Hi.
I used this program and it found this. Am i infected? Log is too long for this post.
Thanks!
+ RKDETECTOR v2.0 Beta (FILESYSTEM DRIVER MODULE)
+ RKDETECTOR (c) Andres Tarasco Acuńa 2003 - 2005
+
Rkdetector - Microsoft Rootkit Detector v2.0 2005 (c)
+ Free for evaluating / personal usage
+ THIS SOFTWARE IS PROVIDED "AS IS". USE IT AT YOUR OWN RISK
ANALIZANDO...
DISABLED IN THIS BETA
FLUSHING DEVICE: \\.\c:
Filesystem: NTFS
ASIGNED: 10760 VCNs, CS= 4096, BPMR = 1024
Reading Device. Found NTFS Partition version 3.1
- WARNING. UNABLE TO BROWSE c:\System Volume Information\*
+ Windows Filesystem exploration Finished (API Calls)
HIDDEN: c:\System Volume Information\MountPointManagerRemoteDatabase
HIDDEN: c:\System Volume Information\tracking.log
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000869.inf
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000852.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000853.inf
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000854.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000855.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000856.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000857.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000858.ocx
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000859.exe
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000860.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000861.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000862.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000863.ocx
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000864.exe
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000865.inf
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000866.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000867.CAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000868.inf
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000870.inf
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000871.inf
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000872.inf
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000873.CAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000874.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000875.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000876.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000877.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000878.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000879.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000880.ver
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000881.exe
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000882.exe
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000883.exe
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000884.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000885.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000886.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000887.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000888.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000889.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000890.ocx
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000891.ocx
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000892.ocx
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000893.exe
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000894.exe
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\A0000895.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\change.log.1
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\drivetable.txt
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\RestorePointSize
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\rp.log
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_USER_NTUSER_ S-1-5-20
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\ComDb.Dat
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\domain.txt
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-1.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-10.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-11.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-2.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-3.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-4.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-5.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-6.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-7.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-8.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\MFEX-9.DAT
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\Repository
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\Repository\$WinMgmt.CF G
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\Repository\FS
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\Repository\FS\INDEX.BT R
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\Repository\FS\INDEX.MA P
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\Repository\FS\MAPPING. VER
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\Repository\FS\MAPPING1 .MAP
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\Repository\FS\MAPPING2 .MAP
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\Repository\FS\OBJECTS. DATA
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\Repository\FS\OBJECTS. MAP
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_MACHINE_SOFT WARE
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_MACHINE_SAM
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_MACHINE_SYST EM
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_MACHINE_SECU RITY
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_USER_NTUSER_ S-1-5-21-1960408961-1801674531-1400454329-500
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_USER_USRCLAS S_S-1-5-21-1960408961-1801674531-1400454329-500
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_USER_NTUSER_ S-1-5-21-1960408961-1801674531-1400454329-1004
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_USER_.DEFAUL T
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_USER_NTUSER_ S-1-5-18
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_USER_NTUSER_ S-1-5-19
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_USER_USRCLAS S_S-1-5-19
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_USER_USRCLAS S_S-1-5-20
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP25\snapshot\_REGISTRY_USER_USRCLAS S_S-1-5-21-1960408961-1801674531-1400454329-1004
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\drivetable.txt
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\A0000001.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\A0000002.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\A0000003.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\A0000004.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\A0000005.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\A0000006.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\A0000007.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\A0000008.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\A0000009.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\A0000010.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP0\change.log.1
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP1
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP1\A0000028.PNF
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP1\A0000011.dll
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP1\A0000012.ini
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP1\A0000013.ini
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP1\A0000014.INI
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP1\A0000015.hhk
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP1\A0000016.hhk
HIDDEN: c:\System Volume Information\_restore{FBCE4D91-E489-4DC1-ACD9-569C6DF44E1D}\RP1\A0000017.hhk