ComboFix 09-12-01.01 - Sameer 12/01/2009 22:26.3.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.140 [GMT -5:00] Running from: H:\ComboFix.exe AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Sameer\Local Settings\Application Data\ngontc c:\documents and settings\Sameer\Local Settings\Application Data\ngontc\brxcsysguard.exe c:\documents and settings\Sameer\My Documents\ZbThumbnail.info c:\program files\RcvSystem c:\windows\system32\Data c:\windows\system32\Process.exe c:\windows\system32\SrchSTS.exe c:\windows\system32\Drivers\atapi.sys . . . is infected!! . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_WSMSPSVC ((((((((((((((((((((((((( Files Created from 2009-11-02 to 2009-12-02 ))))))))))))))))))))))))))))))) . 2009-11-29 21:22 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-11-29 21:22 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-11-29 19:41 . 2009-11-29 19:41 -------- d-----w- c:\program files\Trend Micro 2009-11-26 15:19 . 2009-11-28 15:52 79488 ----a-w- c:\documents and settings\Sameer\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-02 03:18 . 2007-05-13 13:30 -------- d-----w- c:\documents and settings\Sameer\Application Data\DNA 2009-11-29 21:22 . 2008-03-18 02:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-11-29 18:26 . 2008-02-21 23:42 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-11-29 14:08 . 2005-10-20 15:04 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-11-05 12:09 . 2007-11-18 16:28 -------- d-----w- c:\documents and settings\Sameer\Application Data\Azureus 2009-10-11 13:09 . 2009-05-05 19:53 -------- d-----w- c:\documents and settings\Sameer\Application Data\LimeWire 2009-09-25 05:56 . 2004-08-10 17:51 662016 ----a-w- c:\windows\system32\wininet.dll 2009-09-25 05:56 . 2004-08-10 17:51 81920 ----a-w- c:\windows\system32\ieencode.dll 2009-09-11 14:33 . 2009-05-21 00:39 133632 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-07 17:35 . 2005-10-27 03:33 38472 -c--a-w- c:\documents and settings\Sameer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-09-04 20:45 . 2004-08-10 17:51 58880 ----a-w- c:\windows\system32\msasn1.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Red Swoosh EDN Client"="c:\program files\RSSoft\RSEDNClient.exe" [2006-04-19 117279] "EA Core"="c:\program files\Electronic Arts\EA Downloader\Core.exe" [2006-08-16 1826816] "DNA"="c:\program files\BitTorrent_DNA\dna.exe" [2007-05-13 216064] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 1318912] "Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184] "CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248] "DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-01-08 49512] "Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2008-02-16 100056] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941] "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-05-24 188416] "HPHmon04"="c:\windows\system32\hphmon04.exe" [2002-06-20 339968] "HPHUPD04"="c:\program files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" [2002-05-24 49152] "Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-11-19 180269] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2004-06-10 60928] c:\documents and settings\All Users\Start Menu\Programs\Startup\ America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2005-10-20 156784] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912] WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2005-12-15 122880] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 18:41 294912 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "FirewallDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\BitTorrent\\bittorrent.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\BitTorrent_DNA\\dna.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "9420:TCP"= 9420:TCP:Red Swoosh "5000:UDP"= 5000:UDP:Red Swoosh [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 1:53 PM 5632] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 12:39 PM 32256] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/14/2008 8:44 PM 24652] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 5:51 PM 4096] . Contents of the 'Scheduled Tasks' folder 2008-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 18:57] 2009-03-21 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Sameer.job - c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2005-03-15 19:47] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyServer = http=127.0.0.1:5555 uInternet Settings,ProxyOverride = IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html IE: &Search IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000 Trusted Zone: turbotax.com . - - - - ORPHANS REMOVED - - - - HKCU-Run-Spyware Doctor - c:\program files\Spyware Doctor\swdoctor.exe HKCU-Run-RssReader - c:\program files\RssReader\RssReader.exe HKCU-Run-aqhmgeuy - c:\documents and settings\Sameer\Local Settings\Application Data\ngontc\brxcsysguard.exe HKLM-Run-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe HKLM-Run-aqhmgeuy - c:\documents and settings\Sameer\Local Settings\Application Data\ngontc\brxcsysguard.exe HKU-Default-Run-Spyware Doctor - c:\program files\Spyware Doctor\swdoctor.exe Notify-dimsntfy - (no file) AddRemove-InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe AddRemove-InstallShield_{28291BD5-92D2-4685-82DC-CCA925C53CCA} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe AddRemove-InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe AddRemove-InstallShield_{45EF4EE3-F591-4B74-A477-0CAE12934CE7} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe AddRemove-InstallShield_{4C96958A-6562-4143-B820-FF4890D3B734} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe AddRemove-InstallShield_{8AF1E098-1A5C-4336-BBE2-D047ABB401ED} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe AddRemove-InstallShield_{91203BD3-6C3E-472F-ADBD-F60FDC7C4010} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe AddRemove-InstallShield_{91F1A0D6-23AD-49FE-8D4E-379485652214} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe AddRemove-InstallShield_{C7281207-4AA4-425E-B57A-0E9EF8445635} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb AddRemove-kernel - c:\program files\kernel\kernel.exe AddRemove-Router - c:\program files\Router\UnInstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-01 22:49 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-3545857805-4264245001-2759532031-1006\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(804) c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'explorer.exe'(7128) c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Symantec Shared\ccProxy.exe c:\program files\Common Files\Symantec Shared\ccSetMgr.exe c:\program files\Common Files\Symantec Shared\SNDSrvc.exe c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\CTsvcCDA.EXE c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Norton Internet Security\Norton AntiVirus\navapsvc.exe c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe c:\windows\system32\Rundll32.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\MsPMSPSv.exe c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe c:\program files\iPod\bin\iPodService.exe c:\program files\AIM6\aolsoftware.exe c:\program files\Common Files\Symantec Shared\Security Center\SymSCUI.exe . ************************************************************************** . Completion time: 2009-12-01 23:04 - machine was rebooted ComboFix-quarantined-files.txt 2009-12-02 04:04 ComboFix2.txt 2008-03-29 15:49 ComboFix3.txt 2008-03-27 01:27 Pre-Run: 93,093,220,352 bytes free Post-Run: 94,175,100,928 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect - - End Of File - - 9B31FD1D3DE3A7A9555BD44654995827