Potential Rootkit, affects Gmer, RKR, HJT, IE, AVZ, RKhookAnalyzer...
I wasn't sure if I should post a new thread or post in the old one.
I have 2 computers on a home network. My dsl modem seems affected. I have it set to bridge mode, and in that mode the lights should not blink, they do. In bridge mode the router becomes the gateway to the inet.
After my previous posts, I wiped all infected computers, reinstalled OS's.
Reset the dsl modem, reconfigured, new account password. Reset the router, reconfigured. Reset router 2, reconfigured. After doing all this the modem wasn't acting right, was blinking and shouldn't.
I have wiped this computer a second time, a laptop. I wanted to put xp pro on it instead of vista. Could not install xp. Now I am back to vista.
I am having problems. I may have a rootkit. Kaspersky 7 shows nothing.
I was curious because of minor issues, so I used Rootkit Revealer. It acted weird. I get, Interactive Services Dialog Detection, the screen blanks out and the scan is performed in a different environment, finding 285,000+ discrepencies.
Gmer says there is an ntdll.dll issue.
Rootkit hook analyzer worked on initial install but subsequently does not work.
F-Secure blacklight used but found nothing.
Avz has some difficulties, but staes there is a problem.
HiJackThis will not save a log file.
Bat1 will not save a log file.
I used to use Netscape on the previous installs and on downloads, 7.5mb file in less than 1 second. I don't have a T1 and I don't have fios(fiber optic service). I can't explain 1200kb to 2000kb downloads unless I'm pipelined through somebody elses connection.
Is it possible that my ISP is the infection point or my account from the ISP?
Could the flash in my modem be infected? Would reseting it delete the infection?
I am just getting frustrated. No matter what I do or how often I wipe the problems return. On this latest install I have not used any outside media of old saved files. If I became infected it was because of the connection. If I stayed infected then it was embeded in the system.
Potential Rootkit, affects Gmer, RKR, HJT, IE, AVZ, RKhookAnalyzer...
Вложений: 1
I found the HJT log file, not in HJT folder.
File is being saved in a funny location.
AppData/Local/VirtualStore/Program files/HJT/
I thought it was supposed to be saved in the program files/HJT folder.
Вложений: 1
AVPtool, may shed more light.
What I have come to realize is you guys are tops in your fields.
I am glad that you offer insight and help to people like myself.
I understand that this is a war and I am caught in the middle, so to speak. I don't like being the middleman in this scenario.
You guys are on the creative edge of college and I am still mucking about in elementary school.
Also, I may be a quarter bubble off level, but that is nothing a shim can't take care of. :crazy:
I posted this attachment because AVZ for some reason does not always show the ntdll.dll hook/hijack. Not sure why. I may run a scan once a day or every other, sometimes it shows, sometimes not.
I ran Process Monitor, and it shows "service" opening every reg key, open,enum,close, on occasion create. It also did it with every file. I saved a snippet.
And the book is going well.