Jump to content

Security Tool /Spyware/Trojan/Rootkit


Recommended Posts

A fake security alert "Security Tool" downloaded itself. I ran McAfee/MalBytes/Adaware etc., but nothing was found. The fake "Security Tool" its system tray icons and the garbage windows that would pop up disappeared, so I thought it was gone. However, when using Internet Explorer I started to get redirects and then multiple browsers opening. I ran everything again and MalBytes found "Spyware.passwords" and "trojan.hiloti.gen" on first pass. None of the other scans found anything so I tried Inter Explorer again, and redirects/multiple browser continued. I ran another set of scans and MalBytes found "trojan.fakealert" and "rootkit.dropper". Again, I thought it was ok but the same redirects continued.

I ran Mcafee/Malbytes/Adaware/Stinger yet again, but everything comes back clean. The redirects with the browser continue.

I can't seem to shake this one out of my system and really need some help.

I ran Defogger per instructions. I ran DDS and got the logs. I tried to run GMER but had issues. It started o.k., and per instructions I made sure the boxes were unchecked and tried the scan again. It scanned for several minutes, but locked up. I had to reboot and tried again but it locked again. I tried a third time with GMER and after a pretty long time I got the "blue screen" stating that windows was shutting down because of instability so I don't have any logs from GMER.

Please let me know if I should add any additional information. Thank you for your help on this matter.

Last MBAM log (shows clean)

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4442

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

8/17/2010 5:59:35 PM

mbam-log-2010-08-17 (17-59-35).txt

Scan type: Quick scan

Objects scanned: 168786

Time elapsed: 12 minute(s), 52 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

defogger_disable by jpshortstuff (23.02.10.1)

Log created at 18:20 on 17/08/2010

EDIT: The DDS text file may have been too long because I could not post my entry. Will attempt to send log in second posting. Sorry to split my entry.

Link to post
Share on other sites

I know we're not supposed to reply until 48 hours have passed, but I noticed my post has been shuffled down to the bottom of page three and I didn't want it to get lost. Plus, I see some more recent problem entries from today have already been answered.

Redirect problem persists with browser.

Again, sorry to jump the gun but I didn't want my issue to get lost and I definitely need some help.

Thanks.

Link to post
Share on other sites

  • Staff

Hi and welcome to Malwarebytes.

Please visit this webpage for instructions for running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

  • When the tool is finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a new DDS log so we may continue cleaning the system.

-screen317

Link to post
Share on other sites

Thanks for the help on this. I ran ComboFix per instructions. Logs attached, ComboFix first:

ComboFix 10-08-17.04 - William Buckhold 08/18/2010 19:37:51.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.541 [GMT -4:00]

Running from: c:\documents and settings\William Buckhold\Desktop\ComboFix.exe

AV: McAfee Anti-Virus and Anti-Spyware *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Administrator\GoToAssistDownloadHelper.exe

c:\documents and settings\William Buckhold\GoToAssistDownloadHelper.exe

c:\documents and settings\William Buckhold\Local Settings\Application Data\Windows Server

c:\windows\Tasks\diqteegy.job

c:\windows\Tasks\melrfwwg.job

c:\windows\Tasks\tqojdjbm.job

C:\zip.exe

c:\windows\system32\drivers\gpevbz.sys . . . is infected!! . . . Failed to find a valid replacement.

.

((((((((((((((((((((((((( Files Created from 2010-07-19 to 2010-08-19 )))))))))))))))))))))))))))))))

.

2010-08-16 19:28 . 2010-08-16 19:28 -------- d-----w- c:\windows\system32\wbem\Repository

2010-08-16 18:49 . 2010-08-16 18:49 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2010-08-16 18:46 . 2010-08-16 18:46 120 ----a-w- c:\windows\Jmopadote.dat

2010-08-16 18:46 . 2010-08-16 18:46 0 ----a-w- c:\windows\Wgirahi.bin

2010-08-16 18:46 . 2010-08-16 19:27 -------- d-----w- c:\documents and settings\William Buckhold\Local Settings\Application Data\{92DE1F95-A400-4315-B451-895D9DAF0891}

2010-08-14 23:35 . 2010-08-16 19:28 -------- d-----w- C:\Netgear

2010-08-06 15:04 . 2010-08-06 15:04 -------- d-----w- c:\documents and settings\William Buckhold\Local Settings\Application Data\vxcjbimom

2010-07-28 15:52 . 2010-07-28 15:52 -------- d-----w- c:\documents and settings\William Buckhold\Application Data\Malwarebytes

2010-07-28 15:52 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-07-28 15:52 . 2010-07-28 15:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-07-28 15:52 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-07-28 15:52 . 2010-07-28 16:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-07-25 22:04 . 2010-07-25 22:04 -------- d-sh--w- c:\documents and settings\Amy Marshall\PrivacIE

2010-07-25 21:52 . 2010-07-25 21:52 -------- d-sh--w- c:\documents and settings\Amy Marshall\IETldCache

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-18 23:59 . 2006-08-03 02:19 -------- d-----w- c:\program files\Dl_cats

2010-08-18 22:32 . 2006-12-14 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater

2010-08-18 21:37 . 2006-08-19 21:44 1324 ----a-w- c:\windows\system32\d3d9caps.dat

2010-08-16 23:16 . 2010-04-30 13:24 300384 ----a-w- c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\detect.dll

2010-08-16 23:16 . 2008-03-18 01:05 300384 ----a-w- c:\documents and settings\William Buckhold\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll

2010-08-13 11:18 . 2010-02-17 18:02 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS

2010-06-30 12:31 . 2005-08-16 08:18 149504 ----a-w- c:\windows\system32\schannel.dll

2010-06-24 12:22 . 2005-08-16 08:18 916480 ----a-w- c:\windows\system32\wininet.dll

2010-06-23 13:44 . 2005-08-16 08:18 1851904 ----a-w- c:\windows\system32\win32k.sys

2010-06-22 20:58 . 2010-06-22 20:58 501936 ----a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb3E.tmp.exe

2010-06-21 15:27 . 2006-07-29 20:34 354304 ----a-w- c:\windows\system32\drivers\srv.sys

2010-06-17 14:03 . 2005-08-16 08:18 80384 ----a-w- c:\windows\system32\iccvid.dll

2010-06-16 15:42 . 2010-03-11 21:23 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-06-14 14:31 . 2005-08-16 08:40 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-06-14 07:41 . 2005-08-16 08:18 1172480 ----a-w- c:\windows\system32\msxml3.dll

2010-06-03 16:02 . 2010-03-11 20:56 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-05-27 03:08 . 2006-08-03 02:26 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys

2010-05-27 03:08 . 2006-08-03 02:26 88 --sh--r- c:\windows\system32\C644D0FFE4.sys

2010-05-23 14:57 . 2010-05-23 14:57 666112 ----a-w- c:\documents and settings\William Buckhold\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv306hw-1004220-0-main.dll

2006-08-07 17:39 . 2006-08-07 17:39 251 ----a-w- c:\program files\wt3d.ini

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]

"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-03-31 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]

"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]

"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2007-08-28 73728]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-26 30192]

"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-18 110592]

"dlcdmon.exe"="c:\program files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-07-22 430080]

"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 944\memcard.exe" [2005-08-10 286720]

"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-01-18 8192]

"tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2004-01-30 1921024]

"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]

"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]

"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]

"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-03-27 413696]

"DLCDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-06-07 69632]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-06-25 1193848]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-7-29 24576]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=

"c:\\WINDOWS\\system32\\fxsclnt.exe"=

"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Documents and Settings\\William Buckhold\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/11/2010 4:56 PM 64288]

R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [4/22/2010 9:22 AM 82952]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [9/29/2009 3:32 PM 88176]

R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/22/2010 9:22 AM 271480]

R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [4/22/2010 9:22 AM 271480]

R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [4/22/2010 9:22 AM 188136]

R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [4/22/2010 9:22 AM 141792]

R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [4/22/2010 9:22 AM 55456]

R3 dlcd_device;dlcd_device;c:\windows\system32\dlcdcoms.exe -service --> c:\windows\system32\dlcdcoms.exe -service [?]

R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [4/22/2010 9:22 AM 312616]

R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [4/22/2010 9:22 AM 88480]

S0 gpevbz;gpevbz;c:\windows\system32\drivers\gpevbz.sys [4/2/2010 4:55 PM 823808]

S2 gupdate1c986fbc422206;Google Update Service (gupdate1c986fbc422206);c:\program files\Google\Update\GoogleUpdate.exe [2/4/2009 3:01 PM 133104]

S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]

S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [7/29/2006 5:09 PM 30192]

S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1352832]

S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [4/22/2010 9:22 AM 88480]

S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [4/22/2010 9:22 AM 83496]

--- Other Services/Drivers In Memory ---

*Deregistered* - mfeavfk01

.

Contents of the 'Scheduled Tasks' folder

2010-08-18 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2006-12-14 18:33]

2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 19:01]

2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 19:01]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://yahoo.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = iexplore

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

Trusted Zone: interfleet.com\http2

Trusted Zone: internet

Trusted Zone: mcafee.com

Trusted Zone: musicmatch.com\online

DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://conleybottom1.axiscam.net/activex/AMC.cab

DPF: {FE92D9C3-4A69-4EC7-8651-1DC8531D0075} - hxxp://www.bcsrivercam.com/TSBnwCam.CAB

.

