Mikey
Newbie


Posts: 17
|
 |
Re: Help to remove Trojan please
« Reply #13 on: Jul 17th, 2009, 8:12am » |
Quote Modify
|
Next part GMER scan IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryExA] [0280F4B0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryExW] [0280F6C0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!CreateProcessW] [02810160] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [0280F6C0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [0280F6C0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [0280F6C0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [02810160] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [0280FF90] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [02810160] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [0280F6C0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [0280F4B0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [02810160] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [0280F4B0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [0280F6C0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [0280FF90] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [02810160] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [0280F4B0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [0280F6C0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [0280FBD0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [0280F6C0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [0280FDB0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [02810160] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [0280F6C0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [0280F4B0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [0280FDB0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [0280FA50] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [0280F4B0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [02810160] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [0280F8D0] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT C:\WINDOWS\Explorer.EXE[544] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [0280F330] C:\Program Files\CA\PPRT\bin\CACheck.dll (API interceptors/CA, Inc.) IAT
|
|
IP Logged |
|
|
|