Hey everyone.
I got a pretty annoying problem with a nastie, which I would like some help to get rid off.
When I sit on my computer with anything on my screen, it unhiglights everything I've highlighted after a few seconds.
I've followed the steps in the "Read ne before posting a request for assistance"-thread, and I'm going to give you the logs of all the programs.
I got an idea of what is wrong. The command csrss.exe is using my CPU everytime it happends and sometimes if I use alt-tab, then I see an icon of Internet Explorer, even thou I havent opened it. I guess that it maybe has to do with those things, but can you guys help me, please?
1. GMER log one.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-04 00:10:14
Windows 5.1.2600 Service Pack 3
Running: tqy7ysjb.exe; Driver: C:\DOCUME~1\ZREXIO~1\LOKALE~1\Temp\pgtdqpow.sys
---- System - GMER 1.0.15 ----
SSDT sptd.sys ZwEnumerateKey [0xF7387A92]
SSDT sptd.sys ZwEnumerateValueKey [0xF7387E20]
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 86F631E8
Device \FileSystem\Fastfat \Fat 85748980
---- Processes - GMER 1.0.15 ----
Process C:\Programmer\Internet Explorer\iexplore.exe (*** hidden *** ) 2448
---- EOF - GMER 1.0.15 ----
2. GMER log two.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-04 00:40:27
Windows 5.1.2600 Service Pack 3
Running: tqy7ysjb.exe; Driver: C:\DOCUME~1\ZREXIO~1\LOKALE~1\Temp\pgtdqpow.sys
---- System - GMER 1.0.15 ----
SSDT sptd.sys ZwCreateKey [0xF73820B0]
SSDT sptd.sys ZwEnumerateKey [0xF7387A92]
SSDT sptd.sys ZwEnumerateValueKey [0xF7387E20]
SSDT sptd.sys ZwOpenKey [0xF7382090]
SSDT sptd.sys ZwQueryKey [0xF7387EF8]
SSDT sptd.sys ZwQueryValueKey [0xF7387D78]
SSDT sptd.sys ZwSetValueKey [0xF7387F8A]
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 86F631E8
Device \FileSystem\Fastfat \FatCdrom 85748980
Device \Driver\usbuhci \Device\USBPDO-0 85CB51E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86F651E8
Device \Driver\dmio \Device\DmControl\DmConfig 86F651E8
Device \Driver\dmio \Device\DmControl\DmPnP 86F651E8
Device \Driver\dmio \Device\DmControl\DmInfo 86F651E8
Device \Driver\usbuhci \Device\USBPDO-1 85CB51E8
Device \Driver\usbuhci \Device\USBPDO-2 85CB51E8
Device \Driver\usbuhci \Device\USBPDO-3 85CB51E8
Device \Driver\usbehci \Device\USBPDO-4 85C0F540
Device \Driver\Ftdisk \Device\HarddiskVolume1 86FD21E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 86FD21E8
Device \Driver\Cdrom \Device\CdRom0 85CCE4F8
Device \Driver\Cdrom \Device\CdRom1 85CCE4F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 [F72D6B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F72D6B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 [F72D6B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 [F72D6B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f [F72D6B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\Cdrom \Device\CdRom2 85CCE4F8
Device \Driver\Cdrom \Device\CdRom3 85CCE4F8
Device \Driver\Cdrom \Device\CdRom4 85CCE4F8
Device \Driver\Cdrom \Device\CdRom5 85CCE4F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 858721E8
Device \Driver\NetBT \Device\NetbiosSmb 858721E8
Device \Driver\PCI_NTPNP8844 \Device\0000004e sptd.sys
Device \Driver\usbuhci \Device\USBFDO-0 85CB51E8
Device \Driver\usbuhci \Device\USBFDO-1 85CB51E8
Device \Driver\usbuhci \Device\USBFDO-2 85CB51E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 857E2600
Device \Driver\NetBT \Device\NetBT_Tcpip_{6B8F9B48-53E5-4DAB-90B0-32E4350B8BC7} 858721E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 857E2600
Device \Driver\usbuhci \Device\USBFDO-3 85CB51E8
Device \Driver\usbehci \Device\USBFDO-4 85C0F540
Device \Driver\Ftdisk \Device\FtControl 86FD21E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{A397DBAC-CDA7-4F24-850B-1271BACC9228} 858721E8
Device \Driver\a0fu783f \Device\Scsi\a0fu783f1Port3Path0Target0Lun0 85BFD1E8
Device \Driver\a0fu783f \Device\Scsi\a0fu783f1Port3Path0Target0Lun0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\fasttx2k \Device\Scsi\fasttx2k1Port2Path0Target4Lun0 86F641E8
Device \Driver\a0fu783f \Device\Scsi\a0fu783f1Port3Path0Target2Lun0 85BFD1E8
Device \Driver\a0fu783f \Device\Scsi\a0fu783f1Port3Path0Target2Lun0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\fasttx2k \Device\Scsi\fasttx2k1 86F641E8
Device \Driver\a0fu783f \Device\Scsi\a0fu783f1Port3Path0Target3Lun0 85BFD1E8
Device \Driver\a0fu783f \Device\Scsi\a0fu783f1Port3Path0Target3Lun0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\a0fu783f \Device\Scsi\a0fu783f1Port3Path0Target1Lun0 85BFD1E8
Device \Driver\a0fu783f \Device\Scsi\a0fu783f1Port3Path0Target1Lun0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\a0fu783f \Device\Scsi\a0fu783f1 85BFD1E8
Device \Driver\a0fu783f \Device\Scsi\a0fu783f1 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\Fastfat \Fat 85748980
Device \FileSystem\Cdfs \Cdfs 857597C0
---- Processes - GMER 1.0.15 ----
Process C:\Programmer\Internet Explorer\iexplore.exe (*** hidden *** ) 2448
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 549741722
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 552213645
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x22 0x61 0xD5 0x21 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmer\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x14 0x31 0xEB 0xF4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x9F 0xE5 0x45 0xA3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x33 0x47 0xC5 0x2C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x9B 0xCF 0xA4 0x75 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xBE 0x50 0x72 0xB5 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x22 0x61 0xD5 0x21 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmer\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x14 0x31 0xEB 0xF4 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x9F 0xE5 0x45 0xA3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x33 0x47 0xC5 0x2C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x9B 0xCF 0xA4 0x75 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xBE 0x50 0x72 0xB5 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x22 0x61 0xD5 0x21 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Programmer\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x14 0x31 0xEB 0xF4 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x87 0x0A 0x7F 0x1F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x33 0x47 0xC5 0x2C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0x9B 0xCF 0xA4 0x75 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xBE 0x50 0x72 0xB5 ...
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\LocalService\Cookies\system@adnxs[2].txt 0 bytes
---- EOF - GMER 1.0.15 ----
I won't post the MBA-M log because it is in Danish.
Anyone of you got an idea of what is wrong?
Mbr.
BankDJ