- - - - ORPHANS REMOVED - - - -

BHO-{65dbd01a-b56b-48de-8bf5-9b6aa3159029} - yezakive.dll

HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

SharedTaskScheduler-{d61d3580-784e-4774-9b0e-619a0b35aad4} - c:\windows\system32\jegohami.dll

SSODL-bubuwopek-{a6162656-0d14-4004-bff3-8256bd495616} - c:\windows\system32\nulutuni.dll

SSODL-ledeyumid-{d61d3580-784e-4774-9b0e-619a0b35aad4} - c:\windows\system32\jegohami.dll

MSConfigStartUp-zodorizaso - busogeto.dll

AddRemove-Dell Digital Jukebox Driver - c:\program files\Dell\Digital Jukebox Drivers\DrvUnins.exe

AddRemove-McAfee Clean Up Tool - c:\docume~1\WILLIA~1\LOCALS~1\TEMPOR~1\Content.IE5\A2N99RDZ\UNWISE.EXE

AddRemove-McAfee Uninstall Utility - c:\progra~1\McAfee.com\Shared\mcappins.exe

AddRemove-TurboTax 2008 - c:\documents and settings\Amy Marshall\My Documents\Amy Finances\TurboTax\Deluxe 2008\Installer\TurboTax 2008 Installer.exe

AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-08-18 20:00

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

DLCDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully

user: MBR read successfully

called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x870E4EC5]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xf7552f28

\Driver\ACPI -> ACPI.sys @ 0xf73e5cb8

\Driver\atapi -> atapi.sys @ 0xf7377852

\Driver\iaStor -> iastor.sys @ 0xf72aeb10

IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

NDIS: Intel® PRO/1000 PL Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf713bbb0

PacketIndicateHandler -> NDIS.sys @ 0xf7148a21

SendHandler -> NDIS.sys @ 0xf712687b

user & kernel MBR OK

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1076)

c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1136)

c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(1036)

c:\windows\system32\WININET.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\eHome\ehRecvr.exe

c:\windows\eHome\ehSched.exe

c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe

c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\system32\nvsvc32.exe

c:\program files\Dell Support Center\bin\sprtsvc.exe

c:\program files\Common Files\McAfee\SystemCore\mcshield.exe

c:\program files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe

c:\windows\system32\fxssvc.exe

c:\windows\ehome\mcrdsvc.exe

c:\windows\system32\dllhost.exe

c:\windows\stsystra.exe

c:\windows\eHome\ehmsas.exe

c:\windows\system32\dlcdcoms.exe

c:\program files\MUSICMATCH\Musicmatch Jukebox\mim.exe

c:\program files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe

.

**************************************************************************

.

Completion time: 2010-08-18 20:16:38 - machine was rebooted

ComboFix-quarantined-files.txt 2010-08-19 00:16

Pre-Run: 262,109,372,416 bytes free

Post-Run: 263,383,556,096 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - F61EBF39FB843857F88F712F695D88E4

Link to post
Share on other sites

DDS Log with attach.txt zipped.

ComboFix 10-08-17.04 - William Buckhold 08/18/2010 19:37:51.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.541 [GMT -4:00]

Running from: c:\documents and settings\William Buckhold\Desktop\ComboFix.exe

AV: McAfee Anti-Virus and Anti-Spyware *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Administrator\GoToAssistDownloadHelper.exe

c:\documents and settings\William Buckhold\GoToAssistDownloadHelper.exe

c:\documents and settings\William Buckhold\Local Settings\Application Data\Windows Server

c:\windows\Tasks\diqteegy.job

c:\windows\Tasks\melrfwwg.job

c:\windows\Tasks\tqojdjbm.job

C:\zip.exe

c:\windows\system32\drivers\gpevbz.sys . . . is infected!! . . . Failed to find a valid replacement.

.

((((((((((((((((((((((((( Files Created from 2010-07-19 to 2010-08-19 )))))))))))))))))))))))))))))))

.

2010-08-16 19:28 . 2010-08-16 19:28 -------- d-----w- c:\windows\system32\wbem\Repository

2010-08-16 18:49 . 2010-08-16 18:49 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2010-08-16 18:46 . 2010-08-16 18:46 120 ----a-w- c:\windows\Jmopadote.dat

2010-08-16 18:46 . 2010-08-16 18:46 0 ----a-w- c:\windows\Wgirahi.bin

2010-08-16 18:46 . 2010-08-16 19:27 -------- d-----w- c:\documents and settings\William Buckhold\Local Settings\Application Data\{92DE1F95-A400-4315-B451-895D9DAF0891}

2010-08-14 23:35 . 2010-08-16 19:28 -------- d-----w- C:\Netgear

2010-08-06 15:04 . 2010-08-06 15:04 -------- d-----w- c:\documents and settings\William Buckhold\Local Settings\Application Data\vxcjbimom

2010-07-28 15:52 . 2010-07-28 15:52 -------- d-----w- c:\documents and settings\William Buckhold\Application Data\Malwarebytes

2010-07-28 15:52 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-07-28 15:52 . 2010-07-28 15:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-07-28 15:52 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-07-28 15:52 . 2010-07-28 16:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-07-25 22:04 . 2010-07-25 22:04 -------- d-sh--w- c:\documents and settings\Amy Marshall\PrivacIE

2010-07-25 21:52 . 2010-07-25 21:52 -------- d-sh--w- c:\documents and settings\Amy Marshall\IETldCache

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-18 23:59 . 2006-08-03 02:19 -------- d-----w- c:\program files\Dl_cats

2010-08-18 22:32 . 2006-12-14 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater

2010-08-18 21:37 . 2006-08-19 21:44 1324 ----a-w- c:\windows\system32\d3d9caps.dat

2010-08-16 23:16 . 2010-04-30 13:24 300384 ----a-w- c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\detect.dll

2010-08-16 23:16 . 2008-03-18 01:05 300384 ----a-w- c:\documents and settings\William Buckhold\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll

2010-08-13 11:18 . 2010-02-17 18:02 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS

2010-06-30 12:31 . 2005-08-16 08:18 149504 ----a-w- c:\windows\system32\schannel.dll

2010-06-24 12:22 . 2005-08-16 08:18 916480 ----a-w- c:\windows\system32\wininet.dll

2010-06-23 13:44 . 2005-08-16 08:18 1851904 ----a-w- c:\windows\system32\win32k.sys

2010-06-22 20:58 . 2010-06-22 20:58 501936 ----a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb3E.tmp.exe

2010-06-21 15:27 . 2006-07-29 20:34 354304 ----a-w- c:\windows\system32\drivers\srv.sys

2010-06-17 14:03 . 2005-08-16 08:18 80384 ----a-w- c:\windows\system32\iccvid.dll

2010-06-16 15:42 . 2010-03-11 21:23 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-06-14 14:31 . 2005-08-16 08:40 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-06-14 07:41 . 2005-08-16 08:18 1172480 ----a-w- c:\windows\system32\msxml3.dll

2010-06-03 16:02 . 2010-03-11 20:56 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-05-27 03:08 . 2006-08-03 02:26 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys

2010-05-27 03:08 . 2006-08-03 02:26 88 --sh--r- c:\windows\system32\C644D0FFE4.sys

2010-05-23 14:57 . 2010-05-23 14:57 666112 ----a-w- c:\documents and settings\William Buckhold\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv306hw-1004220-0-main.dll

2006-08-07 17:39 . 2006-08-07 17:39 251 ----a-w- c:\program files\wt3d.ini

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]

"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-03-31 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]

"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]

"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2007-08-28 73728]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-26 30192]

"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-18 110592]

"dlcdmon.exe"="c:\program files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-07-22 430080]

"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 944\memcard.exe" [2005-08-10 286720]

"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-01-18 8192]

"tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2004-01-30 1921024]

"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]

"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]

"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]

"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-03-27 413696]

"DLCDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-06-07 69632]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-06-25 1193848]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-7-29 24576]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=

"c:\\WINDOWS\\system32\\fxsclnt.exe"=

"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Documents and Settings\\William Buckhold\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/11/2010 4:56 PM 64288]

R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [4/22/2010 9:22 AM 82952]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [9/29/2009 3:32 PM 88176]

R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/22/2010 9:22 AM 271480]

R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [4/22/2010 9:22 AM 271480]

R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [4/22/2010 9:22 AM 188136]

R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [4/22/2010 9:22 AM 141792]

R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [4/22/2010 9:22 AM 55456]

R3 dlcd_device;dlcd_device;c:\windows\system32\dlcdcoms.exe -service --> c:\windows\system32\dlcdcoms.exe -service [?]

R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [4/22/2010 9:22 AM 312616]

R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [4/22/2010 9:22 AM 88480]

S0 gpevbz;gpevbz;c:\windows\system32\drivers\gpevbz.sys [4/2/2010 4:55 PM 823808]

S2 gupdate1c986fbc422206;Google Update Service (gupdate1c986fbc422206);c:\program files\Google\Update\GoogleUpdate.exe [2/4/2009 3:01 PM 133104]

S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]

S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [7/29/2006 5:09 PM 30192]

S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1352832]

S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [4/22/2010 9:22 AM 88480]

S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [4/22/2010 9:22 AM 83496]

--- Other Services/Drivers In Memory ---

*Deregistered* - mfeavfk01

.

Contents of the 'Scheduled Tasks' folder

2010-08-18 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2006-12-14 18:33]

2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 19:01]

2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 19:01]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://yahoo.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = iexplore

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

Trusted Zone: interfleet.com\http2

Trusted Zone: internet

Trusted Zone: mcafee.com

Trusted Zone: musicmatch.com\online

DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://conleybottom1.axiscam.net/activex/AMC.cab

DPF: {FE92D9C3-4A69-4EC7-8651-1DC8531D0075} - hxxp://www.bcsrivercam.com/TSBnwCam.CAB

.

