Possible Rootkit Prob


What are those symptoms of? Date: 5/30/2009 11:13 AM Size: 14.23 KB C:\WINDOWS\Prefetch\GOOGLEUPDATE.EXE-228FD862.pf: Description: Hidden from Windows API.

Rootkit Virus Removal

  1. Date: 5/29/2009 1:08 AM Size: 628 bytesC:\Documents and Settings\LTUSER\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\ADSAdClient31[1].htm: Description: Hidden from Windows API.
  3. C:\Documents and Settings\LTUSER\Local Settings\Application Data\Mozilla\Firefox\Profiles\y5got11x.default\Cache\80895887d01 5/28/2009 7:13 PM 155.79 KB Hidden from Windows API.
  4. C:\Documents and Settings\LTUSER\Local Settings\Application Data\Mozilla\Firefox\Profiles\y5got11x.default\Cache\64EB149Bd01 5/28/2009 7:13 PM 29.22 KB Hidden from Windows API.

C:\Documents and Settings\LTUSER\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2009-04-27 (23-32-35).txt 4/27/2009 11:32 PM 943 bytes Visible in Windows API, but not in MFT or directory index. Web CureIt log file: RegUBP2b-LTUSER.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.; .mp3;C:\Documents and Settings\LTUSER\Shared;Trojan.WMALoader;Cured.; A0191163.reg;C:\System Volume Information\_restore{408C6063-2FDB-45E0-91D3-CA78E7AA88DD}\RP958;Trojan.StartPage.1505;Deleted.; A0191192.reg;C:\System Volume Information\_restore{408C6063-2FDB-45E0-91D3-CA78E7AA88DD}\RP958;Trojan.StartPage.1505;Deleted.; RootKit Revealer Log as of latest scan: HKU\S-1-5-21-682003330-861567501-725345543-1003\Console:

Rootkit Virus Symptoms

C:\Documents and Settings\LTUSER\Desktop\.torrent :Zone.Identifier 11/19/2008 1:38 AM 26 bytes Hidden from Windows API. Is there specific symptoms to look for?

HKLM\SECURITY\Policy\Secrets\SAC* 6/8/2006 11:51 PM 0 bytes Key name contains embedded nulls (*) HKLM\SECURITY\Policy\Secrets\SAI* 6/8/2006 11:51 PM 0 bytes Key name contains embedded nulls (*) HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed 5/28/2009 7:06 PM 80 bytes Data HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 3/9/2008 1:17 PM 0 bytes Access is denied.

Date: 5/29/2009 1:03 AM Size: 3.31 KBC:\Documents and Settings\LTUSER\Local Settings\Temporary Internet Files\Content.IE5\MT6P2FST\videoByTag[5].xml: Description: Hidden from Windows API.

Does your ex-girlfriend have the skills to do this or do you think she hired someone? The computer hangs at shutdown, the system tray does not fully load and the the desktop freezes. Date: 11/19/2008 1:38 AM Size: 26 bytes C:\Documents and Settings\LTUSER\Desktop\

