ComboFix Log #1
Hello - ComboFix ran through. It went like so:
Disabled ESET.
Placed CF on the Desktop.
Launched it.
Created Recovery Console.
Processing....Declared root kit activity present: Rebooted
Came back up with only wallpaper showing - DOS box...
Stepped through multi-step process.
Rebooted.
Came back up with full desktop and ESET enabled (I worried about that but I guess as it's just producing a log file...)
Produced log file below.
Should I have tested the computer/browser? I held off because I wasn't sure. I'm ready for the next step.
ComboFix 10-07-20.03 - TanteC 07/21/2010 6:28.1.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.180 [GMT -4:00]
Running from: c:\documents and settings\TanteC\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\Winlogon
c:\windows\system32\winlogon.exe.exe
c:\windows\system32\wpcap.dll
Infected copy of c:\windows\system32\drivers\adpu160m.sys was found and disinfected
Restored copy from - Kitty had a snack
Infected copy of c:\windows\system32\drivers\adpu160m.sys was found and disinfected
Restored copy from - Kitty had a snack
Infected copy of c:\windows\system32\drivers\adpu160m.sys was found and disinfected
Restored copy from - Kitty had a snack
Infected copy of c:\windows\system32\drivers\adpu160m.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2010-06-21 to 2010-07-21 )))))))))))))))))))))))))))))))
.
2010-07-18 20:33 . 2010-07-18 20:33 54016 ----a-w- c:\windows\system32\drivers\kscitar.sys
2010-07-18 19:30 . 2010-07-18 19:30 -------- d-----w- C:\FOUND.004
2010-07-18 17:42 . 2010-07-18 17:42 -------- d-----w- C:\The Fix
2010-07-17 23:56 . 2005-10-18 17:33 581632 --sha-r- c:\documents and settings\TanteC\plugin.dat
2010-07-17 23:05 . 2010-07-17 23:05 -------- d-----w- c:\documents and settings\TanteC\Application Data\SUPERAntiSpyware.com
2010-07-17 23:05 . 2010-07-17 23:05 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-17 23:05 . 2010-07-17 23:05 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-07-16 12:41 . 2010-07-16 12:41 -------- d-----w- C:\FOUND.003
2010-07-16 12:35 . 2010-07-16 12:35 -------- d-----w- c:\documents and settings\Admin\Application Data\Malwarebytes
2010-07-16 12:04 . 2010-07-16 12:04 -------- d-----w- C:\FOUND.002
2010-07-16 07:52 . 2010-07-16 07:52 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-15 01:13 . 2010-07-15 01:13 101888 ----a-w- c:\windows\system32\drivers\mtstjzvw.sys
2010-07-15 01:13 . 2010-07-15 01:13 -------- d-----w- c:\documents and settings\TanteC\Local Settings\Application Data\ESET
2010-07-15 00:02 . 2010-07-15 00:02 -------- d-----w- c:\windows\system32\MpEngineStore
2010-07-14 23:34 . 2010-07-20 11:47 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-14 13:07 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-06-23 12:06 . 2010-06-23 12:06 -------- d-----w- c:\documents and settings\TanteC\Local Settings\Application Data\PCHealth
2010-06-23 11:42 . 2010-04-12 21:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-17 23:06 . 2010-07-17 23:06 63488 ----a-w- c:\documents and settings\TanteC\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-17 23:06 . 2010-07-17 23:06 52224 ----a-w- c:\documents and settings\TanteC\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-17 23:06 . 2010-07-17 23:06 117760 ----a-w- c:\documents and settings\TanteC\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-16 12:45 . 2010-07-17 21:11 170932 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2010-06-14 14:31 . 2004-08-04 09:00 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\HelpSvc.exe
2010-06-02 21:08 . 2010-06-02 21:08 503808 ----a-w- c:\documents and settings\TanteC\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-262f432a-n\msvcp71.dll
2010-06-02 21:08 . 2010-06-02 21:08 499712 ----a-w- c:\documents and settings\TanteC\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-262f432a-n\jmc.dll
2010-06-02 21:08 . 2010-06-02 21:08 348160 ----a-w- c:\documents and settings\TanteC\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-262f432a-n\msvcr71.dll
2010-06-02 21:08 . 2010-06-02 21:08 61440 ----a-w- c:\documents and settings\TanteC\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-23b67878-n\decora-sse.dll
2010-06-02 21:08 . 2010-06-02 21:08 12800 ----a-w- c:\documents and settings\TanteC\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-23b67878-n\decora-d3d.dll
2010-05-06 10:41 . 2006-01-09 15:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 09:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2010-01-18 12:45 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-01-18 12:44 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2006-03-16 88204]