- - - - ORPHANS REMOVED - - - -

BHO-{65dbd01a-b56b-48de-8bf5-9b6aa3159029} - yezakive.dll

HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

SharedTaskScheduler-{d61d3580-784e-4774-9b0e-619a0b35aad4} - c:\windows\system32\jegohami.dll

SSODL-bubuwopek-{a6162656-0d14-4004-bff3-8256bd495616} - c:\windows\system32\nulutuni.dll

SSODL-ledeyumid-{d61d3580-784e-4774-9b0e-619a0b35aad4} - c:\windows\system32\jegohami.dll

MSConfigStartUp-zodorizaso - busogeto.dll

AddRemove-Dell Digital Jukebox Driver - c:\program files\Dell\Digital Jukebox Drivers\DrvUnins.exe

AddRemove-McAfee Clean Up Tool - c:\docume~1\WILLIA~1\LOCALS~1\TEMPOR~1\Content.IE5\A2N99RDZ\UNWISE.EXE

AddRemove-McAfee Uninstall Utility - c:\progra~1\McAfee.com\Shared\mcappins.exe

AddRemove-TurboTax 2008 - c:\documents and settings\Amy Marshall\My Documents\Amy Finances\TurboTax\Deluxe 2008\Installer\TurboTax 2008 Installer.exe

AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-08-18 20:00

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

DLCDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully

user: MBR read successfully

called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x870E4EC5]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xf7552f28

\Driver\ACPI -> ACPI.sys @ 0xf73e5cb8

\Driver\atapi -> atapi.sys @ 0xf7377852

\Driver\iaStor -> iastor.sys @ 0xf72aeb10

IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8

NDIS: Intel® PRO/1000 PL Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf713bbb0

PacketIndicateHandler -> NDIS.sys @ 0xf7148a21

SendHandler -> NDIS.sys @ 0xf712687b

user & kernel MBR OK

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1076)

c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1136)

c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(1036)

c:\windows\system32\WININET.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\eHome\ehRecvr.exe

c:\windows\eHome\ehSched.exe

c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe

c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\system32\nvsvc32.exe

c:\program files\Dell Support Center\bin\sprtsvc.exe

c:\program files\Common Files\McAfee\SystemCore\mcshield.exe

c:\program files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe

c:\windows\system32\fxssvc.exe

c:\windows\ehome\mcrdsvc.exe

c:\windows\system32\dllhost.exe

c:\windows\stsystra.exe

c:\windows\eHome\ehmsas.exe

c:\windows\system32\dlcdcoms.exe

c:\program files\MUSICMATCH\Musicmatch Jukebox\mim.exe

c:\program files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe

.

**************************************************************************

.

Completion time: 2010-08-18 20:16:38 - machine was rebooted

ComboFix-quarantined-files.txt 2010-08-19 00:16

Pre-Run: 262,109,372,416 bytes free

Post-Run: 263,383,556,096 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - F61EBF39FB843857F88F712F695D88E4

Attach.zip

Link to post
Share on other sites

Well, maybe I was overly optimistic, but ComboFix didn't seem to eliminate my problem. Both last night after running ComboFix and this morning after starting the machine for the day I am still getting browsers opening/redirecting to random websites. However, it doesn't seem to be gobbling up all the processor power like it was before when it was running up close to 80-90%. Now, when it opens a window/redirects it's a minor CPU bump. It's not constant, but happens after a few minutes or when I take the computer out of standby. I'm sure if that means anything or not, and since I don't understand the logs I don't know if the problem is the same, worse or better---I just know it's still there. I haven't tried to search to see if it's redirecting since it's randomly popping up the occasional browser on its own.

Since this is an ongoing problem, and I don't understand the nature of my infection (is it a nuisance bug or really something devious trying to steal password or data?) I have a couple of questions:

1.) I have not run any manual scans since I posted my problem. I have regularly scheduled scans and I will disable those as well unless told otherwise. I'm trying to abide by the no scans, no new software/hardware rule until this gets resolved. However, I am updating my regular active security and firewall and keeping them active unless told to deactivate to run a particular scan.

2.) What is the relative safety of using non-internet related portions of my computer? Is it relatively safe to run other programs on my computer?

3.) What is the relative safety of using the internet during our cleaning of my system?

a.) How safe is it to be on non-password sites (i.e., looking up info on this problem, clicking the various links to download programs being provided during this cleaning)

b.) How safe is it to be on pass word sites (i.e., checking email) during this process?

Like I said before, since I do not understand the nature of what is infecting my machine, I am in the dark as to what my risks are other than the normal everyday security issues.

Thanks again for you help.

Link to post
Share on other sites

Problem continues with browsers popping up and redirects. Also, this morning when I turned on the computer, I got a FlashPlayer update box. Maybe it was legit, maybe not, but I thought I would mention it as those random "update" boxes may be linked to my infection. Obviously I didn't click on it and shut it down through Task Manager without incident.

Is there anything else I can do while this issue and the logs are being reviewed? I would really like to get this thing fixed with the weekend coming up and I'd prefer to not let this thing drag into next week if possible.

Thanks!

Link to post
Share on other sites

Problem persists, maybe the random redirects and new browsers opening getting a little more frequent. There must be something in the system that wants to try and load something at start up in the morning---has happened everyday since infection with some bogus splash screen from Adobe. I turn on the computer with the modem internet kill switch on so whatever random website it is trying to send me to doesn't load, and then shut down the unwanted browser.

Ignored the above post by "JasonACS" awaiting "official" help.

Thanks for taking a look at this and providing some guidance.

Link to post
Share on other sites

Thanks for getting back to me, I think the problem is getting worse.

Virus Total Log:

MD5: 4ec2c8e861e5dec0b42c709215537b22

Date first seen: 2010-04-06 15:33:13 (UTC)

Date last seen: 2010-04-06 15:33:13 (UTC)

Detection ratio: 0/39

I clicked on the "view last report" on the report screen since I wasn't sure if you needed more info. Here is that info:

File name: gpevbz.sys

Submission date: 2010-08-22 03:02:51 (UTC)

Current status: queued (#6) queued (#6) analysing finished

Result: 0/ 42 (0.0%)

VT Community

not reviewed

Safety score: -

Compact Print results Antivirus Version Last Update Result

AhnLab-V3 2010.08.22.00 2010.08.21 -

AntiVir 8.2.4.38 2010.08.20 -

Antiy-AVL 2.0.3.7 2010.08.16 -

Authentium 5.2.0.5 2010.08.22 -

Avast 4.8.1351.0 2010.08.22 -

Avast5 5.0.332.0 2010.08.22 -

AVG 9.0.0.851 2010.08.21 -

BitDefender 7.2 2010.08.22 -

CAT-QuickHeal 11.00 2010.08.21 -

ClamAV 0.96.2.0-git 2010.08.22 -

Comodo 5811 2010.08.22 -

DrWeb 5.0.2.03300 2010.08.22 -

Emsisoft 5.0.0.37 2010.08.21 -

eSafe 7.0.17.0 2010.08.19 -

eTrust-Vet 36.1.7804 2010.08.21 -

F-Prot 4.6.1.107 2010.08.22 -

F-Secure 9.0.15370.0 2010.08.21 -

Fortinet 4.1.143.0 2010.08.21 -

GData 21 2010.08.22 -

Ikarus T3.1.1.88.0 2010.08.21 -

Jiangmin 13.0.900 2010.08.21 -

Kaspersky 7.0.0.125 2010.08.22 -

McAfee 5.400.0.1158 2010.08.22 -

McAfee-GW-Edition 2010.1B 2010.08.21 -

Microsoft 1.6103 2010.08.21 -

NOD32 5385 2010.08.21 -

Norman 6.05.11 2010.08.21 -

nProtect 2010-08-21.01 2010.08.21 -

Panda 10.0.2.7 2010.08.21 -

PCTools 7.0.3.5 2010.08.22 -

Prevx 3.0 2010.08.22 -

Rising 22.61.04.04 2010.08.20 -

Sophos 4.56.0 2010.08.22 -

Sunbelt 6773 2010.08.22 -

SUPERAntiSpyware 4.40.0.1006 2010.08.21 -

Symantec 20101.1.1.7 2010.08.22 -

TheHacker 6.5.2.1.352 2010.08.20 -

TrendMicro 9.120.0.1004 2010.08.21 -

TrendMicro-HouseCall 9.120.0.1004 2010.08.22 -

VBA32 3.12.14.0 2010.08.20 -

ViRobot 2010.8.18.3995 2010.08.21 -

VirusBuster 5.0.27.0 2010.08.21 -

Additional informationShow all

MD5 : 4ec2c8e861e5dec0b42c709215537b22

SHA1 : d78d2fa4966c1775523fd2f2eddf4bf548d3e525

SHA256: bf976bdc8d2b3799f5cb00253e1b5f411d91c546eabee1b5a07be92588465a52

Link to post
Share on other sites

And the quick scan results:

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4460

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

8/21/2010 11:21:15 PM

mbam-log-2010-08-21 (23-21-15).txt

Scan type: Quick scan

Objects scanned: 164319

Time elapsed: 17 minute(s), 19 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

I have no idea what Virus Total results mean (or most of the logs, for that matter), and I see that the Quick Scan with MBAM came up with nothing. However, I know the problem is still there with the redirects. I'll post in the morning and see if the problem is staying the same/getting worse after a fresh start up.

Thanks again for you help, it's much appreciated.

Link to post
Share on other sites

  • Staff

Hi,

Next, download MBRCheck.exe by a_d_13 and save it to your Desktop.

Run it; when it completes, a log will be available on your Desktop (MBRCheck xxxxxx .txt) where xxxxxx is the time it ran.

Next,

  • Download the file TDSSKiller.zip and extract it into a folder on the infected PC.
  • Execute the file TDSSKiller.exe by double-clicking on it.
  • Wait for the scan and disinfection process to be over.
  • When its work is over, the utility prompts for a reboot to complete the disinfection.

By default, the utility outputs runtime log into the system disk root directory (the disk where the operating system is installed, C:\ as a rule).

The log is like UtilityName.Version_Date_Time_log.txt.

for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt.

Please post that log here.

