I was infected by some malware and even after getting a clean machine, I can no longer turn on the firewall cis. Enjoy the icon in the notification area indicating problems and run the diagnostic problems are encountered but the cis not resolve them, and generates a log file. Have reinstalled the application but the problem persists. What should I do to solve this problem? Thank you.
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCommandLineW] 00246683
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!InitializeCriticalSection] FFFC4D83
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetProcessHeap] 8514768B
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!SetErrorMode] 560674F6
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!SetUnhandledExceptionFilter] 01F57EE8
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!RegisterWaitForSingleObject] [406FE800] C:\WINDOWS\system32\ieframe.dll (Internet Explorer/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!InterlockedCompareExchange] 04C20002
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LoadLibraryA] F18B5600
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!QueryPerformanceCounter] FFB4E856
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetTickCount] 44F6FFFF
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCurrentThreadId] 74010824
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCurrentProcessId] 3BE85607
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetSystemTimeAsFileTime] 590001F9
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!TerminateProcess] C25EC68B
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!UnhandledExceptionFilter] [408B0004] C:\WINDOWS\system32\ieframe.dll (Internet Explorer/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LocalAlloc] 74C08514
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!lstrcmpW] 4CE85006
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!DelayLoadFailureHook] C30001F5
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!NtQuerySecurityObject] 33002083
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlFreeHeap] 0008C2C0
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!NtOpenKey] [004005B8] C:\WINDOWS\System32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!wcscat] 0018C280
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!wcscpy] [004005B8] C:\WINDOWS\System32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlAllocateHeap] 0024C280
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlCompareUnicodeString] 1024448B
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlInitUnicodeString] B8002083
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlInitializeSid] 80004001
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlLengthRequiredSid] 8B0010C2
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlSubAuthoritySid] 83082444
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!NtClose] 02B80020
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlSubAuthorityCountSid] C2800040
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlGetDaclSecurityDescriptor] C0330008
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlQueryInformationAcl] 0014C240
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlGetAce] 0824448B
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlImageNtHeader] 000440C7
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!wcslen] 33000002
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlUnhandledExceptionFilter] 0008C2C0
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlCopySid] 18C2C033
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcServerUnregisterIfEx] 330008C2
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcMgmtWaitServerListen] 10C240C0
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcMgmtSetServerStackSize] 24448B00
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcServerUnregisterIf] 0020830C
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcServerListen] [004001B8] C:\WINDOWS\System32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcServerUseProtseqEpW] 000CC280
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcServerRegisterIf] 51EC8B55
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!I_RpcMapWin32Status] 00FC6583
IAT C:\WINDOWS\System32\svchost.exe[2548] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcMgmtStopServerListening] FC458D56
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!RegQueryValueExW] [77F5ECE5] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!SetSecurityDescriptorDacl] [77F56AAF] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!SetEntriesInAclW] [77F56FFF] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!SetSecurityDescriptorGroup] [77F5D767] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!SetSecurityDescriptorOwner] [77F651B6] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!InitializeSecurityDescriptor] [77F64332] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!GetTokenInformation] [77F56C27] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!OpenProcessToken] [77F57852] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!OpenThreadToken] [77F5E9F4] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!SetServiceStatus] [77F642A0] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!RegisterServiceCtrlHandlerW] [77F5EAE7] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!RegCloseKey] [77F57ABB] C:\WINDOWS\system32\ADVAPI32.dll (API de base do Windows 32 avançada/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!RegOpenKeyExW] 00000000
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!StartServiceCtrlDispatcherW] [77E561C1] C:\WINDOWS\system32\GDI32.dll (GDI Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!WideCharToMultiByte] [77E55B70] C:\WINDOWS\system32\GDI32.dll (GDI Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!lstrlenW] 00000000
