Okay, I ran Combofix with a message warning me that McAfee Virus Scan is enbled(I tried my best to locate the source but culdn't disable it).
On finishing, Combofix restarted my windows and to my surprise it restarted in Normal mode without the NT authority shutdown message coming before I could log in. But the system is still slow and there are a couple of svchost.exe still runnning in the task manager. When I looged in the normal mode, I uninstalled McAfee and Spybot just in case you want me to run combofix again. I still cannot access firefox. Maybe I have to unistall and re-install it?
————————————————————————————————————————————-
ComboFix.log
————————————————————————————————————————————–
ComboFix 09-09-14.01 - pvirk 09/14/2009 14:32.1.2 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1728 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\mmcshane\Local Settings\Temporary Internet Files\Fiddler_.xml
c:\windows\msa.exe
c:\windows\run.log
c:\windows\system32\Cache
c:\windows\system32\drivers\rotscxkkrcunjy.sys
c:\windows\system32\drivers\UACssecbgpump.sys
c:\windows\system32\rotscxctexvoyl.dll
c:\windows\system32\rotscxonljggsm.dll
c:\windows\system32\rotscxrxwiotpe.dll
c:\windows\system32\rotscxvwppntvu.dat
c:\windows\system32\rotscxxeejttxh.dat
c:\windows\system32\UACkeidxrlkwe.dll
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\i386\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-08-14 to 2009-09-14 )))))))))))))))))))))))))))))))
.
2010-01-14 19:37 . 2009-02-14 21:57 ——– d—–w- c:\documents and settings\pvirk\Application Data\Apple Computer
2010-01-14 19:37 . 2010-01-14 19:37 ——– d—–w- c:\documents and settings\mmcshane\Local Settings\Application Data\Apple Computer
2010-01-14 19:35 . 2010-01-14 19:35 ——– d—–w- c:\program files\Bonjour
2010-01-14 19:35 . 2009-05-19 23:25 ——– d—–w- c:\program files\QuickTime
2010-01-14 19:34 . 2010-01-14 19:34 ——– d—–w- c:\documents and settings\pvirk\Local Settings\Application Data\Apple
2010-01-14 19:34 . 2010-01-14 19:34 ——– d—–w- c:\program files\Apple Software Update
2010-01-14 19:34 . 2008-11-07 19:23 32000 -c–a-w- c:\windows\system32\drivers\usbaapl.sys
2010-01-14 19:34 . 2009-05-19 23:35 ——– d—–w- c:\program files\Common Files\Apple
2010-01-14 19:34 . 2010-01-14 19:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-01-14 19:33 . 2010-01-14 19:37 ——– d—–w- c:\documents and settings\pvirk\Local Settings\Application Data\Apple Computer
2009-09-14 17:13 . 2009-09-14 17:13 ——– d—–w- c:\program files\ERUNT
2009-09-11 18:07 . 2009-09-11 18:07 19824532 —-a-w- c:\documents and settings\nvirk.zip
2009-09-11 07:44 . 2009-09-11 07:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-09-11 05:11 . 2009-09-11 05:16 ——– d—–w- c:\program files\Windows Live Safety Center
2009-09-11 04:36 . 2009-09-11 04:51 ——– d–h–w- c:\windows\PIF
2009-09-11 03:36 . 2009-09-11 03:39 135360 —-a-w- C:\FixBlast.exe
2009-09-11 02:53 . 2009-09-11 02:53 16409960 —-a-w- C:\spybotsd162.exe
2009-09-10 21:49 . 2009-09-10 21:49 ——– d—–w- c:\documents and settings\pvirk\Local Settings\Application Data\AVG Security Toolbar
2009-09-10 20:55 . 2009-09-10 23:23 ——– d—–w- C:\$AVG8.VAULT$
2009-09-10 20:30 . 2009-09-11 05:02 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-09-10 20:29 . 2009-09-11 02:57 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-09-10 20:29 . 2009-09-11 05:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-10 20:29 . 2009-09-11 02:56 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-09-10 20:04 . 2009-09-10 20:04 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-09-10 20:04 . 2009-09-10 20:04 ——– d—–w- c:\documents and settings\pvirk\Application Data\Malwarebytes
2009-09-10 20:04 . 2009-09-10 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-10 04:47 . 2009-09-10 04:47 ——– d—–w- C:\spoolerlogs
2009-08-27 23:15 . 2007-11-22 04:28 ——– d—–w- C:\commons-logging-1.1.1
2009-08-27 00:32 . 2009-08-27 00:32 ——– d—–w- C:\spring-framework-2.5.6-with-dependencies
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-10 23:54 . 2008-07-12 16:37 ——– d—–w- c:\documents and settings\pvirk\Application Data\Yahoo!