Link to post
Share on other sites

MBRCheck, version 1.2.3

© 2010, AD

Command-line:

Windows Version: Windows XP Professional

Windows Information: Service Pack 3 (build 2600)

Logical Drives Mask: 0x000003fc

Kernel Drivers (total 147):

0x804D7000 \WINDOWS\system32\ntkrnlpa.exe

0x806E4000 \WINDOWS\system32\hal.dll

0xF7B52000 \WINDOWS\system32\KDCOM.DLL

0xF7A62000 \WINDOWS\system32\BOOTVID.dll

0xF7523000 ACPI.sys

0xF7B54000 \WINDOWS\system32\DRIVERS\WMILIB.SYS

0xF7512000 pci.sys

0xF7652000 isapnp.sys

0xF7C1A000 pciide.sys

0xF78D2000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS

0xF7662000 MountMgr.sys

0xF74F3000 ftdisk.sys

0xF7B56000 dmload.sys

0xF74CD000 dmio.sys

0xF78DA000 PartMgr.sys

0xF7672000 VolSnap.sys

0xF74B5000 atapi.sys

0xF73E0000 iastor.sys

0xF7682000 disk.sys

0xF7692000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS

0xF73C0000 fltmgr.sys

0xF73AE000 sr.sys

0xF7351000 mfehidk.sys

0xF76A2000 Lbd.sys

0xF733B000 DRVMCDB.SYS

0xF76B2000 PxHelp20.sys

0xF7324000 KSecDD.sys

0xF7297000 Ntfs.sys

0xF726A000 NDIS.sys

0xF7250000 Mup.sys

0xF7752000 \SystemRoot\system32\DRIVERS\intelppm.sys

0xF5651000 \SystemRoot\system32\DRIVERS\nv4_mini.sys

0xF563D000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS

0xF5615000 \SystemRoot\system32\DRIVERS\HDAudBus.sys

0xF55D3000 \SystemRoot\system32\DRIVERS\atinavrr.sys

0xF55B0000 \SystemRoot\system32\DRIVERS\ks.sys

0xF7B1A000 \SystemRoot\system32\DRIVERS\BdaSup.SYS

0xF5583000 \SystemRoot\system32\DRIVERS\e1e5132.sys

0xF79BA000 \SystemRoot\system32\DRIVERS\usbuhci.sys

0xF555F000 \SystemRoot\system32\DRIVERS\USBPORT.SYS

0xF79AA000 \SystemRoot\system32\DRIVERS\usbehci.sys

0xF552B000 \SystemRoot\system32\DRIVERS\HSFHWBS2.sys

0xF542C000 \SystemRoot\system32\DRIVERS\HSF_DP.sys

0xF5385000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys

0xF79C2000 \SystemRoot\System32\Drivers\Modem.SYS

0xF7BA8000 \SystemRoot\System32\Drivers\DLACDBHM.SYS

0xF7782000 \SystemRoot\system32\DRIVERS\cdrom.sys

0xF7792000 \SystemRoot\system32\DRIVERS\redbook.sys

0xF77A2000 \SystemRoot\system32\DRIVERS\imapi.sys

0xF7BAA000 \SystemRoot\system32\DRIVERS\ELacpi.sys

0xF7CA5000 \SystemRoot\system32\DRIVERS\audstub.sys

0xF5371000 \SystemRoot\system32\DRIVERS\mfendisk.sys

0xF77B2000 \SystemRoot\system32\DRIVERS\rasl2tp.sys

0xF7B2A000 \SystemRoot\system32\DRIVERS\ndistapi.sys

0xF535A000 \SystemRoot\system32\DRIVERS\ndiswan.sys

0xF77C2000 \SystemRoot\system32\DRIVERS\raspppoe.sys

0xF77D2000 \SystemRoot\system32\DRIVERS\raspptp.sys

0xF79CA000 \SystemRoot\system32\DRIVERS\TDI.SYS

0xF5349000 \SystemRoot\system32\DRIVERS\psched.sys

0xF7852000 \SystemRoot\system32\DRIVERS\msgpc.sys

0xF5325000 \SystemRoot\system32\drivers\mfeavfk.sys

0xF52DA000 \SystemRoot\system32\drivers\mfefirek.sys

0xF79D2000 \SystemRoot\system32\DRIVERS\ptilink.sys

0xF79DA000 \SystemRoot\system32\DRIVERS\raspti.sys

0xF5282000 \SystemRoot\system32\DRIVERS\rdpdr.sys

0xF7862000 \SystemRoot\system32\DRIVERS\termdd.sys

0xF79E2000 \SystemRoot\system32\DRIVERS\kbdclass.sys

0xF79EA000 \SystemRoot\system32\DRIVERS\mouclass.sys

0xF7BB0000 \SystemRoot\system32\DRIVERS\swenum.sys

0xF5224000 \SystemRoot\system32\DRIVERS\update.sys

0xF5CF3000 \SystemRoot\system32\DRIVERS\mssmbios.sys

0xF5CEF000 \SystemRoot\system32\drivers\MODEMCSA.sys

0xF7882000 \SystemRoot\System32\Drivers\NDProxy.SYS

0xEED64000 \SystemRoot\system32\drivers\sthda.sys

0xEED40000 \SystemRoot\system32\drivers\portcls.sys

0xF0584000 \SystemRoot\system32\drivers\drmk.sys

0xF0574000 \SystemRoot\system32\DRIVERS\usbhub.sys

0xF7BFC000 \SystemRoot\system32\DRIVERS\USBD.SYS

0xF5208000 \SystemRoot\System32\Drivers\i2omgmt.SYS

0xF7C02000 \SystemRoot\System32\Drivers\Fs_Rec.SYS

0xEF2FE000 \SystemRoot\System32\Drivers\Null.SYS

0xF7C04000 \SystemRoot\System32\Drivers\Beep.SYS

0xF148E000 \SystemRoot\System32\Drivers\DLARTL_N.SYS

0xF1486000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS

0xF147E000 \SystemRoot\System32\drivers\vga.sys

0xF7C06000 \SystemRoot\System32\Drivers\mnmdd.SYS

0xF7C08000 \SystemRoot\System32\DRIVERS\RDPCDD.sys

0xF1476000 \SystemRoot\System32\Drivers\Msfs.SYS

0xF146E000 \SystemRoot\System32\Drivers\Npfs.SYS

0xF51FC000 \SystemRoot\system32\DRIVERS\rasacd.sys

0xECB65000 \SystemRoot\system32\DRIVERS\ipsec.sys

0xECB0C000 \SystemRoot\system32\DRIVERS\tcpip.sys

0xECAF9000 \SystemRoot\system32\drivers\mfetdi2k.sys

0xECAD3000 \SystemRoot\system32\DRIVERS\ipnat.sys

0xECAAB000 \SystemRoot\system32\DRIVERS\netbt.sys

0xEEEBB000 \SystemRoot\system32\DRIVERS\wanarp.sys

0xECA61000 \SystemRoot\System32\drivers\afd.sys

0xEEEAB000 \SystemRoot\system32\DRIVERS\netbios.sys

0xECA03000 \SystemRoot\system32\DRIVERS\rdbss.sys

0xEC993000 \SystemRoot\system32\DRIVERS\mrxsmb.sys

0xF05B4000 \SystemRoot\System32\Drivers\Fips.SYS

0xEBFF2000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS

0xEBFEA000 \SystemRoot\system32\DRIVERS\usbccgp.sys

0xF7B80000 \SystemRoot\System32\DRIVERS\ELmou.sys

0xF7B82000 \SystemRoot\System32\DRIVERS\ELmon.sys

0xF7B84000 \SystemRoot\System32\DRIVERS\ELkbd.sys

0xEEE70000 \SystemRoot\System32\DRIVERS\ELhid.sys

0xB8817000 \SystemRoot\system32\DRIVERS\usbscan.sys

0xB7BD6000 \SystemRoot\system32\DRIVERS\usbprint.sys

0xB8813000 \SystemRoot\system32\DRIVERS\hidusb.sys

0xB846D000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS

0xB845D000 \SystemRoot\system32\DRIVERS\IrBus.sys

0xB8174000 \SystemRoot\system32\DRIVERS\mouhid.sys

0xB816C000 \SystemRoot\system32\DRIVERS\kbdhid.sys

0xEBFE2000 \SystemRoot\system32\DRIVERS\hidir.sys

0xB7190000 \SystemRoot\System32\Drivers\Cdfs.SYS

0xB6D9A000 \SystemRoot\System32\Drivers\dump_iastor.sys

0xBF800000 \SystemRoot\System32\win32k.sys

0xEB05B000 \SystemRoot\System32\drivers\Dxapi.sys

0xEBFCA000 \SystemRoot\System32\watchdog.sys

0xBF000000 \SystemRoot\System32\drivers\dxg.sys

0xF7D03000 \SystemRoot\System32\drivers\dxgthk.sys

0xBF012000 \SystemRoot\System32\nv4_disp.dll

0xBFFA0000 \SystemRoot\System32\ATMFD.DLL

0xF7772000 \SystemRoot\System32\Drivers\DRVNDDM.SYS

0xB747B000 \SystemRoot\System32\DLA\DLADResN.SYS

0xB63E1000 \SystemRoot\System32\DLA\DLAIFS_M.SYS

0xF19DA000 \SystemRoot\System32\DLA\DLAOPIOM.SYS

0xF7BEA000 \SystemRoot\System32\DLA\DLAPoolM.SYS

0xF7942000 \SystemRoot\System32\DLA\DLABOIOM.SYS

0xB63C9000 \SystemRoot\System32\DLA\DLAUDFAM.SYS

0xB63B3000 \SystemRoot\System32\DLA\DLAUDF_M.SYS

0xB71D4000 \SystemRoot\system32\DRIVERS\ndisuio.sys

0xB634E000 \SystemRoot\system32\drivers\wdmaud.sys

0xF78C2000 \SystemRoot\system32\drivers\sysaudio.sys

0xB60CC000 \SystemRoot\system32\DRIVERS\mrxdav.sys

0xB894A000 \SystemRoot\system32\DRIVERS\dsunidrv.sys

0xB5B63000 \SystemRoot\System32\Drivers\HTTP.sys

0xF7B9A000 \SystemRoot\system32\drivers\MSPQM.sys

0xB597C000 \SystemRoot\system32\DRIVERS\srv.sys

0xB5794000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys

0xB5178000 \SystemRoot\system32\drivers\cfwids.sys

0xB3448000 \SystemRoot\system32\drivers\mfeapfk.sys

0xB400A000 \SystemRoot\system32\drivers\mfebopk.sys

0xB8952000 \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys

0xB341D000 \SystemRoot\system32\drivers\kmixer.sys

0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 58):