"RTHDCPL"="RTHDCPL.EXE" [2006-02-27 16005120]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-08-25 53248]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-08 102491]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-08 692315]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-04-04 421888]
"Boot"="c:\acer\Empowering Technology\ePower\Boot.exe" [2006-03-16 579584]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-04-28 401408]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-27 2029640]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NetStats.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NetStats.lnk
backup=c:\windows\pss\NetStats.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchApp]
Alaunch [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD]
2006-03-31 20:39 204800 ----a-w- c:\acer\Empowering Technology\ePresentation\ePresentation.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-04-16 01:47 136176 ----a-w- c:\documents and settings\TanteC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImageItEncrypt]
2005-12-30 18:02 40960 ----a-w- c:\windows\system32\ImageItEncrypt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-04-29 19:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
2009-07-17 15:12 288080 ----a-w- c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSN Toolbar]
2009-12-09 01:29 240992 ----a-w- c:\program files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2004-08-04 09:00 455168 ------w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2004-08-04 09:00 455168 ------w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-03 00:24 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 15:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-07-17 23:08 2403568 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-12-21 04:45 39424 ----a-w- c:\program files\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4/27/2009 1:22 AM 107256]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 2:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 2:41 PM 67656]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [4/27/2009 1:22 AM 731840]
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;\??\c:\windows\system32\eLock2BurnerLockDriver.sys --> c:\windows\system32\eLock2BurnerLockDriver.sys [?]
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;\??\c:\windows\system32\eLock2FSCTLDriver.sys --> c:\windows\system32\eLock2FSCTLDriver.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1/18/2010 8:45 AM 38224]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [4/6/2010 11:14 PM 27064]
.
Contents of the 'Scheduled Tasks' folder
2010-07-21 c:\windows\Tasks\User_Feed_Synchronization-{B3204F40-EC3C-42EF-8F5D-694C6701E687}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
2010-07-15 c:\windows\Tasks\Malwarebytes' Scheduled Update for Administrator.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2010-01-18 19:39]
2010-07-21 c:\windows\Tasks\User_Feed_Synchronization-{EBA9C105-6592-4C4E-964F-4CC442A667D6}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
2010-07-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4213325216-2343158164-1464277813-1007Core1cb0cda97c5a08a.job
- c:\documents and settings\TanteC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-16 01:47]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe"
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Cerberus - c:\windows\system32\winlogon.exe.exe
MSConfigStartUp-HKLM - c:\windows\system32\winlogon\winlogon.exe
ActiveSetup-{36K3DTB1-2174-737D-68CD-NY6P1SU1JT60} - c:\windows\system32\winlogon\winlogon.exe
ActiveSetup-{AV0EQ4R6-Y588-N4Q6-SC63-Y6P21MLT75B6} - Restart
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-21 06:37
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1084)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\documents and settings\TanteC\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
c:\documents and settings\TanteC\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
c:\documents and settings\TanteC\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(148)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\acer\Empowering Technology\ePower\SysHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\AGRSMMSG.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Completion time: 2010-07-21 06:43:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-21 10:43
Pre-Run: 29,175,054,336 bytes free
Post-Run: 29,148,741,632 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 157671BBC8FE688054DE78E51AC772E0
Thank you very much for this help!