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LocalFree] [7C80CD48] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCurrentProcess] [7C838E18] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCurrentThread] [7C80D302] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetProcAddress] [7C80B8C9] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LoadLibraryExW] [7C81116B] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LCMapStringW] [7C809AF1] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!FreeLibrary] [7C809B84] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!lstrcpyW] [7C80B56F] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!ExpandEnvironmentStringsW] [7C812FD9] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!lstrcmpiW] [7C809C65] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!ExitProcess] [7C8097E0] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCommandLineW] [7C80E4DD] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!InitializeCriticalSection] [7C813133] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetProcessHeap] [7C84495D] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!SetErrorMode] [7C863FCA] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!SetUnhandledExceptionFilter] [7C80DE95] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!RegisterWaitForSingleObject] [7C801E1A] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!InterlockedCompareExchange] [7C80BA71] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LoadLibraryA] [7C92ABC5] C:\WINDOWS\system32\ntdll.dll (DLL de nível do NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!QueryPerformanceCounter] [7C838A3C] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetTickCount] [7C80A530] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCurrentThreadId] [7C80BEA1] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCurrentProcessId] [7C80BE56] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetSystemTimeAsFileTime] [7C8101B1] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!TerminateProcess] [7C812FBD] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!UnhandledExceptionFilter] [7C81127A] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LocalAlloc] [7C80E9DF] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!lstrcmpW] [7C802446] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!DelayLoadFailureHook] [7C809BE7] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!NtQuerySecurityObject] [7C90FE21] C:\WINDOWS\system32\ntdll.dll (DLL de nível do NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlFreeHeap] [7C80934A] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!NtOpenKey] [7C80BB04] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!wcscat] [7C809AA9] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!wcscpy] [7C801812] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlAllocateHeap] [7C810B17] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlCompareUnicodeString] [7C801A28] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlInitUnicodeString] [7C810E27] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlInitializeSid] [7C810FD2] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlLengthRequiredSid] [7C810800] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlSubAuthoritySid] [7C809F91] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!NtClose] [7C9010E0] C:\WINDOWS\system32\ntdll.dll (DLL de nível do NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlSubAuthorityCountSid] [7C901000] C:\WINDOWS\system32\ntdll.dll (DLL de nível do NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlGetDaclSecurityDescriptor] [7C834D71] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlQueryInformationAcl] [7C81CB12] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlGetAce] [7C802530] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlImageNtHeader] [7C814B92] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!wcslen] [7C801629] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlUnhandledExceptionFilter] [7C80A174] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [ntdll.dll!RtlCopySid] [7C809C98] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcServerUnregisterIfEx] [7C830D7C] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcMgmtWaitServerListen] [7C80E88C] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcMgmtSetServerStackSize] [7C80176F] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcServerUnregisterIf] [7C813851] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcServerListen] [7C831EDD] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcServerUseProtseqEpW] [7C80EE77] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcServerRegisterIf] [7C834EE1] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!I_RpcMapWin32Status] [7C813879] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
IAT C:\WINDOWS\System32\svchost.exe[3752] @ C:\WINDOWS\System32\svchost.exe [RPCRT4.dll!RpcMgmtStopServerListening] [7C812AA9] C:\WINDOWS\system32\kernel32.dll (DLL cliente da API BASE do Windows NT/Microsoft Corporation)
It looks like there are firewall drivers left from Jetico FW.
SSDT \SystemRoot\System32\Drivers\bcftdi.SYS (Jetico Personal Firewall TDI Filter Driver/Jetico, Inc.)
And you can also “attach” the gmer report instead of having to copy/past it, using the “Additional Options” Below the Post box, click to expand and select Browse button to add the gmer report.
We need to get rid of the Jetico firewall (drivers) first before you can get CIS to function correctly…
I also don’t like the complain about the ndis.sys driver, can you please check your driver signatures with this tool here: Sigcheck - Sysinternals | Microsoft Learn
.reloc C:\WINDOWS\System32\DRIVERS\NDIS.SYS section is executable [0x899B2200, 0x32AAA, 0xE0000060]
---- User code sections - GMER 1.0.15 ----
? C:\WINDOWS\System32\svchost.exe[436] image checksum mismatch; number of sections mismatch; time/date stamp mismatch;
? C:\WINDOWS\System32\svchost.exe[936] image checksum mismatch; number of sections mismatch; time/date stamp mismatch;
Looks like svchost.exe get's injected or something... probably by the ndis "driver".
My guess would be a MBR Rootkit variant based on this here…
It is known that the rootkit's main purpose is to act as an ultimate downloader. To be stealthy and effective it is essential that the rootkit does not trigger nor is blocked by personal firewalls. It is able to achieve this by operating in the lowest parts of the NDIS layer just above the physical hardware.
Do you have the original disk that came with the computer?
Here is mine from a XP sp3 system.
c:\windows\system32\drivers\ndis.sys:
Verified: Signed
Signing date: 3:07 AM 4/14/2008
Publisher: Microsoft Corporation
Description: NDIS 5.1 wrapper driver
Product: Microsoft« Windows« Operating System
Version: 5.1.2600.5512
File version: 5.1.2600.5512 (xpsp.080413-0852)
I guess somewhere in the i386 folder but i think you need to search the cd before you boot in safe-mode and write it down… it’s probably named ndis.sy_ or something similar…
Did you run the avira rescue cd? I suspect there are more “infections” present on your system… it should not be limited to ndis.sys only… otherwise please read this post here:
And I’m not sure what you mean with:
but de sign program tell "No matching files were found." to restored file.
Yes, I scanned the cd and avira found a protector rootkit (Ndis.sys). When I run the program verifier signature it gives me this message "No matching files were found. What does this mean? Is everything ok with the file that I restored?