0 System Idle Process

4 System

988 C:\WINDOWS\system32\smss.exe

1048 csrss.exe

1072 C:\WINDOWS\system32\winlogon.exe

1120 C:\WINDOWS\system32\services.exe

1132 C:\WINDOWS\system32\lsass.exe

1400 C:\WINDOWS\system32\svchost.exe

1476 svchost.exe

1644 C:\WINDOWS\system32\svchost.exe

1700 svchost.exe

1968 svchost.exe

228 C:\WINDOWS\system32\spoolsv.exe

616 C:\WINDOWS\explorer.exe

796 C:\WINDOWS\ehome\ehtray.exe

812 C:\WINDOWS\stsystra.exe

820 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

844 C:\WINDOWS\system32\DLA\DLACTRLW.EXE

856 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

888 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe

948 C:\Program Files\Dell Photo AIO Printer 944\memcard.exe

964 C:\Program Files\Support.com\bin\tgcmd.exe

1460 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

1528 C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe

1560 C:\Program Files\Dell Support Center\bin\sprtcmd.exe

1580 svchost.exe

1816 C:\Program Files\McAfee.com\Agent\mcagent.exe

1708 C:\Program Files\DellSupport\DSAgnt.exe

1920 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

1988 C:\WINDOWS\ehome\ehrecvr.exe

1880 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

512 C:\WINDOWS\system32\ctfmon.exe

1380 C:\WINDOWS\ehome\ehSched.exe

788 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe

1268 C:\Program Files\Digital Line Detect\DLG.exe

2284 C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

2328 C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe

2484 C:\Program Files\Java\jre6\bin\jqs.exe

2696 C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

3096 C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

3284 C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe

3380 C:\WINDOWS\system32\nvsvc32.exe

3552 C:\Program Files\Dell Support Center\bin\sprtsvc.exe

3668 svchost.exe

3740 C:\WINDOWS\system32\svchost.exe

3916 C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe

3972 C:\WINDOWS\system32\fxssvc.exe

1252 mcrdsvc.exe

460 C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe

2420 C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe

4212 C:\WINDOWS\system32\dllhost.exe

5036 C:\WINDOWS\ehome\ehmsas.exe

5168 C:\WINDOWS\system32\dlcdcoms.exe

5784 alg.exe

4008 C:\WINDOWS\system32\svchost.exe

760 C:\PROGRA~1\McAfee\MSM\McSmtFwk.exe

4908 C:\PROGRA~1\COMMON~1\McAfee\MSC\McUICnt.exe

2880 C:\Documents and Settings\William Buckhold\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`036e8e00 (NTFS)

PhysicalDrive0 Model Number: WDCWD3200KS-75PFB0, Rev: 21.00M21

Size Device Name MBR Status

--------------------------------------------

298 GB \\.\PhysicalDrive0 Dell MBR code detected

SHA1: 57BDF501CE769EF2720C705B6C71C893DA31574E

Done!

Link to post
Share on other sites

Here's the TDSS log. It found one item and fixed it and asked for a reboot, but the scan was VERY VERY fast. I guess I was expecting a much longer scan like ComboFix was. Normal to scan that fast?

Thanks.

2010/08/22 09:14:52.0484 TDSS rootkit removing tool 2.4.1.2 Aug 16 2010 09:46:23

2010/08/22 09:14:52.0484 ================================================================================

2010/08/22 09:14:52.0484 SystemInfo:

2010/08/22 09:14:52.0484

2010/08/22 09:14:52.0484 OS Version: 5.1.2600 ServicePack: 3.0

2010/08/22 09:14:52.0484 Product type: Workstation

2010/08/22 09:14:52.0484 ComputerName: DHYNSHB1

2010/08/22 09:14:52.0484 UserName: William Buckhold

2010/08/22 09:14:52.0484 Windows directory: C:\WINDOWS

2010/08/22 09:14:52.0484 System windows directory: C:\WINDOWS

2010/08/22 09:14:52.0484 Processor architecture: Intel x86

2010/08/22 09:14:52.0484 Number of processors: 2

2010/08/22 09:14:52.0484 Page size: 0x1000

2010/08/22 09:14:52.0484 Boot type: Normal boot

2010/08/22 09:14:52.0484 ================================================================================

2010/08/22 09:14:52.0812 Initialize success

2010/08/22 09:15:11.0843 ================================================================================

2010/08/22 09:15:11.0843 Scan started

2010/08/22 09:15:11.0843 Mode: Manual;

2010/08/22 09:15:11.0843 ================================================================================

2010/08/22 09:15:12.0109 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS

2010/08/22 09:15:12.0171 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys

2010/08/22 09:15:12.0218 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys

2010/08/22 09:15:12.0265 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys

2010/08/22 09:15:12.0296 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys

2010/08/22 09:15:12.0343 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys

2010/08/22 09:15:12.0375 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys

2010/08/22 09:15:12.0390 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys

2010/08/22 09:15:12.0437 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys

2010/08/22 09:15:12.0453 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys

2010/08/22 09:15:12.0468 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys

2010/08/22 09:15:12.0500 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys

2010/08/22 09:15:12.0515 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys

2010/08/22 09:15:12.0531 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys

2010/08/22 09:15:12.0546 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys

2010/08/22 09:15:12.0578 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys

2010/08/22 09:15:12.0593 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys

2010/08/22 09:15:12.0609 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys

2010/08/22 09:15:12.0656 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

2010/08/22 09:15:12.0671 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys

2010/08/22 09:15:12.0718 ATIAVPCI (b27fec21c1125bab7d3c8cdf872e627b) C:\WINDOWS\system32\DRIVERS\atinavrr.sys

2010/08/22 09:15:12.0734 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

2010/08/22 09:15:12.0765 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

2010/08/22 09:15:12.0796 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

2010/08/22 09:15:12.0859 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys

2010/08/22 09:15:12.0875 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

2010/08/22 09:15:12.0890 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys

2010/08/22 09:15:12.0921 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys

2010/08/22 09:15:12.0937 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

2010/08/22 09:15:12.0953 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys

2010/08/22 09:15:12.0984 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys

2010/08/22 09:15:13.0031 cfwids (44e4a7dded054dd55ae995c3aed719ae) C:\WINDOWS\system32\drivers\cfwids.sys

2010/08/22 09:15:13.0078 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys

2010/08/22 09:15:13.0109 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys

2010/08/22 09:15:13.0140 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys

2010/08/22 09:15:13.0156 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys

2010/08/22 09:15:13.0171 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys

2010/08/22 09:15:13.0234 DLABOIOM (e2d0de31442390c35e3163c87cb6a9eb) C:\WINDOWS\system32\DLA\DLABOIOM.SYS

2010/08/22 09:15:13.0281 DLACDBHM (d979bebcf7edcc9c9ee1857d1a68c67b) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS

2010/08/22 09:15:13.0296 DLADResN (83545593e297f50a8e2524b4c071a153) C:\WINDOWS\system32\DLA\DLADResN.SYS

2010/08/22 09:15:13.0359 DLAIFS_M (96e01d901cdc98c7817155cc057001bf) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS

2010/08/22 09:15:13.0421 DLAOPIOM (0a60a39cc5e767980a31ca5d7238dfa9) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS

2010/08/22 09:15:13.0500 DLAPoolM (9fe2b72558fc808357f427fd83314375) C:\WINDOWS\system32\DLA\DLAPoolM.SYS

2010/08/22 09:15:13.0578 DLARTL_N (7ee0852ae8907689df25049dcd2342e8) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS

2010/08/22 09:15:13.0593 DLAUDFAM (f08e1dafac457893399e03430a6a1397) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS

2010/08/22 09:15:13.0625 DLAUDF_M (e7d105ed1e694449d444a9933df8e060) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS

2010/08/22 09:15:13.0750 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys

2010/08/22 09:15:13.0781 dmio (20466c312bf9b59722cccd33a19434a5) C:\WINDOWS\system32\drivers\dmio.sys

2010/08/22 09:15:13.0781 Suspicious file (Forged): C:\WINDOWS\system32\drivers\dmio.sys. Real md5: 20466c312bf9b59722cccd33a19434a5, Fake md5: 7c824cf7bbde77d95c08005717a95f6f

2010/08/22 09:15:13.0781 dmio - detected Rootkit.Win32.TDSS.tdl3 (0)

2010/08/22 09:15:13.0796 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

2010/08/22 09:15:13.0828 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys

2010/08/22 09:15:13.0859 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys

2010/08/22 09:15:13.0906 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys

2010/08/22 09:15:13.0921 DRVMCDB (fd0f95981fef9073659d8ec58e40aa3c) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS

2010/08/22 09:15:13.0937 DRVNDDM (b4869d320428cdc5ec4d7f5e808e99b5) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS

2010/08/22 09:15:14.0015 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys

2010/08/22 09:15:14.0140 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys

2010/08/22 09:15:14.0187 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys

2010/08/22 09:15:14.0250 e1express (0849eacdc01487573add86f5e470806c) C:\WINDOWS\system32\DRIVERS\e1e5132.sys

2010/08/22 09:15:14.0281 ELacpi (1976fedf6d7f87135c9b7f5cb4c8c868) C:\WINDOWS\system32\DRIVERS\ELacpi.sys

2010/08/22 09:15:14.0312 ELhid (ae65c02444907966378454138b9f99f0) C:\WINDOWS\system32\DRIVERS\ELhid.sys

2010/08/22 09:15:14.0328 ELkbd (e485c3ba1daddeef3e14fea1e8fda6e1) C:\WINDOWS\system32\DRIVERS\ELkbd.sys

2010/08/22 09:15:14.0343 ELmon (0d87cb825ed6cb2ebcc147a10a42f1d6) C:\WINDOWS\system32\DRIVERS\ELmon.sys

2010/08/22 09:15:14.0359 ELmou (a4add3847b67bacab6fc851a2b60fdb3) C:\WINDOWS\system32\DRIVERS\ELmou.sys

2010/08/22 09:15:14.0406 ENTECH (fd9fc82f134b1c91004ffc76a5ae494b) C:\WINDOWS\system32\DRIVERS\ENTECH.sys

2010/08/22 09:15:14.0437 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys

2010/08/22 09:15:14.0468 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys

2010/08/22 09:15:14.0484 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys

2010/08/22 09:15:14.0515 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys

2010/08/22 09:15:14.0531 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys

2010/08/22 09:15:14.0546 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

2010/08/22 09:15:14.0593 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

2010/08/22 09:15:14.0671 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys

2010/08/22 09:15:14.0765 gpevbz (4ec2c8e861e5dec0b42c709215537b22) C:\WINDOWS\system32\drivers\gpevbz.sys

2010/08/22 09:15:14.0843 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys

2010/08/22 09:15:14.0875 HidIr (bb1a6fb7d35a91e599973fa74a619056) C:\WINDOWS\system32\DRIVERS\hidir.sys

