrupt] 0000005B
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoDetachDevice] 000000A2
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeWaitForSingleObject] 00000049
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInitializeEvent] 0000006D
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeCancelTimer] 0000008B
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 000000D1
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlInitAnsiString] 00000025
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 00000072
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoQueueWorkItem] 000000F8
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmMapIoSpace] 000000F6
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 00000064
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoReportDetectedDevice] 00000086
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoReportResourceForDetection] 00000068
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 00000098
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!NlsMbCodePageTag] 00000016
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!PoRequestPowerIrp] 000000D4
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 000000A4
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 0000005C
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!sprintf] 000000CC
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 0000005D
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ObfDereferenceObject] 00000065
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 000000B6
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 00000092
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ZwClose] 0000006C
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 00000070
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 00000048
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 00000050
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 000000FD
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoCreateDevice] 000000ED
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 000000B9
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 000000DA
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 0000005E
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ZwOpenKey] 00000015
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 00000046
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoStartTimer] 00000057
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInitializeTimer] 000000A7
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoInitializeTimer] 0000008D
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInitializeDpc] 0000009D
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInitializeSpinLock] 00000084
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoInitializeIrp] 00000090
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ZwCreateKey] 000000D8
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 000000AB
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 00000000
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ZwSetValueKey] 0000008C
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeInsertQueueDpc] 000000BC
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 000000D3
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoStartPacket] 0000000A
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 000000F7
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000E4
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoFreeMdl] 00000058
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmUnlockPages] 00000005
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 000000B8
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 000000B3
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 00000045
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 00000006
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeSynchronizeExecution] 000000D0
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoStartNextPacket] 0000002C
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeBugCheckEx] 0000001E
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 0000008F
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeSetTimer] 000000CA
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!_allmul] 0000003F
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmProbeAndLockPages] 0000000F
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!_except_handler3] 00000002
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!PoSetPowerState] 000000C1
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 000000AF
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 000000BD
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlDeleteRegistryValue] 00000003
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!_aulldiv] 00000001
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!strstr] 00000013
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!_strupr] 0000008A
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeQuerySystemTime] 0000006B
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 0000003A
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!KeTickCount] 00000091
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 00000011
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoDeleteDevice] 00000041
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 0000004F
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAllocateWorkItem] 00000067
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAllocateIrp] 000000DC
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoAllocateMdl] 000000EA
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 00000097
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000F2
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 000000CF
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 000000CE
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!ExFreePoolWithTag] 000000F0
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoFreeIrp] 000000B4
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!IoFreeWorkItem] 000000E6
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!InitSafeBootMode] 00000073
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!RtlCompareMemory] 00000096
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!PoCallDriver] 000000AC
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!memmove] 00000074
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[ntoskrnl.exe!MmHighestUserAddress] 00000022
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KfAcquireSpinLock] 00000034
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!READ_PORT_UCHAR] 0000008E
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KeGetCurrentIrql] 00000043
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KfRaiseIrql] 00000044
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KfLowerIrql] 000000C4
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!HalGetInterruptVector] 000000DE
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!HalTranslateBusAddress] 000000E9
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KeStallExecutionProcessor] 000000CB
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!KfReleaseSpinLock] 00000054
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 0000007B
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!READ_PORT_USHORT] 00000094
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000032
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[HAL.dll!WRITE_PORT_UCHAR] 000000A6
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[WMILIB.SYS!WmiSystemControl] 00000023
IAT \SystemRoot\System32\Drivers\anoojwv9.SYS[WMILIB.SYS!WmiCompleteRequest] 0000003D