flying_suser
Baseband Member
- Messages
- 41
Looks like the 'str.sys' finally gone with SDfix followed by ComboFix treatment.But still I'm not happy with the CPU usage.BTW noramally at what 'update speed'(high , normal or low) one should look at the CPU usage history?
Here's the SDFix log:
SDFix: Version 1.240
Run by Administrator on Wed 02/04/2009 at 11:03 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-04 23:10:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\grkfikrol]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"\??\C:\WINDOWS\system32\drivers\khwmcm.sys"
"DisplayName"="grkfikrol"
"RulesData"=hex:03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\grkfikrol\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,..
scanning hidden registry entries ...
scanning hidden files ...
C:\WINDOWS\system32\drivers\str.sys 208928 bytes
C:\WINDOWS\system32\drivers\khwmcm.sys 31104 bytes executable
scan completed successfully
hidden processes: 0
hidden services: 1
hidden files: 2
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\ZakFromAnotherPlanet\\Yazak Chat\\iexplore.exe"="C:\\Program Files\\ZakFromAnotherPlanet\\Yazak Chat\\iexplore.exe:*:Enabled:iexplore"
"C:\\Program Files\\ABC\\abc.exe"="C:\\Program Files\\ABC\\abc.exe:*:Enabled:abc"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\ActiveState Komodo IDE 4.1\\lib\\mozilla\\komodo.exe"="C:\\Program Files\\ActiveState Komodo IDE 4.1\\lib\\mozilla\\komodo.exe:*:Enabled:ActiveState Komodo"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*isabled:Microsoft Office Outlook"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*isabledxpsp2res.dll,-22019"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabledxpsp2res.dll,-22019"
"D:\\Cytoscape_v2.6.0\\Cytoscape.exe"="D:\\Cytoscape_v2.6.0\\Cytoscape.exe:*:Enabled:Cytoscape"
"%windir%\\system32\\drivers\\svchost.exe"="%windir%\\system32\\drivers\\svchost.exe:*:Enabled:svchost"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabledxpsp2res.dll,-22019"
"%windir%\\system32\\drivers\\svchost.exe"="%windir%\\system32\\drivers\\svchost.exe:*:Enabled:svchost"
Remaining Files :
Files with Hidden Attributes :
Tue 7 Oct 2008 6,108,728 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Sun 27 Jul 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 12 Apr 2008 43,008 ...H. --- "C:\Documents and Settings\SRay\My Documents\~WRL1029.tmp"
Fri 11 Apr 2008 40,960 ...H. --- "C:\Documents and Settings\SRay\My Documents\~WRL1535.tmp"
Mon 28 Jul 2008 58,368 ...H. --- "C:\Documents and Settings\SRay\My Documents\_APPLICATION_\~WRL0001.tmp"
Tue 3 Feb 2009 58,368 ...H. --- "C:\Documents and Settings\SRay\My Documents\_APPLICATION_\~WRL0002.tmp"
Finished!
Here's the SDFix log:
SDFix: Version 1.240
Run by Administrator on Wed 02/04/2009 at 11:03 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-04 23:10:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\grkfikrol]
"Type"=dword:00000001
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"\??\C:\WINDOWS\system32\drivers\khwmcm.sys"
"DisplayName"="grkfikrol"
"RulesData"=hex:03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\grkfikrol\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,..
scanning hidden registry entries ...
scanning hidden files ...
C:\WINDOWS\system32\drivers\str.sys 208928 bytes
C:\WINDOWS\system32\drivers\khwmcm.sys 31104 bytes executable
scan completed successfully
hidden processes: 0
hidden services: 1
hidden files: 2
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\ZakFromAnotherPlanet\\Yazak Chat\\iexplore.exe"="C:\\Program Files\\ZakFromAnotherPlanet\\Yazak Chat\\iexplore.exe:*:Enabled:iexplore"
"C:\\Program Files\\ABC\\abc.exe"="C:\\Program Files\\ABC\\abc.exe:*:Enabled:abc"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\ActiveState Komodo IDE 4.1\\lib\\mozilla\\komodo.exe"="C:\\Program Files\\ActiveState Komodo IDE 4.1\\lib\\mozilla\\komodo.exe:*:Enabled:ActiveState Komodo"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*isabled:Microsoft Office Outlook"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*isabledxpsp2res.dll,-22019"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabledxpsp2res.dll,-22019"
"D:\\Cytoscape_v2.6.0\\Cytoscape.exe"="D:\\Cytoscape_v2.6.0\\Cytoscape.exe:*:Enabled:Cytoscape"
"%windir%\\system32\\drivers\\svchost.exe"="%windir%\\system32\\drivers\\svchost.exe:*:Enabled:svchost"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabledxpsp2res.dll,-22019"
"%windir%\\system32\\drivers\\svchost.exe"="%windir%\\system32\\drivers\\svchost.exe:*:Enabled:svchost"
Remaining Files :
Files with Hidden Attributes :
Tue 7 Oct 2008 6,108,728 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Sun 27 Jul 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 12 Apr 2008 43,008 ...H. --- "C:\Documents and Settings\SRay\My Documents\~WRL1029.tmp"
Fri 11 Apr 2008 40,960 ...H. --- "C:\Documents and Settings\SRay\My Documents\~WRL1535.tmp"
Mon 28 Jul 2008 58,368 ...H. --- "C:\Documents and Settings\SRay\My Documents\_APPLICATION_\~WRL0001.tmp"
Tue 3 Feb 2009 58,368 ...H. --- "C:\Documents and Settings\SRay\My Documents\_APPLICATION_\~WRL0002.tmp"
Finished!