2010/08/22 09:15:14.0906 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys

2010/08/22 09:15:14.0984 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys

2010/08/22 09:15:15.0031 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys

2010/08/22 09:15:15.0062 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys

2010/08/22 09:15:15.0140 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys

2010/08/22 09:15:15.0171 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys

2010/08/22 09:15:15.0203 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys

2010/08/22 09:15:15.0218 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys

2010/08/22 09:15:15.0250 iastor (9a65e42664d1534b68512caad0efe963) C:\WINDOWS\system32\drivers\iastor.sys

2010/08/22 09:15:15.0281 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys

2010/08/22 09:15:15.0296 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys

2010/08/22 09:15:15.0343 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys

2010/08/22 09:15:15.0375 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys

2010/08/22 09:15:15.0421 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys

2010/08/22 09:15:15.0484 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

2010/08/22 09:15:15.0500 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys

2010/08/22 09:15:15.0531 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys

2010/08/22 09:15:15.0578 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys

2010/08/22 09:15:15.0609 IrBus (b43b36b382aea10861f7c7a37f9d4ae2) C:\WINDOWS\system32\DRIVERS\IrBus.sys

2010/08/22 09:15:15.0656 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys

2010/08/22 09:15:15.0671 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys

2010/08/22 09:15:15.0718 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

2010/08/22 09:15:15.0734 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys

2010/08/22 09:15:15.0781 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys

2010/08/22 09:15:15.0812 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys

2010/08/22 09:15:15.0859 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys

2010/08/22 09:15:15.0953 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys

2010/08/22 09:15:16.0000 mfeapfk (b77e959e1c50d3e3a9d9ef423be62e09) C:\WINDOWS\system32\drivers\mfeapfk.sys

2010/08/22 09:15:16.0015 mfeavfk (e84596fcb591117f5597498a5f82ad97) C:\WINDOWS\system32\drivers\mfeavfk.sys

2010/08/22 09:15:16.0109 mfebopk (d40ce01e2d3fe0c079cd2d6b3e4b823b) C:\WINDOWS\system32\drivers\mfebopk.sys

2010/08/22 09:15:16.0140 mfefirek (3962c6a9e35c4319dcdab0497614fd69) C:\WINDOWS\system32\drivers\mfefirek.sys

2010/08/22 09:15:16.0171 mfehidk (e7ecf7872bf8f2897ae5a696d908c2f7) C:\WINDOWS\system32\drivers\mfehidk.sys

2010/08/22 09:15:16.0187 mfendisk (554dbbdc8c3b4f380b21269239bd29bb) C:\WINDOWS\system32\DRIVERS\mfendisk.sys

2010/08/22 09:15:16.0203 mfendiskmp (554dbbdc8c3b4f380b21269239bd29bb) C:\WINDOWS\system32\DRIVERS\mfendisk.sys

2010/08/22 09:15:16.0218 mferkdet (e411594ac94baef7f8ea991cc8f47fd1) C:\WINDOWS\system32\drivers\mferkdet.sys

2010/08/22 09:15:16.0265 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\WINDOWS\system32\drivers\mferkdk.sys

2010/08/22 09:15:16.0328 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\WINDOWS\system32\drivers\mfesmfk.sys

2010/08/22 09:15:16.0375 mfetdi2k (1bfe4c4ccf8cd2d7deaffb424e691196) C:\WINDOWS\system32\drivers\mfetdi2k.sys

2010/08/22 09:15:16.0437 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys

2010/08/22 09:15:16.0453 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

2010/08/22 09:15:16.0468 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys

2010/08/22 09:15:16.0515 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys

2010/08/22 09:15:16.0531 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys

2010/08/22 09:15:16.0562 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys

2010/08/22 09:15:16.0593 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys

2010/08/22 09:15:16.0625 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys

2010/08/22 09:15:16.0671 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys

2010/08/22 09:15:16.0687 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

2010/08/22 09:15:16.0750 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

2010/08/22 09:15:16.0781 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys

2010/08/22 09:15:16.0828 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys

2010/08/22 09:15:16.0843 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

2010/08/22 09:15:16.0875 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys

2010/08/22 09:15:16.0906 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

2010/08/22 09:15:16.0937 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys

2010/08/22 09:15:16.0968 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys

2010/08/22 09:15:17.0015 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys

2010/08/22 09:15:17.0062 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys

2010/08/22 09:15:17.0093 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys

2010/08/22 09:15:17.0125 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

2010/08/22 09:15:17.0156 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

2010/08/22 09:15:17.0171 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

2010/08/22 09:15:17.0187 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys

2010/08/22 09:15:17.0203 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys

2010/08/22 09:15:17.0218 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys

2010/08/22 09:15:17.0265 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys

2010/08/22 09:15:17.0281 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys

2010/08/22 09:15:17.0312 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

2010/08/22 09:15:17.0500 nv (5950e6cc9fb3fabb61604d395dbc8550) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys

2010/08/22 09:15:17.0703 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

2010/08/22 09:15:17.0718 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

2010/08/22 09:15:17.0750 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys

2010/08/22 09:15:17.0765 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys

2010/08/22 09:15:17.0796 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys

2010/08/22 09:15:17.0812 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys

2010/08/22 09:15:17.0843 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys

2010/08/22 09:15:17.0890 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys

2010/08/22 09:15:18.0015 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys

2010/08/22 09:15:18.0078 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys

2010/08/22 09:15:18.0109 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys

2010/08/22 09:15:18.0156 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys

2010/08/22 09:15:18.0171 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

2010/08/22 09:15:18.0187 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys

2010/08/22 09:15:18.0234 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys

2010/08/22 09:15:18.0296 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys

2010/08/22 09:15:18.0328 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys

2010/08/22 09:15:18.0343 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys

2010/08/22 09:15:18.0437 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys

2010/08/22 09:15:18.0484 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

2010/08/22 09:15:18.0500 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

2010/08/22 09:15:18.0531 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

2010/08/22 09:15:18.0546 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

2010/08/22 09:15:18.0593 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys

2010/08/22 09:15:18.0609 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

2010/08/22 09:15:18.0625 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys

2010/08/22 09:15:18.0687 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys

2010/08/22 09:15:18.0734 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys

2010/08/22 09:15:18.0812 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys

2010/08/22 09:15:18.0843 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys

2010/08/22 09:15:18.0875 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys

2010/08/22 09:15:18.0921 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys

2010/08/22 09:15:18.0984 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys

2010/08/22 09:15:19.0046 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys

2010/08/22 09:15:19.0093 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys

2010/08/22 09:15:19.0125 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys

2010/08/22 09:15:19.0156 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys

2010/08/22 09:15:19.0203 Srv (da852e3e0bf1cea75d756f9866241e57) C:\WINDOWS\system32\DRIVERS\srv.sys

2010/08/22 09:15:19.0281 STHDA (2a2dc39623adef8ab3703ab9fac4b440) C:\WINDOWS\system32\drivers\sthda.sys

2010/08/22 09:15:19.0343 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys

2010/08/22 09:15:19.0375 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys

2010/08/22 09:15:19.0390 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys

2010/08/22 09:15:19.0453 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys

2010/08/22 09:15:19.0468 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys

2010/08/22 09:15:19.0500 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys

2010/08/22 09:15:19.0515 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys

2010/08/22 09:15:19.0562 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys

2010/08/22 09:15:19.0609 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys

2010/08/22 09:15:19.0640 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys

2010/08/22 09:15:19.0671 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys

2010/08/22 09:15:19.0718 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys

2010/08/22 09:15:19.0765 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys

2010/08/22 09:15:19.0812 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys

2010/08/22 09:15:19.0828 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys

2010/08/22 09:15:19.0875 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys

2010/08/22 09:15:19.0921 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

2010/08/22 09:15:19.0937 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys

2010/08/22 09:15:19.0953 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys

2010/08/22 09:15:19.0984 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys

2010/08/22 09:15:20.0000 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys

2010/08/22 09:15:20.0015 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

2010/08/22 09:15:20.0046 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

2010/08/22 09:15:20.0078 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys

2010/08/22 09:15:20.0109 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys

2010/08/22 09:15:20.0156 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys

2010/08/22 09:15:20.0171 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys

2010/08/22 09:15:20.0203 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys

2010/08/22 09:15:20.0281 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys

2010/08/22 09:15:20.0328 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys

2010/08/22 09:15:20.0453 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS

2010/08/22 09:15:20.0546 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys

2010/08/22 09:15:20.0640 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys

2010/08/22 09:15:20.0687 ================================================================================

2010/08/22 09:15:20.0687 Scan finished

2010/08/22 09:15:20.0687 ================================================================================

2010/08/22 09:15:20.0703 Detected object count: 1

2010/08/22 09:15:28.0312 dmio (20466c312bf9b59722cccd33a19434a5) C:\WINDOWS\system32\drivers\dmio.sys

2010/08/22 09:15:28.0312 Suspicious file (Forged): C:\WINDOWS\system32\drivers\dmio.sys. Real md5: 20466c312bf9b59722cccd33a19434a5, Fake md5: 7c824cf7bbde77d95c08005717a95f6f

2010/08/22 09:15:28.0843 Backup copy found, using it..

2010/08/22 09:15:28.0859 C:\WINDOWS\system32\drivers\dmio.sys - will be cured after reboot

2010/08/22 09:15:28.0859 Rootkit.Win32.TDSS.tdl3(dmio) - User select action: Cure

2010/08/22 09:15:55.0031 Deinitialize success

Link to post
Share on other sites

  • Staff

Hi,

Here's the TDSS log. It found one item and fixed it and asked for a reboot, but the scan was VERY VERY fast. I guess I was expecting a much longer scan like ComboFix was. Normal to scan that fast?
Yes that's normal. How are things running now? Grab a fresh copy of ComboFix, run it, and post its log. Also post a fresh DDS log.
Link to post
Share on other sites

ComboFix 10-08-23.01 - William Buckhold 08/23/2010 20:39:47.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.586 [GMT -4:00]

Running from: c:\documents and settings\William Buckhold\Desktop\ComboFix.exe

AV: McAfee Anti-Virus and Anti-Spyware *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

* Created a new restore point

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\William Buckhold\Local Settings\Application Data\{92DE1F95-A400-4315-B451-895D9DAF0891}

c:\documents and settings\William Buckhold\Local Settings\Application Data\{92DE1F95-A400-4315-B451-895D9DAF0891}\chrome\content\_cfg.js

c:\documents and settings\William Buckhold\Local Settings\Application Data\{92DE1F95-A400-4315-B451-895D9DAF0891}\chrome\content\overlay.xul

c:\documents and settings\William Buckhold\Local Settings\Application Data\{92DE1F95-A400-4315-B451-895D9DAF0891}\install.rdf

.