2009-09-10 23:54 . 2008-07-12 16:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-09-09 05:14 . 2008-12-17 00:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-13 06:18 . 2004-08-11 22:00 233472 —-a-w- c:\windows\system32\wmpdxm.dll
2009-06-24 18:09 . 2009-06-24 18:09 262144 —-a-w- C:\ntuser.dat
2007-12-18 13:42 . 2007-12-18 13:42 294912 -c–a-w- c:\program files\pscp.exe
2007-04-25 23:04 . 2007-04-25 23:04 454656 -c–a-w- c:\program files\putty.exe
2006-11-06 16:55 . 2006-11-27 15:46 748344 -c–a-w- c:\program files\Filemon.exe
2006-11-01 18:07 . 2006-11-27 15:46 707384 -c–a-w- c:\program files\Regmon.exe
2006-11-01 18:07 . 2006-11-27 15:46 3623736 —-a-w- c:\program files\procexp.exe
2004-11-08 19:34 . 2007-03-19 13:48 1489920 -c–a-w- c:\program files\pdftk.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\pchealth\helpctr\binaries\msconfig.exe" [2004-08-04 158208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1606980848-362288127-725345543-1231\Scripts\Logon\0\0]
"Script"=\\ciber-db\sysvol\phillydev.com\scripts\login.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1606980848-362288127-725345543-1329\Scripts\Logon\0\0]
"Script"=\\ciber-db\sysvol\phillydev.com\scripts\login.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1606980848-362288127-725345543-2202\Scripts\Logon\0\0]
"Script"=\\ciber-db\sysvol\phillydev.com\scripts\login.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1606980848-362288127-725345543-500\Scripts\Logon\0\0]
"Script"=\\ciber-db\sysvol\phillydev.com\scripts\login.bat
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"YahooAUService"=2 (0x2)
"Wmi"=2 (0x2)
"Visual Studio Analyzer RPC bridge"=3 (0x3)
"SSDPSRV"=3 (0x3)
"SQLWriter"=3 (0x3)
"SQLSERVERAGENT"=3 (0x3)
"Spooler"=2 (0x2)
"SMTPSVC"=2 (0x2)
"ReportServer"=2 (0x2)
"ose"=3 (0x3)
"MSSQLServerOLAPService"=2 (0x2)
"msftesql"=2 (0x2)
"MsDtsServer"=2 (0x2)
"MSDTC"=3 (0x3)
"mnmsrvc"=3 (0x3)
"MDM"=2 (0x2)
"McTaskManager"=2 (0x2)
"McShield"=2 (0x2)
"McAfeeFramework"=2 (0x2)
"Imapi Helper"=3 (0x3)
"IISADMIN"=2 (0x2)
"IDriverT"=2 (0x2)
"IBExpertBackupRestore"=3 (0x3)
"HTTPFilter"=3 (0x3)
"HidServ"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"EventSystem"=3 (0x3)
"COMSysApp"=3 (0x3)
"clr_optimization_v2.0.50727_32"=3 (0x3)
"CiSvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"aspnet_state"=3 (0x3)
"ALG"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"25:TCP"= 25:TCP:localhost
S0 black;black;c:\windows\system32\drivers\BlackDrv.sys –> c:\windows\system32\drivers\BlackDrv.sys [?]
S1 vcdrom;Virtual CD-ROM Device Driver;\??\c:\documents and settings\ciber\Desktop\Virtual CDROM\VCdRom.sys –> c:\documents and settings\ciber\Desktop\Virtual CDROM\VCdRom.sys [?]
S3 RapFile;RapFile;c:\windows\system32\drivers\RapFile.sys [1/12/2007 3:34 PM 36676]
S3 RapNet;RapNet;c:\windows\system32\drivers\RapNet.sys [1/12/2007 3:34 PM 24344]
S3 VSPerfDrv;Performance Tools Driver;c:\program files\Microsoft Visual Studio 8\Team Tools\Performance Tools\VSPerfDrv.sys [12/2/2006 4:10 AM 48128]
S4 IBExpertBackupRestore;IBExpertBackupRestore;c:\program files\HK-Software\IBExpertBackupRestore\hkIBRS.exe –> c:\program files\HK-Software\IBExpertBackupRestore\hkIBRS.exe [?]
S4 MsDtsServer;SQL Server Integration Services;c:\program files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe [3/4/2007 12:12 AM 202096]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [12/2/2006 7:17 AM 2805000]
S4 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe [3/4/2007 12:09 AM 17264]
.
Contents of the 'Scheduled Tasks' folder
2010-01-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-09-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-17 00:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://philadelphia.ciber.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = ciberproxy:8080
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Google; Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate; English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
Trusted Zone: localhost
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\pvirk\Application Data\Mozilla\Firefox\Profiles\ykl3zcyx.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
Notify-avgrsstarter - avgrsstx.dll
Notify-NavLogon - (no file)
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9b.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-14 14:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\msftesql]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:MSSQLSERVER"
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\windows\system32\scardsvr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\msiexec.exe
c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-09-14 14:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-14 18:50
Pre-Run: 9,243,488,256 bytes free
Post-Run: 7,205,289,984 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
226 — E O F — 2009-09-11 07:10
———————————————————————————————————————————————
Thanks again.
-NV