((((((((((((((((((((((((( Files Created from 2010-07-24 to 2010-08-24 )))))))))))))))))))))))))))))))

.

2010-08-16 19:28 . 2010-08-16 19:28 -------- d-----w- c:\windows\system32\wbem\Repository

2010-08-16 18:49 . 2010-08-16 18:49 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2010-08-16 18:46 . 2010-08-16 18:46 120 ----a-w- c:\windows\Jmopadote.dat

2010-08-16 18:46 . 2010-08-16 18:46 0 ----a-w- c:\windows\Wgirahi.bin

2010-08-14 23:35 . 2010-08-16 19:28 -------- d-----w- C:\Netgear

2010-08-06 15:04 . 2010-08-06 15:04 -------- d-----w- c:\documents and settings\William Buckhold\Local Settings\Application Data\vxcjbimom

2010-07-28 15:52 . 2010-07-28 15:52 -------- d-----w- c:\documents and settings\William Buckhold\Application Data\Malwarebytes

2010-07-28 15:52 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-07-28 15:52 . 2010-07-28 15:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-07-28 15:52 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-07-28 15:52 . 2010-07-28 16:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-07-25 22:04 . 2010-07-25 22:04 -------- d-sh--w- c:\documents and settings\Amy Marshall\PrivacIE

2010-07-25 21:52 . 2010-07-25 21:52 -------- d-sh--w- c:\documents and settings\Amy Marshall\IETldCache

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-23 20:01 . 2006-12-14 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater

2010-08-23 11:05 . 2006-08-03 02:19 -------- d-----w- c:\program files\Dl_cats

2010-08-22 13:16 . 2005-08-16 08:18 153344 ----a-w- c:\windows\system32\drivers\dmio.sys

2010-08-22 03:31 . 2006-08-19 21:44 1324 ----a-w- c:\windows\system32\d3d9caps.dat

2010-08-16 23:16 . 2010-04-30 13:24 300384 ----a-w- c:\documents and settings\All Users\Application Data\McAfee\Supportability\Content\MVT\XMLFiles\detect.dll

2010-08-16 23:16 . 2008-03-18 01:05 300384 ----a-w- c:\documents and settings\William Buckhold\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll

2010-08-13 11:18 . 2010-02-17 18:02 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS

2010-06-30 12:31 . 2005-08-16 08:18 149504 ----a-w- c:\windows\system32\schannel.dll

2010-06-24 12:22 . 2005-08-16 08:18 916480 ----a-w- c:\windows\system32\wininet.dll

2010-06-23 13:44 . 2005-08-16 08:18 1851904 ----a-w- c:\windows\system32\win32k.sys

2010-06-22 20:58 . 2010-06-22 20:58 501936 ----a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb3E.tmp.exe

2010-06-21 15:27 . 2006-07-29 20:34 354304 ----a-w- c:\windows\system32\drivers\srv.sys

2010-06-17 14:03 . 2005-08-16 08:18 80384 ----a-w- c:\windows\system32\iccvid.dll

2010-06-16 15:42 . 2010-03-11 21:23 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-06-14 14:31 . 2005-08-16 08:40 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-06-14 07:41 . 2005-08-16 08:18 1172480 ----a-w- c:\windows\system32\msxml3.dll

2010-06-03 16:02 . 2010-03-11 20:56 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys

2010-05-27 03:08 . 2006-08-03 02:26 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys

2010-05-27 03:08 . 2006-08-03 02:26 88 --sh--r- c:\windows\system32\C644D0FFE4.sys

2006-08-07 17:39 . 2006-08-07 17:39 251 ----a-w- c:\program files\wt3d.ini

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]

"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-03-31 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]

"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]

"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2007-08-28 73728]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-26 30192]

"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-18 110592]

"dlcdmon.exe"="c:\program files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-07-22 430080]

"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 944\memcard.exe" [2005-08-10 286720]

"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-01-18 8192]

"tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2004-01-30 1921024]

"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]

"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]

"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]

"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-03-27 413696]

"DLCDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-06-07 69632]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-06-25 1193848]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-7-29 24576]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=

"c:\\WINDOWS\\system32\\fxsclnt.exe"=

"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Documents and Settings\\William Buckhold\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/11/2010 4:56 PM 64288]

R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [4/22/2010 9:22 AM 82952]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [9/29/2009 3:32 PM 88176]

R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/22/2010 9:22 AM 271480]

R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [4/22/2010 9:22 AM 271480]

R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [4/22/2010 9:22 AM 188136]

R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [4/22/2010 9:22 AM 141792]

R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [4/22/2010 9:22 AM 55456]

R3 dlcd_device;dlcd_device;c:\windows\system32\dlcdcoms.exe -service --> c:\windows\system32\dlcdcoms.exe -service [?]

R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [4/22/2010 9:22 AM 312616]

R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [4/22/2010 9:22 AM 88480]

S0 gpevbz;gpevbz;c:\windows\system32\drivers\gpevbz.sys [4/2/2010 4:55 PM 823808]

S2 gupdate1c986fbc422206;Google Update Service (gupdate1c986fbc422206);c:\program files\Google\Update\GoogleUpdate.exe [2/4/2009 3:01 PM 133104]

S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]

S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [7/29/2006 5:09 PM 30192]

S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1352832]

S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [4/22/2010 9:22 AM 88480]

S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [4/22/2010 9:22 AM 83496]

--- Other Services/Drivers In Memory ---

*Deregistered* - mfeavfk01

.

Contents of the 'Scheduled Tasks' folder

2010-08-23 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2006-12-14 18:33]

2010-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 19:01]

2010-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 19:01]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://yahoo.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = iexplore

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

Trusted Zone: interfleet.com\http2

Trusted Zone: internet

Trusted Zone: mcafee.com

Trusted Zone: musicmatch.com\online

DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://conleybottom1.axiscam.net/activex/AMC.cab

DPF: {FE92D9C3-4A69-4EC7-8651-1DC8531D0075} - hxxp://www.bcsrivercam.com/TSBnwCam.CAB

.

- - - - ORPHANS REMOVED - - - -

SafeBoot-klmdb.sys

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-08-23 20:51

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

DLCDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

Completion time: 2010-08-23 20:56:36

ComboFix-quarantined-files.txt 2010-08-24 00:56

ComboFix2.txt 2010-08-19 00:16

Pre-Run: 263,445,217,280 bytes free

Post-Run: 263,428,792,320 bytes free

- - End Of File - - 16EBD08D895C4EF90D8A7603887EAF12

Link to post
Share on other sites

DDS (Ver_10-03-17.01) - NTFSx86

Run by William Buckhold at 21:05:45.81 on Mon 08/23/2010

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.526 [GMT -4:00]

AV: McAfee Anti-Virus and Anti-Spyware *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\ehome\ehtray.exe

C:\WINDOWS\stsystra.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe

C:\WINDOWS\System32\DLA\DLACTRLW.EXE

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe

C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe

C:\Program Files\Dell Photo AIO Printer 944\memcard.exe

C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe

svchost.exe

C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe

C:\Program Files\McAfee.com\Agent\mcagent.exe

C:\Program Files\DellSupport\DSAgnt.exe

C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe

C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Dell Support Center\bin\sprtsvc.exe

svchost.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe

C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe

C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe

C:\WINDOWS\system32\fxssvc.exe

C:\WINDOWS\system32\dlcdcoms.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\WINDOWS\explorer.exe

C:\Documents and Settings\William Buckhold\Desktop\dds.scr

C:\WINDOWS\system32\rundll32.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://yahoo.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = iexplore

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s

uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll

mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

BHO: AutorunsDisabled - No File

BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll

BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20100518093135.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll

BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll

BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll

TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup

uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter

uRun: [iSUSPM] "c:\program files\common files\installshield\updateservice\isuspm.exe" -scheduler

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

uRunOnce: [shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~2.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB0.0; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.ancientegypt.co.uk/life/activity/act_main.html"

mRun: [ehTray] c:\windows\ehome\ehtray.exe

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [sigmatelSysTrayApp] stsystra.exe

mRun: [iAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe

mRun: [iSUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup

mRun: [iSUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start

mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE

mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup

mRun: [MMTray] "c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe"

mRun: [dlcdmon.exe] "c:\program files\dell photo aio printer 944\dlcdmon.exe"

mRun: [MemoryCardManager] "c:\program files\dell photo aio printer 944\memcard.exe"

mRun: [MimBoot] c:\progra~1\musicm~1\musicm~3\mimboot.exe

mRun: [tgcmd] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf

mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide

mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"

mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"

mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [DLCDCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCDtime.dll,_RunDLLEntry@16

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL

IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll

Trusted Zone: interfleet.com\http2

Trusted Zone: internet

Trusted Zone: mcafee.com

Trusted Zone: musicmatch.com\online

DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://www.activation.rr.com/install/download/tgctlcm.cab

DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB

DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab

DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} - hxxp://download.microsoft.com/download/7/0/7/707a44ad-52ad-49af-b7ef-e21b6b0656e4/VirtualEarth3D.cab

DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://www.ipix.com/viewers/ipixx.cab

DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204

DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab

DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - hxxp://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab

DPF: {3BB1D69B-A780-4BE1-876E-F3D488877135} - hxxp://download.microsoft.com/download/3/B/E/3BE57995-8452-41F1-8297-DD75EF049853/VirtualEarth3D.cab

DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab

DPF: {43E3F87D-DE7F-4087-BD4F-0DC854981158} - hxxp://download.microsoft.com/download/7/3/8/7384c441-3721-41ee-ae15-b678888f00dd/clearadj.CAB

DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154555276078

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155235105937

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk/6u12-b04/jinstall-6u12-windows-i586-jc.cab?e=1236810724684&h=16aaa9abf58df9af205cd9bafaee7903/&filename=jinstall-6u12-windows-i586-jc.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://floridakeysmedia.tv/axiscam/Codebase/AxisCamControl.ocx

DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab

DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://advisor.futuremark.com/global/msc311.cab

DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe

DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://conleybottom1.axiscam.net/activex/AMC.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

DPF: {E856B973-45FD-4559-8F82-EAB539144667} - hxxp://pccheckup.dellfix.com/rel/41/install/gtdownde.cab

DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4876/mcfscan.cab

DPF: {FE92D9C3-4A69-4EC7-8651-1DC8531D0075} - hxxp://www.bcsrivercam.com/TSBnwCam.CAB

Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll

Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-3-11 64288]

R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-9-29 385880]

R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-4-22 82952]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-9-29 88176]

R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-4-22 271480]

R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-4-22 271480]

R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-4-22 271480]

R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]

R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-4-22 170144]

R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-4-22 188136]

R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-4-22 141792]

R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-4-22 55456]

R3 dlcd_device;dlcd_device;c:\windows\system32\dlcdcoms.exe -service --> c:\windows\system32\dlcdcoms.exe -service [?]

R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-9-29 152320]

R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-9-29 51688]

R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-4-22 312616]

R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-4-22 88480]

S0 gpevbz;gpevbz;c:\windows\system32\drivers\gpevbz.sys [2010-4-2 823808]

S2 gupdate1c986fbc422206;Google Update Service (gupdate1c986fbc422206);c:\program files\google\update\GoogleUpdate.exe [2009-2-4 133104]

S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]

S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2006-7-29 30192]

S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1352832]

S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-4-22 88480]

S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-4-22 83496]

S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-9-29 34248]

S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-9-29 40552]

=============== Created Last 30 ================

2010-08-18 23:26:42 0 d-sha-r- C:\cmdcons

2010-08-18 23:21:37 98816 ----a-w- c:\windows\sed.exe

2010-08-18 23:21:37 77312 ----a-w- c:\windows\MBR.exe

2010-08-18 23:21:37 256512 ----a-w- c:\windows\PEV.exe

2010-08-18 23:21:37 161792 ----a-w- c:\windows\SWREG.exe

2010-08-17 22:18:50 0 ----a-w- c:\documents and settings\william buckhold\defogger_reenable

2010-08-16 19:28:11 0 d-----w- c:\windows\system32\wbem\Repository

2010-08-16 18:46:44 120 ----a-w- c:\windows\Jmopadote.dat

2010-08-16 18:46:44 0 ----a-w- c:\windows\Wgirahi.bin

2010-08-14 23:35:29 0 d-----w- C:\Netgear

2010-07-28 15:52:51 0 d-----w- c:\docume~1\willia~1\applic~1\Malwarebytes

2010-07-28 15:52:36 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-07-28 15:52:35 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-07-28 15:52:34 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-07-28 15:52:33 0 d-----w- c:\program files\Malwarebytes' Anti-Malware

==================== Find3M ====================

2010-08-22 13:16:39 153344 ----a-w- c:\windows\system32\drivers\dmio.sys

2010-07-27 06:30:35 8462336 ------w- c:\windows\system32\dllcache\shell32.dll

2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll

2010-06-30 12:31:35 149504 ------w- c:\windows\system32\dllcache\schannel.dll

2010-06-24 21:51:58 11077120 ------w- c:\windows\system32\dllcache\ieframe.dll

2010-06-24 12:22:03 916480 ----a-w- c:\windows\system32\wininet.dll

2010-06-24 12:22:03 916480 ------w- c:\windows\system32\dllcache\wininet.dll

2010-06-24 12:22:03 12800 ------w- c:\windows\system32\dllcache\xpshims.dll

2010-06-24 12:22:02 1210368 ------w- c:\windows\system32\dllcache\urlmon.dll

2010-06-24 12:22:01 611840 ------w- c:\windows\system32\dllcache\mstime.dll

2010-06-24 12:22:01 5951488 ------w- c:\windows\system32\dllcache\mshtml.dll

2010-06-24 12:22:01 206848 ------w- c:\windows\system32\dllcache\occache.dll

2010-06-24 12:21:59 599040 ------w- c:\windows\system32\dllcache\msfeeds.dll

2010-06-24 12:21:59 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll

2010-06-24 12:21:59 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll

2010-06-24 12:21:58 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll

2010-06-24 12:21:58 1986560 ------w- c:\windows\system32\dllcache\iertutil.dll

2010-06-24 12:21:58 184320 ------w- c:\windows\system32\dllcache\iepeers.dll

2010-06-24 12:21:56 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll

2010-06-24 12:21:55 387584 ------w- c:\windows\system32\dllcache\iedkcs32.dll

2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys

2010-06-23 13:44:04 1851904 ------w- c:\windows\system32\dllcache\win32k.sys

2010-06-23 12:08:09 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe

2010-06-21 15:27:11 354304 ------w- c:\windows\system32\dllcache\srv.sys

2010-06-18 13:36:12 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe

2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll

2010-06-16 15:42:34 15880 ----a-w- c:\windows\system32\lsdelete.exe

2010-06-14 14:31:20 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe

2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll

2010-06-14 07:41:45 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll

2010-05-27 03:08:08 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys

2006-08-07 17:39:20 251 ----a-w- c:\program files\wt3d.ini

============= FINISH: 21:07:09.23 ===============

Attach2.txt

Link to post
Share on other sites

Hi,

Yes that's normal. How are things running now? Grab a fresh copy of ComboFix, run it, and post its log. Also post a fresh DDS log.

Completed ComboFix/DDS and posted logs as requested. You'll have to check those logs to see if there is anything of concern in them that might give me additional problems.....I wouldn't really know what to look for if there is still a problem lurking.

As far as your question about how the computer is running, things seemed to quiet down after the TDSSKill the other day. The randomly opening browsers stopped, and didn't come back after reboots which it had been doing.

To be honest, I have really stayed off the computer (just checking this forum) until I heard further from you. Since I didn't understand the nature or threat level of my infection, and since I didn't want to foul up the cleaning process, I haven't tested the issue with the browser redirects. While typing this, however, I tried a few searches and clicked on some links on websites I "trust", and I didn't get any redirects or redirects via searches.

If you think we're almost done, I can try a little more internet activity and fully test the random browser opening and redirects/search redirects.

Thanks.

Link to post
Share on other sites

I tried some additional light internet activity since we posted on this thread yesterday---major, well known websites that are generally considered "safe"---- without incident (crossing fingers I haven't jinxed myself for saying that). Includes searches and links within those websites, and so far no redirects/no redirects from searching or links/no random browsers popping up and nothing I could see trying to install/reinstall itself.

One weird thing however. I have Microsoft Media Center (with the built in TV tuner DVR attached by a separate cable TV connection) that came with the system. It comes with a remote (speaker volume, mute, channel selection, FF, rewind, etc.) , but most of the remote control functions don't work. Some do, but most don't and it's not the batteries or something simple like that. All functions on Media Center work fine when using the mouse and controls on screen, it's just the remote that seems to have a problem.

I doubt that this has anything to do with the recent infection, but I can't say for sure. I can't tell from the logs if anything was changed or deleted to cause this. If this annoyance (since the rest of the functions can still be accessed from the screen, just not the remote) is the result of getting the overall system cleaned, then so be it. I just thought this was odd that the remote stopped functioning after running some of these scans.

Any thoughts on this?

Also, please let me know what else I need to do to get this machine cleaned and good to go.

Thanks.

Link to post
Share on other sites

  • Staff

Hi,

The infections seems to have been cleared, and the issue with the remote appears to be separate. Since some of the functions work, I would say that the remote itself is at fault. Maybe it fell on the ground at one point. Either way, nothing removed is related to it.

Let's check for any residual infection.

Next, please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

Next, download my Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me know how things are running now and what issues remain.

-screen317

Link to post
Share on other sites

Hello:

1.) ESET and Security Check logs below. McAfee threw a fit with warnings about Security Check, but I ran it anyway without any problem.

2.) Still crossing fingers, everything seems to be running smoothly. No lingering or additional problems have been noticed relating to my original browser/redirect issues.

3.) If we are nearing completing the cleaning process, please note any special deletion/removal instructions or any further items necessary to deal with concerning the programs downloaded or system changes that might have been made during this process. I'm assuming I don't want some of these programs laying around the machine for somebody else in the house to inadvertently run and screw things up.

Thanks again for your help. It's good to have the machine back under my control.

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=82bcf4d4e1b4c24e8e2ae4361a5ff1a4

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2010-08-25 02:15:37

# local_time=2010-08-25 10:15:37 (-0500, Eastern Daylight Time)

# country="United States"

# lang=9

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=5121 16777173 100 75 4459446 11894617 0 0

# compatibility_mode=6143 16777215 0 0 0 0 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=129693

# found=0

# cleaned=0

# scan_time=5240

Results of screen317's Security Check version 0.99.5

Windows XP Service Pack 3

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Disabled!

McAfee SecurityCenter

McAfee Virtual Technician

Antivirus up to date!

```````````````````````````````

Anti-malware/Other Utilities Check:

Ad-Aware

Malwarebytes' Anti-Malware

Java 6 Update 12

Java 2 Runtime Environment, SE v1.4.2_03

Out of date Java installed!

Adobe Flash Player

Adobe Reader 9.3.3

````````````````````````````````

Process Check:

objlist.exe by Laurent

Ad-Aware AAWService.exe is disabled!

Ad-Aware AAWTray.exe is disabled!

````````````````````````````````

DNS Vulnerability Check:

Unknown. This method cannot test your vulnerability to DNS cache poisoning. (Wireless connection?)

``````````End of Log````````````

Link to post
Share on other sites

  • Staff

Hi,

Navigate to Start --> Run, and type Combofix /uninstall in the box that appears. Click OK afterward. Notice the space between the X and the /uninstall

This uninstalls all of ComboFix's components.

Delete SecurityCheck.

After that, navigate to Start --> Control Panel --> Add or Remove Programs, and uninstall the following programs (if present):

Java

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.